SAP Knowledge Base Article - Preview

3742834 - “SSL certificate validation failed: host name 'AAA‘ does not match names in certificate” error when enable SSL connection for ABAP connection

Symptom

  • Application cannot connect to the database after SSL connection is enabled.
    Following error messages are shown in trans.log:
    4 ETW000  [     dev trc,00000]  connect property [sslKeyStore = sapsrv.pse]
    4 ETW000  [     dev trc,00000]  connect property [sslTrustStore = sapsrv.pse]
    4 ETW000  [     dev trc,00000]  connect property [sslCryptoProvider = commoncrypto]
    4 ETW000  [     dev trc,00000]  connect property [sslValidateCertificate = true]
    4 ETW000  [dbhdbsql.cpp,00000]  *** ERROR => Connect to database failed, rc=1, rcSQL=-10709
    4 ETW000  [     dev trc,00000]  SQLCODE    : -10709
    4 ETW000  [     dev trc,00000]  SQLERRTEXT : Connection failed (RTE:[300015] SSL certificate validation failed: host name 'AAA.\
    4 ETW000  [     dev trc,00000]               com' does not match names in certificate: 'BBB.com, SAP HANA ClientPKI' (aaa.bbb.ccc.\
    4 ETW000  [     dev trc,00000]               ddd:14696 -> AAA.com:30015))
    4 ETW000  [    dblink  ,00000]  ***LOG BY2=>sql error -10709 performing CON
    4 ETW000  [    dblink  ,00000]  ***LOG BY0=>Connection failed (RTE:[300015] SSL certificate validation failed: host name 'AAA.com' does not match names in certificate: 'BBB.com, SAP HANA ClientPKI' (aaa.bbb.ccc.ddd:14696 -> AAA:30015))
    2EETW169 no connect possible: "DBMS = HDB                              ---  SERVER = '' PORT = ''"
    4 ETW000  [     dev trc,00000]  Resetting statement cache ...
    4 ETW000  [     dev trc,00000]  Statement cache reset


Read more...

Environment

  • SAP HANA, Platform Edition

Product

SAP HANA, platform edition all versions

Keywords

sql error -10709, 300015, connection failed, ssl certificate validation failed, hostname mismatch, hdbuserstore, DEFAULT entry, sslHostNameInCertificate, dbs/hdb/connect_property, sapsrv.pse, commoncrypto, hana client pki, virtual hostname, certificate cn san, post-patching connection failure , KBA , HAN-DB-CLI , SAP HANA Clients (JDBC, ODBC) , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.