Symptom
- mTLS handshake fails at client certificate verification stage .
- HAProxy log error: “SSL client CA chain cannot be verified”
- Client side error: “Certificate validation failed - unknown_ca”
- Client logs indicate multiple CAs supported by Load Balancer.
- Load balancer responds with HTTP 401 Unauthorized
Environment
SAP Traceability Hub
Cause
Root CA is missing in Custom Domain Manager trust store. This results in an incomplete certificate chain and failed SSL validation during mTLS.
Resolution
Maintain the complete certificate chain (Root + Intermediate + Client) in Custom Domain Manager.
Kindly note:
- Root CA must be uploaded correctly.
- Complete certificate chain is maintained.
Keywords
mTLS, HTTP 401, HAProxy, Root CA missing, SSL handshake failure, unknown_ca, certificate validation, Custom Domain Manager, client authentication , KBA , IS-LS-TH-OBT , SAP Traceability Hub Onboarding Issues , Problem
Product
SAP Traceability Hub all versions
SAP Knowledge Base Article - Public