Symptom
AS2 messages are shown as Error with Status Description indicating a negative MDN response
Environment
SAP Traceability Hub
Cause
The trading partner returned a negative MDN with the error authentication-failed because the message signature could not be authenticated.
This occurs when there is an MLS certificate mismatch between SAP Traceability Hub/CPI and the trading partner system. The certificate configured for signing the AS2 message does not match the certificate maintained by the receiver for signature verification.
As a result, the receiver rejects the message and returns a negative MDN with the disposition authentication-failed.
Resolution
- Verify the MLS/signing certificate configured in SAP Traceability Hub/CPI.
- Confirm that the same certificate is registered and active on the trading partner side.
- Review certificate validity and ensure the certificate has not expired.
- Update the certificate configuration if a certificate renewal or rotation has taken place.
- Reprocess the message after synchronizing the certificate configuration between both systems.
Keywords
AS2 Message Failed, Negative MDN, authentication-failed, MLS Certificate Mismatch, Certificate Verification Error, Digital Signature Validation, Supply Chain Partner Collaboration, U.S. Transaction Exchange, SAP Traceability Hub , KBA , IS-LS-ICH-NET-CER , SAP ICH Message Exchange Issues Certificates , Problem
SAP Knowledge Base Article - Public