SAP Knowledge Base Article - Public

3650610 - Enhancement to PGP Key Management and Security Center Compliance with Updated RFC Standards

Symptom

  • Error displayed when attempting to decrypt a file received from Concur SFTP using a PGP key generated in SuccessFactors.
  • Error with Signing Key - Key validation failed: PGP public key does not include required encryption capability.
  • Error with Decryption Key - Key validation failed: PGP public sub key uses an unsupported algorithm: 2.

Environment

SAP SuccessFactors HCM Suite

Reproducing the Issue

  1. Access the instance
  2. Generate a PGP key using Admin Center in SuccessFactors.
  3. Add a Decryption Key and generate the Public Key.
  4. Share the generated Public Key with Concur.
  5. Attempt to upload the key on Concur's side for file decryption.
  6. The user is prompted with the error "Key validation failed: PGP public sub key uses an unsupported algorithm: 2."

Cause

RSA Encrypt-Only and RSA Sign-Only key types have been deprecated as per the updated RFC Standards.

Resolution

As per the latest RFC compliance standards, RSA Encrypt-Only and RSA Sign-Only key types are now deprecated.

The fix for this issue is planned to be deployed on 2H 2026 release (Preview: October 12 / Production: November 13 - 14).

For release timelines, please review SAP SuccessFactors Product Release & Road Map Information.

See Also

Keywords

KI2505, SFINT-20397, PGP Key, RSA Encrypt-Only, RSA Sign-Only, encryption, decryption, concur, SFTP, Key validation failed, unsupported algorithm, Security Center, Compliance
, KBA , LOD-SF-PLT-PGP , PGP Key Generation , Known Error

Product

SAP SuccessFactors HCM Suite 2511