Symptom
When using X.509/mTLS certificate for authentication between SuccessFactors HCM Suite and IAS/IPS, the mTLS certificate generated by IPS by default is set to expire in a year from the date when it is created. Should the certificate in IPS be regenerated, reimported into source/target system?
“Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.”
Environment
SAP SuccessFactors HCM Suite
Resolution
There's the option to enable Automatic Regeneration so that mTLS certificate will be regenerated upon expiration:
If you are using mTLS certificate based authentication in the IPS source/target system for the SuccessFactors:
- In IAS/IPS Admin Console, please go to Identity Provisioning -> Target/Source Systems, locate the associated IPS system for the SuccessFactors.
- Then go to Outbound Certificate tab, set the radio button for Automatic Regeneration from OFF to ON.
With this “Automatic Regeneration” option enabled, the certificate will be automatically regenerated within 14 days prior to its expiration. The renewed certificate is not required to import in SF again.
This “Automatic Regeneration” option is supported for IPS tenants running on SAP Cloud Identity Service infrastructure. If your IPS tenants are still on the NEO infrastructure, please upgrade to SAP Cloud Identity Service infrastructure then enable this option.
If you are still using basic authentication between IAS/IPS and SuccessFactors HCM Suite, we recommend that you migrate to X509/mTLS certificate based authentication as early as possible. For information regarding the migration, please refer to this blog
See Also
Keywords
mTLS certificate, x.509 certificate, IPS certificate, expiration certificate , KBA , LOD-SF-PLT-IAS , Identity Authentication Services (IAS) With BizX , BC-IAM-IDS , Identity Authentication Service , BC-IAM-IPS , Identity Provisioning Service (IPS) , How To
Product
Attachments
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
| Pasted image.png |
SAP Knowledge Base Article - Public