SAP Knowledge Base Article - Preview

3767904 - Cloud Integration - PGP signature verification fails because signing subkey is used instead of primary key

Symptom

When using the PGP signing step in SAP Cloud Integration, the signature is created using a signing subkey rather than the primary key of the PGP key pair. The receiving party reports that signature verification fails when they attempt to verify using the primary key from the shared public key ring.

On closer inspection, verification succeeds only when the receiving party uses the subkey from the public key ring. The sender has no option within SAP Integration Suite to select a specific key or subkey by Key ID for signing operations.

This behavior is observed in integration flows where a PGP private key containing a primary key and one or more signing subkeys is configured for the signing step.


Read more...

Environment

  • SAP Integration Suite
  • SAP Cloud Integration

Product

Cloud Integration 4.0 ; SAP Integration Suite 1.0

Keywords

PGP signing subkey, primary key, signature verification failed, OpenPGP, KeyFlag, key selection, CPI PGP sign, Integration Suite PGP, signing subkey verification, RFC 4880, public key ring, subkey signing, B2B signing , KBA , LOD-HCI-PI-CON-SOAP , SOAP Adapter , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.