Symptom
- When attempting to connect to the S/4 hana backend system through the cloud connector and web dispatcher, the connection fails and 401 error is raised.
- The cloud connector point as reachable but the backend shows 401 unauthorized error.
Web dispatcher logs
[Thr 139774570526400] Fri Dec 27 18:17:05:959 2024
[Thr 139774570526400] SSL_get_state()==0x1180 "TLS read client certificate A"
[Thr 139774570526400] *** ERROR in secussl_read: SSL_read() lasterr 0x20001046
[Thr 139774570526400] => "received a fatal TLS certificate unknown alert message from the peer"
[Thr 139774570526400] srv SSL session PSE "/usr/sap/WDP/W03/sec/SAPSSLS.pse" (load=Thu Dec 12 22:58:22 2024, rcnt=1)
[Thr 139774570526400] Subject : CN=*.xxxxxxxxxx.com
[Thr 139774570526400] Issuer : CN=GlobalSign GCC R6 AlphaSSL CA 2023, O=GlobalSign nv-sa, C=BE
[Thr 139774570526400] SerialNo: 1C:00:1E:00:E1:1E:00:1D:E1:C1:11:11
[Thr 139774570526400] Validity - NotBefore: Sat Apr 13 11:42:02 2024 (240413061202Z)
[Thr 139774570526400] NotAfter: Thu May 8 14:13:08 2025 (250508084308Z)
[Thr 139774570526400] SSL_CTX ciphersuites=135:PFS:HIGH::EC_X25519:EC_P256:EC_HIGH
[Thr 139774570526400] Server SSL_CTX 7j1jj40jj2j0 pvflags=897 (TLSv1.2,TLSv1.1,TLSv1.0,BC)
[Thr 139774570526400] TLSextSNI server_name="s4hana.xxxxxxx.com"
[Thr 139774570526400] secussl_read: SSL_read() failed (536875078/0x20001046)
[Thr 139774570526400] => "received a fatal TLS certificate unknown alert message from the peer"
[Thr 139774570526400] SSL NI-hdl 84: local=XXXXXXXXXXXX:44303 peer= XXXXXXXXXX:55064
[Thr 139774570526400] <<- ERROR: SapSSLSessionStartNB(sssl_hdl=7f1fb40028b0)==SSSLERR_ALERT_CERTIFICATE_UNKNOWN
[Thr 139774570526400] *** ERROR => IcmConnInitServerSSL: SapSSLSessionStartNB returned (-127): SSSLERR_ALERT_CERTIFICATE_UNKNOWN [icxxconn.c 3088]
SCC Logs
2024-12-27 17:40:07,349 +0530#DEBUG#com.sap.scc.rt#AccessControl connection checker# #SCCEndpointValidator received issuer certificates trusted by the server:
[CN=GlobalSign GCC R6 AlphaSSL CA 2023,O=GlobalSign nv-sa,C=BE, CN=GlobalSign,O=GlobalSign,OU=GlobalSign Root CA - R6]
2024-12-27 17:40:07,349 +0530#DEBUG#com.sap.scc.rt#AccessControl connection checker# #ssl_debug(3): No client certificate available, sending empty certificate message...
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Read more...
Environment
- SAP Cloud Connector On-Demand/On-Premise Connectivity
- S/4 HANA
- Web dispatcher
Product
Keywords
401 unauthorized, system certificate, web dispatcher, backend, certificate unknown, No trusted connection, session PSE. , KBA , BC-MID-SCC , SAP Cloud Connector On-Demand/On-Premise Connectivity , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.