Symptom
- In SAP Cloud Connector, the “Check Internal Host” functionality fails with an SSL/TLS error:
2026-01-29 15:54:32,455 +0100#INFO#com.sap.scc.rt#AccessControl connection checker# #SccEndpointValidator for <host>:<port> can't retrieve further TLS information witk IAIK
iaik.security.ssl.SSLException: Peer sent alert: Alert Fatal: handshake failure
iaik.security.ssl.SSLException: Peer sent alert: Alert Fatal: handshake failure
- The error is logged with reference to:
AccessControl connection checker
SccEndpointValidator
SccEndpointValidator
- Productive communication (e.g. via SAP BTP application) works successfully
- No handshake failure is observed in backend ICM logs for productive requests
Read more...
Environment
- SAP Cloud Connector
- Backend system with TLS configuration (including ECDSA-only or restricted cipher suites)
- SAP BTP connectivity scenarios
Product
SAP NetWeaver all versions
Keywords
cloud connector, connection checker, iaik, ssl handshake failure, ecdsa, ecc, tlsv1.2, no common ciphersuite, clienthello, handshake failure alert, scc_core.trc, strust, ecdhe_ecdsa, abap icm, tls diagnostics , KBA , BC-MID-SCC , SAP Cloud Connector On-Demand/On-Premise Connectivity , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview