SAP Knowledge Base Article - Preview

3781785 - Difference between the Solr SAML certificate and the SSL certificate on the Solr endpoint, and their renewal cycles

Symptom

Confusion arises when the expiry dates of the Solr certificates are compared, because the Solr endpoint depends on two different certificates that are frequently treated as one. The user inspecting the certificates finds two separate expiry dates and two different renewal behaviors, which gives the false impression that a single certificate is being renewed on an inconsistent or unexpectedly short cycle, for example every few months rather than yearly.

The practical trigger for this confusion is often an authentication outage on the Solr endpoint. When the Solr SAML certificate expires, the endpoint becomes inaccessible and returns an Identity Provider authentication error. During the follow up, the SSL certificate of the endpoint is inspected as well, its unrelated expiry date is noted, and the two dates are then compared as if they described the same certificate.


Read more...

Environment

SAP Commerce Cloud

Product

SAP Commerce Cloud all versions

Keywords

SAP Commerce Cloud, Solr, Solr SAML certificate, SAML certificate, SSL certificate, default SSL certificate, custom SSL certificate, TLS certificate, Solr endpoint, Solr admin, certificate difference, two certificates, certificate expiration, certificate renewal, certificate validity, renewal cycle, yearly renewal, automatic renewal, recreate deployment, offline deployment, rolling deployment, backend process, Identity Provider, HTTPS certificate , KBA , CEC-SCC-COM-SRC-SER , Search and Navigation , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.