SAP Knowledge Base Article - Preview

3800498 - Internal Server Error during SAP HANA Cockpit 2.0 logon - UAA token exchange fails with "tunneling socket could not be established, statusCode=403"

Symptom

  • Internal Server Error occurs after entering COCKPIT_ADMIN credentials and selecting Log On.
  • Login fails during OAuth token exchange with XSA UAA.
  • Error message (or similar) seen in cockpit-web-app.log: "Could not authenticate with UAA: Could not obtain access token ... tunneling socket could not be established, statusCode=403."
  • The issue may become visible after a restart of the SAP HANA / XS Advanced host or after the affected Cockpit applications are restarted or recreated.
  • SAP HANA and XS Advanced services are running.
  • The Cockpit login page itself is reachable.
  • A direct curl request from the operating system to the UAA endpoint succeeds.


Read more...

Environment

SAP HANA Cockpit 2.0

SAP HANA XS Advanced

Product

SAP HANA, platform edition all versions

Keywords

internal server error, cockpit login, uaa, oauth token, 403, tunneling socket, proxy, http_proxy, https_proxy, xs set-env, cockpit-web-app, cockpit-admin-web-app, cockpit-adminui-svc, cockpit-landscape-svc, token exchange , KBA , HAN-CPT-CPT2 , SAP HANA Cockpit version 2 - based on XSA , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.