Symptom
- When attempting to connect to the S/4 hana backend system through the cloud connector and web dispatcher, the connection fails and 401 error is raised.
- The cloud connector point as reachable but the backend shows 401 unauthorized error.
Web dispatcher logs
[Thr 139774570526400] Fri Dec 27 18:17:05:959 2024
[Thr 139774570526400] SSL_get_state()==0x1180 "TLS read client certificate A"
[Thr 139774570526400] *** ERROR in secussl_read: SSL_read() lasterr 0x20001046
[Thr 139774570526400] => "received a fatal TLS certificate unknown alert message from the peer"
[Thr 139774570526400] srv SSL session PSE "/usr/sap/WDP/W03/sec/SAPSSLS.pse" (load=Thu Dec 12 22:58:22 2024, rcnt=1)
[Thr 139774570526400] Subject : CN=*.xxxxxxxxxx.com
[Thr 139774570526400] Issuer : CN=GlobalSign GCC R6 AlphaSSL CA 2023, O=GlobalSign nv-sa, C=BE
[Thr 139774570526400] SerialNo: 1C:00:1E:00:E1:1E:00:1D:E1:C1:11:11
[Thr 139774570526400] Validity - NotBefore: Sat Apr 13 11:42:02 2024 (240413061202Z)
[Thr 139774570526400] NotAfter: Thu May 8 14:13:08 2025 (250508084308Z)
[Thr 139774570526400] SSL_CTX ciphersuites=135:PFS:HIGH::EC_X25519:EC_P256:EC_HIGH
[Thr 139774570526400] Server SSL_CTX 7j1jj40jj2j0 pvflags=897 (TLSv1.2,TLSv1.1,TLSv1.0,BC)
[Thr 139774570526400] TLSextSNI server_name="s4hana.xxxxxxx.com"
[Thr 139774570526400] secussl_read: SSL_read() failed (536875078/0x20001046)
[Thr 139774570526400] => "received a fatal TLS certificate unknown alert message from the peer"
[Thr 139774570526400] SSL NI-hdl 84: local=XXXXXXXXXXXX:44303 peer= XXXXXXXXXX:55064
[Thr 139774570526400] <<- ERROR: SapSSLSessionStartNB(sssl_hdl=7f1fb40028b0)==SSSLERR_ALERT_CERTIFICATE_UNKNOWN
[Thr 139774570526400] *** ERROR => IcmConnInitServerSSL: SapSSLSessionStartNB returned (-127): SSSLERR_ALERT_CERTIFICATE_UNKNOWN [icxxconn.c 3088]
SCC Logs
2024-12-27 17:40:07,349 +0530#DEBUG#com.sap.scc.rt#AccessControl connection checker# #SCCEndpointValidator received issuer certificates trusted by the server:
[CN=GlobalSign GCC R6 AlphaSSL CA 2023,O=GlobalSign nv-sa,C=BE, CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R6]
2024-12-27 17:40:07,349 +0530#DEBUG#com.sap.scc.rt#AccessControl connection checker# #ssl_debug(3): No client certificate available, sending empty certificate message...
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Read more...
Environment
- SAP Cloud Connector On-Demand/On-Premise Connectivity
- S/4 HANA
- Web dispatcher
Product
Keywords
401 unauthorized, system certificate, web dispatcher, backend, certificate unknown, No trusted connection, session PSE. , KBA , BC-MID-SCC , SAP Cloud Connector On-Demand/On-Premise Connectivity , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview