SAP Knowledge Base Article - Preview

3748504 - SSL connection fails when restricting SSL certificates in SAP ASE - SDK for SAP ASE

Symptom

  • When restricting SSL to specific newer ciphers in ASE

    sp_ssladmin 'setcipher','TLS_ECDHE_RSA_WITH_AES128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES256_GCM_SHA384'
    go

    The following cipher suites and order of preference are set for SSL connections:

     Cipher Suite Name                                                               Preference
     ----------------------------------------------------------------  -------------
     TLS_ECDHE_RSA_WITH_AES128_GCM_SHA256                     1
     TLS_ECDHE_RSA_WITH_AES256_GCM_SHA384                     2

  • Valid client connections using SSL fail, showing Open Client application example:

    CT-LIBRARY error:
    ct_connect(): network packet layer: internal net library error: Net-Lib protocol driver call to connect two endpoints failed


Read more...

Environment

  • SAP Adaptive Server Enterprise (ASE) 16.0 SP04  & 16.1
  • SAP Adaptive Server Enterprise (ASE) Software Developer Kit (SDK) 16.0 SP04 & 16.1
  • Open Client Client-Library

Product

SAP Adaptive Server Enterprise 16.0.4 ; SAP Adaptive Server Enterprise 16.1 ; SAP Adaptive Server Enterprise SDK all versions

Keywords

ct-library, isql, bcp, sybase, libsyb, @@ssl_ciphersuite Null , @@ssl_ciphersuite , KBA , BC-SYB-SDK , SDK , BC-SYB-ASE , Sybase ASE Database Platform (non Business Suite) , Known Error

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.