SAP Knowledge Base Article - Preview

3318100 - Internal Server Error on CF apps calling https://<subdomain>.authentication.cert.<landscape>/oauth/token endpoint

Symptom

A cloud foundry application is configured with mutual TLS (mTLS) as can be determined with the url called for oauth token: https://<subdomain>.authentication.cert.<landscape>/oauth/token. After some time the application gives Internal Server Error in the browser. Application logs show similar error: completed with status 500 Could not authenticate with UAA: Could not obtain access token: request to authentication service at https://<subdomain>.authentication.cert.<region>.hana.ondemand.com/oauth/token failed, error: unexpected response from authentication service at https://<subdomain>.authentication.cert.<region>.hana.ondemand.com/oauth/token: status code: NaN, response body: \"undefined\", "}. 

It is important to note that if authentication.cert is not seen in the url in the application logs, but only authentication alone, then this is not an mTLS xsuaa service call and this kba shall not be relevant. 

It is possible to see authentication only in a network trace like  https://<subdomain>.authentication.<region>.hana.ondemand.com/... before the call to the certificate endpoint, which happens internally, so the application logs should be the source for the above determination. 


Read more...

Environment

SAP Business Technology Platform

Product

SAP Business Technology Platform all versions

Keywords

KBA , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.