Symptom
While updating Cloud Foundry subaccount certificate from SCC, following is raised from SCC trace (ljs_trace.log / scc_core.trc):
====
20xx-xx-xx xx:x:36,xxx +0000#INFO#com.sap.scc.security#https-jsse-nio2-8443-exec-14# #https://connectivitycertsigning.cf.us10.hana.ondemand.com:443/certificate/management/v1/sign/account/<Subaccount-ID> Returned Http Response with code 401
20xx-xx-xx xx:xx:xx,xxx +0000#DEBUG#org.apache.http.impl.conn.PoolingHttpClientConnectionManager#https-jsse-nio2-8443-exec-14# #Connection manager is shutting down
20xx-xx-xx xx:xx:xx,xxx +0000#DEBUG#org.apache.http.impl.conn.DefaultManagedHttpClientConnection#https-jsse-nio2-8443-exec-14# #http-outgoing-148344: Close connection
20xx-xx-xx xx:xx:xx,xxx +0000#INFO#com.sap.scc.tomcat.utils.SystemPrintStreamSSLWrapper#https-jsse-nio2-8443-exec-14# #javax.net.ssl|FINE|04 1E|https-jsse-nio2-8443-exec-14|20xx-xx-xx xx:xx:xx.xx UTC|SSLSocketImpl.java:497|duplex close of SSLSocket
20xx-x-xx xx:xx:xx,xxx +0000#INFO#com.sap.scc.tomcat.utils.SystemPrintStreamSSLWrapper#https-jsse-nio2-8443-exec-14# #javax.net.ssl|FINE|04 1E|https-jsse-nio2-8443-exec-14|20xx-xx-xx xx:xx:xx.xx UTC|SSLSocketImpl.java:1570|close the SSL connection (passive)
20xx-xx-x xx:xx:xx,xxx +0000#DEBUG#org.apache.http.impl.conn.PoolingHttpClientConnectionManager#https-jsse-nio2-8443-exec-14# #Connection manager shut down
20xx-x-xx xx:xx:xx,xxx +0000#INFO#com.sap.scc#https-jsse-nio2-8443-exec-14# #An error occurred when trying to connect. See 'Log And Trace Files' and in particular ljs_trace.log for details. Associated entries were logged on or around 20xx-xx-xx xx:xx:xx,xxx +0000.
com.sap.scc.servlets.RequestFailureExecution$InvalidConfiguration: An error occurred when trying to connect. See 'Log And Trace Files' and in particular ljs_trace.log for details. Associated entries were logged on or around 20xx-xx-xx xx:xx:xx,xxx +0000.
at com.sap.scc.servlets.ConfigurationServlet.refreshCertificate(ConfigurationServlet.java:1539)
at com.sap.scc.servlets.ConfigurationServlet.dispatch(ConfigurationServlet.java:364)
at com.sap.scc.servlets.ServletUtilities.service(ServletUtilities.java:58)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:583)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:212)
Caused by: com.sap.scc.servlets.CriticalSccException: Preparation of tunnel certificate for <Subaccount-ID>@cf.us10.hana.ondemand.com account failed due to unknown exception.
at com.sap.scc.ui.SubaccountControl.applyConfig(SubaccountControl.java:225)
at com.sap.scc.ui.SubaccountControl.refreshSubaccount(SubaccountControl.java:282)
at com.sap.scc.servlets.ConfigurationServlet.refreshCertificate(ConfigurationServlet.java:1530)
... 39 common frames omitted
Caused by: com.sap.scc.servlets.SccHandshakeException: SCC handshake failed: 401 — Unauthorized
====
Read more...
Environment
- SAP Cloud Connector(SCC) release independent;
- SAP Business Technology Platform(BTP).
Keywords
cloud foundry, SCC, Cloud Connector, Authorization, handshake, unauthorized, code 401, error, HTTP, HTTPs, certificate renew manage subaccount, subaccount certificate, an error occurred when trying to connect, 417 an authorization problem occurred, unable to add a cloud foundry subaccount, subaccount (sac) in sap cloud connector,sap cloud platform, JVM, subacocunt, sub-account, sub account, tenant, refresh, cert, certificate, SccHandshakeException, handshake, 401, HTTP 401, tunnel, /certificate/management/v1/sign/account , KBA , BC-MID-SCC , SAP Cloud Connector On-Demand/On-Premise Connectivity , BC-CP-CF , Cloud Foundry , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview