SAP Knowledge Base Article - Public

3770084 - 401 Authentication Error in Load Balancer.

Symptom

  • mTLS handshake fails at client certificate verification stage . 
  • HAProxy log error: “SSL client CA chain cannot be verified”
  • Client side error: “Certificate validation failed - unknown_ca”
  • Client logs indicate multiple CAs supported by Load Balancer.
  • Load balancer responds with HTTP 401 Unauthorized

Environment

SAP Traceability Hub

Cause

Root CA is missing in Custom Domain Manager trust store. This results in an incomplete certificate chain and failed SSL validation during mTLS.

Resolution

Maintain the complete certificate chain (Root + Intermediate + Client) in Custom Domain Manager. 

Kindly note:

  • Root CA must be uploaded correctly.
  • Complete certificate chain is maintained.

Keywords

mTLS, HTTP 401, HAProxy, Root CA missing, SSL handshake failure, unknown_ca, certificate validation, Custom Domain Manager, client authentication , KBA , IS-LS-TH-OBT , SAP Traceability Hub Onboarding Issues , Problem

Product

SAP Traceability Hub all versions