SAP Knowledge Base Article - Preview

3788346 - SAP HANA Cloud: vector_embedding returns ssl certificate validation failed: peer not trusted (issuer: cn=pal-service-root)

Symptom

  • The VECTOR_EMBEDDING() function is not working in the SAP HANA Cloud instance.
  • Error message: "SSL certificate validation failed. Peer not trusted. Issuer: CN=pal-service-root." or "SSL certificate validation failed. Peer not trusted. Issuer: CN=hana-shared-services-cert-root."
(dberror) [403]: internal error: exception 337250: Embedding service returned the following error: exception 300015: SSL certificate validation failed: SSL error [536872221]: Unknown error, General error: 0x2000051d | SAPCRYPTOLIB | SSL_do_handshake
SSL API error
Failed to verify peer certificate. Peer not trusted.
0xa0600203 | SSL_ | tls13_handshake
Peer not trusted
0xa0600203 | SSL_ | tls13_msg_decode
Peer not trusted
0xa0600203 | SSL_ | ssl_verify_peer_certificates
Peer not trusted
0xa0600203 | SSL_ | ssl_cert_checker_verify_certificates
Peer not trusted
Certificate verification failed
0xa0600203 | SSL_ | ssl_cert_checker_verify_certificates
Peer not trusted
----- BEGIN VERIFICATION RESULT -----
 # --- Messages -----------
 ERROR: The verified certificate chain is complete but no certificate is trusted.
 # --- Summary -----------
 #01 Certificate (End Entity): VALID
  Subject:                      CN=pal-service
  Issuer:                       CN=pal-services-root
  Fingerprint (SHA256):         xx:xx:xx:xx;

or

(dberror) [403]: internal error: exception 337250: Embedding service returned the following error: exception 300015: SSL certificate validation failed: SSL error [536872221]: Unknown error, General error: 0x2000051d | SAPCRYPTOLIB | SSL_do_handshake
SSL API error
Failed to verify peer certificate. Peer not trusted.
0xa0600203 | SSL_ | tls13_handshake
Peer not trusted
0xa0600203 | SSL_ | tls13_msg_decode
Peer not trusted
0xa0600203 | SSL_ | ssl_verify_peer_certificates
Peer not trusted
0xa0600203 | SSL_ | ssl_cert_checker_verify_certificates
Peer not trusted
Certificate verification failed
0xa0600203 | SSL_ | ssl_cert_checker_verify_certificates
Peer not trusted
----- BEGIN VERIFICATION RESULT -----
 # --- Messages -----------
 ERROR: The verified certificate chain is complete but no certificate is trusted.
 # --- Summary -----------
 #01 Certificate (End Entity): VALID
  Subject:                      CN=pal-service
  Issuer:                       CN=hana-shared-services-cert-root
  Fingerprint (SHA256):         xx:xx:xx:xx;

or
(dberror) [129]: transaction rolled back by an internal error: isRegularFile(path= '/tmp/<instance ID-pod>/sec/hana-shared-services-client.pem', resolveLinks= true): Object not found (rc= 2, 'No such file or directory')


Read more...

Environment

  • Product: SAP HANA Cloud
  • HANA Cloud Services HANA Cloud 1.0

Product

SAP HANA Cloud 1.0

Keywords

vector_embedding, ssl certificate validation failed, peer not trusted, cn=pal-service-root, hana cloud, free tier, nlp service, natural language processing, embeddings, vector engine, btp cockpit, cli, certificate trust, digicert root g5, sys.certificates , KBA , HAN-CLS-HC , HANA Cloud Services HANA Cloud , HAN-DB-ENG-VEC , HANA Vector Engine , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.