Symptom
When using the PGP signing step in SAP Cloud Integration, the signature is created using a signing subkey rather than the primary key of the PGP key pair. The receiving party reports that signature verification fails when they attempt to verify using the primary key from the shared public key ring.
On closer inspection, verification succeeds only when the receiving party uses the subkey from the public key ring. The sender has no option within SAP Integration Suite to select a specific key or subkey by Key ID for signing operations.
This behavior is observed in integration flows where a PGP private key containing a primary key and one or more signing subkeys is configured for the signing step.
Read more...
Environment
- SAP Integration Suite
- SAP Cloud Integration
Product
Keywords
PGP signing subkey, primary key, signature verification failed, OpenPGP, KeyFlag, key selection, CPI PGP sign, Integration Suite PGP, signing subkey verification, RFC 4880, public key ring, subkey signing, B2B signing , KBA , LOD-HCI-PI-CON-SOAP , SOAP Adapter , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview