Symptom
When trying to access the system via the SAP Web Dispatcher the following warning appears:
In Web Dispatcher trace following entries can be found related to the issue:
SSL_get_state()==0x1180 "TLS read client certificate A"
*** ERROR in secussl_read: SSL_read() lasterr 0x20001046
=> "received a fatal TLS certificate unknown alert message from the peer"
srv SSL session PSE "/usr/sap/<SID>/<instance name>/sec/SAPSSLS.pse" (load=<date>, rcnt=1)
Subject : CN=<subject information>
Issuer : CN=<issuer information>
SerialNo: <serial number>
Validity - NotBefore: <Certificate validity>
NotAfter: <Certificate validity>
SSL_CTX ciphersuites=135:PFS:HIGH::EC_X25519:EC_P256:EC_HIGH
Server SSL_CTX 7f973c0971a0 pvflags=897 (TLSv1.2,TLSv1.1,TLSv1.0,BC)
TLSextSNI server_name="<hostname>"
(789_REL patchno 226,linuxx86_64_gcc43) CommonCryptoLib 8.5.53 (/usr/sap/<SID>/SYS/exe/uc/linuxx86_64/libsapcrypto.so)
secussl_read: SSL_read() failed (536875078/0x20001046)
=> "received a fatal TLS certificate unknown alert message from the peer"
SSL NI-hdl 71: local=<local IP::<port> peer=<client IP>:<port>
<<- ERROR: SapSSLSessionStartNB(sssl_hdl=7f9730000b60)==SSSLERR_ALERT_CERTIFICATE_UNKNOWN
*** ERROR => IcmConnInitServerSSL: SapSSLSessionStartNB returned (-127): SSSLERR_ALERT_CERTIFICATE_UNKNOWN [icxxconn.c 3090]
Read more...
Environment
SAP Web Dispatcher
Keywords
ERR_CERT_COMMON_NAME_INVALID, insecure, SSSLERR_ALERT_CERTIFICATE_UNKNOWN, ERROR in secussl_read, SAPSSLS.pse, host mismatch, received a fatal TLS certificate unknown alert message from the peer, Your connection is not private, SSSLERR_SSL_READ , KBA , BC-CST-WDP , Web Dispatcher , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.