Symptom
A cloud foundry application is configured with mutual TLS (mTLS) as can be determined with the url called for oauth token: https://<subdomain>.authentication.cert.<landscape>/oauth/token. After some time the application gives Internal Server Error in the browser. Application logs show similar error: completed with status 500 Could not authenticate with UAA: Could not obtain access token: request to authentication service at https://<subdomain>.authentication.cert.<region>.hana.ondemand.com/oauth/token failed, error: unexpected response from authentication service at https://<subdomain>.authentication.cert.<region>.hana.ondemand.com/oauth/token: status code: NaN, response body: \"undefined\", "}.
It is important to note that if authentication.cert is not seen in the url in the application logs, but only authentication alone, then this is not an mTLS xsuaa service call and this kba shall not be relevant.
It is possible to see authentication only in a network trace like https://<subdomain>.authentication.<region>.hana.ondemand.com/... before the call to the certificate endpoint, which happens internally, so the application logs should be the source for the above determination.
Read more...
Environment
SAP Business Technology Platform
Product
Keywords
KBA , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.