Posts

Showing posts with the label keystore

Strict Hostname Checking

Image
The default setting in SAP doesn't make a strict hostname check when executing an SSL handshake. Depending on your security audit requirements you may have to change this behaviour. You can set messaging.ssl.serverNameCheck to true in SAP XI AF Messaging service to ensure that SSL handshake succeeds only in the hostname of the server matches the CN of the public certificate.

Visual Admin Doesn't Open KeyStore

Copy the iaik_jce.jar or iaik_jce_export.jar from the SCS Instance \\<HOST>\SAPMNT\<SID>\SYS\global\security\lib\tools\iaik_jce.jar to your CI \usr\sap\<SID>\JC<Inst. Nr.>\j2ee\admin\lib

Unable to Delete Old Certificate Entries from Key Storage

If deletion of an old/unused certificate from TrustedCAs errors out saying "Entry [cert_name] from view [TrustedCAs] is not deleted - respective security resource was not deleted": 1. Export the TrustedCAs view to Filesystem(*.view file) and import it back as a test view (Ex: TrustedTest). 2. Delete the old/unused entries from the new view(TrustedTest). 3. Export the new view(TrustedTest) to Filesystem(*.view file). 4. Delete the view TrustedCAs and restart the application. 5. During the restart the "TrustedCAs" view will be recreated and the default certificates will also be regenerated. 6. Import the file that was created in step 3. If the certificates deletion problem is with a custom view follow steps 1, 2, 3 and delete the custom view. Create the view with same name again and reimport the view file created in step 3.

SAP XI: XIAFUSER user is not configured

Communication Channel errors with a message similar to: Sender Agreement: [sender agreement name] Security Settings > Partner certificate configured for signing: ERROR: XIAFUSER user is not configured for keystore [keystore view name] Change KEYSTORE_USER_NAME parameter in SAP XI Industry Speak Service to XIAFUSER. Make the changes on all server nodes. The Channel will be red until the next message is processed through it.