Symptom
- Error displayed when attempting to decrypt a file received from Concur SFTP using a PGP key generated in SuccessFactors.
- Error with Signing Key - Key validation failed: PGP public key does not include required encryption capability.
- Error with Decryption Key - Key validation failed: PGP public sub key uses an unsupported algorithm: 2.
Environment
SAP SuccessFactors HCM Suite
Reproducing the Issue
- Access the instance
- Generate a PGP key using Admin Center in SuccessFactors.
- Add a Decryption Key and generate the Public Key.
- Share the generated Public Key with Concur.
- Attempt to upload the key on Concur's side for file decryption.
- The user is prompted with the error "Key validation failed: PGP public sub key uses an unsupported algorithm: 2."
Cause
RSA Encrypt-Only and RSA Sign-Only key types have been deprecated as per the updated RFC Standards.
Resolution
As per the latest RFC compliance standards, RSA Encrypt-Only and RSA Sign-Only key types are now deprecated.
The fix for this issue is planned to be deployed on 2H 2026 release (Preview: October 12 / Production: November 13 - 14).
For release timelines, please review SAP SuccessFactors Product Release & Road Map Information.
See Also
- KBA 2296971 - Generating and Importing PGP Keys
- SAP SuccessFactors Product Release & Road Map Information
- SAP SuccessFactors Patches Knowledge Base
- KBA 2171560 - How to be notified of new or updated SAP Notes or KBAs
Keywords
KI2505, SFINT-20397, PGP Key, RSA Encrypt-Only, RSA Sign-Only, encryption, decryption, concur, SFTP, Key validation failed, unsupported algorithm, Security Center, Compliance
Product
SAP SuccessFactors HCM Suite 2511
SAP Knowledge Base Article - Public