Symptom
Confusion arises when the expiry dates of the Solr certificates are compared, because the Solr endpoint depends on two different certificates that are frequently treated as one. The user inspecting the certificates finds two separate expiry dates and two different renewal behaviors, which gives the false impression that a single certificate is being renewed on an inconsistent or unexpectedly short cycle, for example every few months rather than yearly.
The practical trigger for this confusion is often an authentication outage on the Solr endpoint. When the Solr SAML certificate expires, the endpoint becomes inaccessible and returns an Identity Provider authentication error. During the follow up, the SSL certificate of the endpoint is inspected as well, its unrelated expiry date is noted, and the two dates are then compared as if they described the same certificate.
Read more...
Environment
SAP Commerce Cloud
Product
Keywords
SAP Commerce Cloud, Solr, Solr SAML certificate, SAML certificate, SSL certificate, default SSL certificate, custom SSL certificate, TLS certificate, Solr endpoint, Solr admin, certificate difference, two certificates, certificate expiration, certificate renewal, certificate validity, renewal cycle, yearly renewal, automatic renewal, recreate deployment, offline deployment, rolling deployment, backend process, Identity Provider, HTTPS certificate , KBA , CEC-SCC-COM-SRC-SER , Search and Navigation , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview