<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPs connection from SAP WebAS in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005161#M1165324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't beg for points. I don't care for it. I am sorry, I don't feel retyping everything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Jan 2009 11:02:50 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-01-15T11:02:50Z</dc:date>
    <item>
      <title>HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005147#M1165310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to establish a connection from SAP WebAS to an iSaSiLk server via HTTPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The iSaSiLk authentication is based on client certificates. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created a SSL client PSE, generated the Certificate Request, imported the certificate response and the chain of certificates associated  with no errors. When testing the connection we're getting the following error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SAP icm log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Thr 1087400256] -&amp;gt;&amp;gt; SapSSLSessionInit(&amp;amp;sssl_hdl=0x2aaaba679980, role=1 (CLIENT), auth_type=3 (USE_CLIENT_CERT))&lt;/P&gt;&lt;P&gt;[Thr 1087400256] &amp;lt;&amp;lt;- SapSSLSessionInit()==SAP_O_K&lt;/P&gt;&lt;P&gt;[Thr 1087400256]      in: args = "role=1 (CLIENT), auth_type=3 (USE_CLIENT_CERT)"&lt;/P&gt;&lt;P&gt;[Thr 1087400256]     out: sssl_hdl = 0x1a3310c0&lt;/P&gt;&lt;P&gt;[Thr 1087400256] -&amp;gt;&amp;gt; SapSSLSetNiHdl(sssl_hdl=0x1a3310c0, ni_hdl=22)&lt;/P&gt;&lt;P&gt;[Thr 1087400256] NiIBlockMode: set blockmode for hdl 22 TRUE&lt;/P&gt;&lt;P&gt;[Thr 1087400256] &amp;lt;&amp;lt;- SapSSLSetNiHdl(sssl_hdl=0x1a3310c0, ni_hdl=22)==SAP_O_K&lt;/P&gt;&lt;P&gt;[Thr 1087400256] -&amp;gt;&amp;gt; SapSSLSetSessionCredential(sssl_hdl=0x1a3310c0, &amp;amp;cred_name=0x1a49e4e0)&lt;/P&gt;&lt;P&gt;[Thr 1087400256]   SapISSLComposeFilename(): Filename = "/usr/sap/XID/DVEBMGS00/sec/SAPSSLSPHTID.pse"&lt;/P&gt;&lt;P&gt;[Thr 1087400256] &amp;lt;&amp;lt;- SapSSLSetSessionCredential(sssl_hdl=0x1a3310c0)==SAP_O_K&lt;/P&gt;&lt;P&gt;[Thr 1087400256]      in: cred_name = "/usr/sap/XID/DVEBMGS00/sec/SAPSSLSPHTID.pse"&lt;/P&gt;&lt;P&gt;[Thr 1087400256] -&amp;gt;&amp;gt; SapSSLSetTargetHostname(sssl_hdl=0x1a3310c0, &amp;amp;hostname=0x1a4a09e0)&lt;/P&gt;&lt;P&gt;[Thr 1087400256] &amp;lt;&amp;lt;- SapSSLSetTargetHostname(sssl_hdl=0x1a3310c0)==SAP_O_K&lt;/P&gt;&lt;P&gt;[Thr 1087400256]      in: hostname = "&amp;lt;remoteServer_to_be_accessed&amp;gt;"&lt;/P&gt;&lt;P&gt;[Thr 1087400256] -&amp;gt;&amp;gt; SapSSLSessionStart(sssl_hdl=0x1a3310c0)&lt;/P&gt;&lt;P&gt;[Thr 1087400256]   SapISSLUseSessionCache(): Creating NEW session (0 cached)&lt;/P&gt;&lt;P&gt;[Thr 1087400256] Tue Jan 13 10:10:22 2009&lt;/P&gt;&lt;P&gt;*[Thr 1087400256] *** ERROR during SecudeSSL_SessionStart() from SSL_connect()==SSL_ERROR_SSL*&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[Thr 1087400256]    session uses PSE file "/usr/sap/XID/DVEBMGS00/sec/SAPSSLSPHTID.pse"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[Thr 1087400256] SecudeSSL_SessionStart: SSL_connect() failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;  &lt;STRONG&gt;secude_error 536871693 (0x2000030d) = "none of the PSEs registered with hSsl can suffice the negotiated SSL cipher suite"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[Thr 1087400256] &amp;gt;&amp;gt;            Begin of Secude-SSL Errorstack            &amp;gt;&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[Thr 1087400256] ERROR in ssl3_get_certificate_request: (536871693/0x2000030d) none of the PSEs registered with hSsl can suffice&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[Thr 1087400256] &amp;lt;&amp;lt;            End of Secude-SSL Errorstack&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[Thr 1087400256]   SSL_get_state() returned 0x00002150 "SSLv3 read server certificate request A"&lt;/P&gt;&lt;P&gt;[Thr 1087400256]   No certificate request received from Server&lt;/P&gt;&lt;P&gt;[Thr 1087400256] &amp;lt;&amp;lt;- ERROR: SapSSLSessionStart(sssl_hdl=0x1a3310c0)==SSSLERR_SSL_CONNECT&lt;/P&gt;&lt;P&gt;[Thr 1087400256] -&amp;gt;&amp;gt; SapSSLErrorName(rc=-57)&lt;/P&gt;&lt;P&gt;[Thr 1087400256] &amp;lt;&amp;lt;- SapSSLErrorName()==SSSLERR_SSL_CONNECT&lt;/P&gt;&lt;P&gt;[Thr 1087400256] *** ERROR =&amp;gt; IcmConnInitClientSSL: SapSSLSessionStart failed (-57): SSSLERR_SSL_CONNECT &lt;SPAN __jive_macro_name="0002168c"&gt;&lt;/SPAN&gt; [icxxconn_mt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the iSaSiLk server we're getting:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl_debug(2): Starting handshake (iSaSiLk 3.06)...&lt;/P&gt;&lt;P&gt;ssl_debug(2): Received v3 client_hello handshake message.&lt;/P&gt;&lt;P&gt;ssl_debug(2): Client requested SSL version 3.0, selecting version 3.0.&lt;/P&gt;&lt;P&gt;ssl_debug(2): Creating new session 11:5F:04:C9:0D:32:15:B9...&lt;/P&gt;&lt;P&gt;ssl_debug(2): CipherSuites supported by the client:&lt;/P&gt;&lt;P&gt;ssl_debug(2): SSL_RSA_WITH_RC4_128_SHA&lt;/P&gt;&lt;P&gt;ssl_debug(2): SSL_RSA_WITH_RC4_128_MD5&lt;/P&gt;&lt;P&gt;ssl_debug(2): SSL_RSA_WITH_3DES_EDE_CBC_SHA&lt;/P&gt;&lt;P&gt;ssl_debug(2): SSL_RSA_WITH_DES_CBC_SHA&lt;/P&gt;&lt;P&gt;ssl_debug(2): SSL_RSA_EXPORT_WITH_DES40_CBC_SHA&lt;/P&gt;&lt;P&gt;ssl_debug(2): SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5&lt;/P&gt;&lt;P&gt;ssl_debug(2): SSL_RSA_EXPORT_WITH_RC4_40_MD5&lt;/P&gt;&lt;P&gt;ssl_debug(2): CompressionMethods supported by the client:&lt;/P&gt;&lt;P&gt;ssl_debug(2): NULL&lt;/P&gt;&lt;P&gt;ssl_debug(2): Sending server_hello handshake message.&lt;/P&gt;&lt;P&gt;ssl_debug(2): Selecting CipherSuite: SSL_RSA_WITH_RC4_128_SHA&lt;/P&gt;&lt;P&gt;ssl_debug(2): Selecting CompressionMethod: NULL&lt;/P&gt;&lt;P&gt;ssl_debug(2): Sending certificate handshake message with server certificate...&lt;/P&gt;&lt;P&gt;ssl_debug(2): Sending certificate_request handshake message...&lt;/P&gt;&lt;P&gt;ssl_debug(2): Sending server_hello_done handshake message...&lt;/P&gt;&lt;P&gt;ssl_debug(2): IOException while handshaking: Connection closed by remote host.&lt;/P&gt;&lt;P&gt;ssl_debug(2): Sending alert: Alert Fatal: handshake failure&lt;/P&gt;&lt;P&gt;ssl_debug(2): Shutting down SSL layer...&lt;/P&gt;&lt;P&gt;ssl_debug(2): Closing transport...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the iSaSiLk everything seems to be OK, but on the SAP WebAS the error "none of the PSEs registered with hSsl can suffice the negotiated SSL cipher suite" is really unclear, since the cipher chosen by the iSaSiLk is one of the ciphers sent by SAP WebAS...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone give me any suggestion?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 11:49:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005147#M1165310</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T11:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005148#M1165311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SSL PSE certificates, with the abap stack, I always had to select RSA (and not DSA) for the cipher algorythm.&lt;/P&gt;&lt;P&gt;All the cipher suite problems I have had were always where I selected DSA by error in STRUST.&lt;/P&gt;&lt;P&gt;Maybe a check to do ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS : For my information, what is a iSaSiLk server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 11:58:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005148#M1165311</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T11:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005149#M1165312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;I've implemented note 800240 which facilitates the PSE analysis by implementing the report ZSSF_TEST_PSE. With this report I'm able to check all the PSE content, which are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Filename            SAPSSLSPHTID.pse&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PIN                 &amp;lt;no&amp;gt;&lt;/P&gt;&lt;P&gt;Signature           X&lt;/P&gt;&lt;P&gt;Encryption          X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Profile Parameter&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;DIR_INSTANCE                   /usr/sap/XID/DVEBMGS00                       /usr/sap/XID/D00&lt;/P&gt;&lt;P&gt;sec/dsakeylengthdefault                                                     1024&lt;/P&gt;&lt;P&gt;sec/libsapsecu                 /usr/sap/XID/SYS/exe/run/libsapcrypto.so&lt;/P&gt;&lt;P&gt;sec/rsakeylengthdefault                                                     1024&lt;/P&gt;&lt;P&gt;ssf/name                       SAPSECULIB&lt;/P&gt;&lt;P&gt;ssf/ssf_md_alg                                                              SHA1&lt;/P&gt;&lt;P&gt;ssf/ssf_symencr_alg                                                         DES-CBC&lt;/P&gt;&lt;P&gt;ssf/ssfapi_lib                 /usr/sap/XID/SYS/exe/run/libsapcrypto.so&lt;/P&gt;&lt;P&gt;ssf2/name&lt;/P&gt;&lt;P&gt;ssf2/ssf_md_alg                                                             SHA1&lt;/P&gt;&lt;P&gt;ssf2/ssf_symencr_alg                                                        DES-CBC&lt;/P&gt;&lt;P&gt;ssf2/ssfapi_lib&lt;/P&gt;&lt;P&gt;ssf3/name&lt;/P&gt;&lt;P&gt;ssf3/ssf_md_alg                                                             SHA1&lt;/P&gt;&lt;P&gt;ssf3/ssf_symencr_alg                                                        DES-CBC&lt;/P&gt;&lt;P&gt;ssf3/ssfapi_lib&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment variables&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;USER                xidadm&lt;/P&gt;&lt;P&gt;SECUDIR             /usr/sap/XID/DVEBMGS00/sec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PSE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Validity            18.12.2008 19:47:04   18.12.2009 19:47:04&lt;/P&gt;&lt;P&gt;Algorithm           RSA (OID 1.2.840.113549.1.1.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test signature&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Signature OK&lt;/P&gt;&lt;P&gt;Verification OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test encryption&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Encryption OK&lt;/P&gt;&lt;P&gt;Decryption OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see, the cipher algorithm used is RSA. Any suggestion... ?&lt;/P&gt;&lt;P&gt;An iSaSiLk server "is a Java programming language implementation of the SSLv2 (client-side), SSLv3, TLS 1.0 and TLS 1.1 protocols. It supports all defined cipher suites (except for Fortezza), including all AES and PSK cipher suites. iSaSiLk implements all standard TLS extensions, comes with an easy to use API and operates on top of the IAIK-JCE Javau2122 Cryptography Extension. iSaSiLk is highly configurable and will work with any alternative JCE implementation supported by a proper provider for supplying the required cryptographic algorithms".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again thanks for your answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 12:11:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005149#M1165312</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T12:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005150#M1165313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should also configure the SSL library (typically sap crypto lib). using the parameter ssl/ssl_lib. In addition, you have to make sure that the list of CA certificates trusted by the server includes the one you used for the client certificate generation (intermediate CA's are ok though).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Oliver has said: Only use RSA keys. AFAIK DSA is not supported by the SSL (TLS) protocol. Do not use the MD5 algorithm (this one has been broken badly).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 12:40:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005150#M1165313</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T12:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005151#M1165314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sietze,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Related to the SSL Libraries, we've implemented the parameters mentioned in SAP Note 510007 (Setting-up SSL on the Web Application Server ABAP):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssf/name = SAPSECULIB&lt;/P&gt;&lt;P&gt;ssf/ssfapi_lib  - /usr/sap/XID/SYS/exe/run/libsapcrypto.so&lt;/P&gt;&lt;P&gt;sec/libsapsecu  - /usr/sap/XID/SYS/exe/run/libsapcrypto.so&lt;/P&gt;&lt;P&gt;ssl/ssl_lib     - /usr/sap/XID/SYS/exe/run/libsapcrypto.so&lt;/P&gt;&lt;P&gt;icm/server_port_2 - PROT=HTTPS,PORT=1443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Relating to the CA certificates that was well remembered but all the certificates were included in the PSE including the certificate response. &lt;STRONG&gt;Does the certificate request needs to be placed on the certificate list?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you mention "Only use RSA keys. AFAIK DSA is not supported by the SSL (TLS) protocol. Do not use the MD5 algorithm (this one has been broken badly)." , have you seen anything on my description that suggested that I'm using DSA or the MD5 algorithm? Because from the PSE I've created, I've used RSA and not DSA, and SHA-1 and not MD5 but maybe I'm missing something.... All of your suggestions are welcomed &lt;SPAN __jive_emoticon_name="grin"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 13:09:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005151#M1165314</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T13:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005152#M1165315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, the certificate request does not need to put in the PSE (and you won't be able to do this). It is generated based on the contents of the PSE. The response contains the certificate, so you have to import the response. You should also include the root certificate from your PKI in the list of trusted certificates. Did you do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding RSA and SHA-1: No, I just want to make sure you don't do this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 14:05:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005152#M1165315</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T14:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005153#M1165316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gonçalo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have implemented the ZSSF_TEST_PSE report in my CRM 2007 test system and I get a nearly identical result from it. I also get the RSA cipher algorythm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you check your SSL &lt;STRONG&gt;client&lt;/STRONG&gt; certificate with the report ? Filename SAPSSLSPHTID.pse seems to me to be a SSL &lt;STRONG&gt;server&lt;/STRONG&gt;  certificate....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This client certificate should include the CA list of the servers you want to connect to.&lt;/P&gt;&lt;P&gt;But your error message is not about CA...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your client certificate uses also RSA, I'm out of ideas for your problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 14:30:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005153#M1165316</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T14:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005154#M1165317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sietze,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, all the certificates were included without the certificate request When you mentioned the certificate request I thougt "Nice, that's it :)" . &lt;/P&gt;&lt;P&gt;Once again, thanks for your answer!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 17:18:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005154#M1165317</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T17:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005155#M1165318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the result is from my client certificate. The name SAPSSLSPHTTID means SaphetyID, that's why the 'S' may lead to confusion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My error is strangely related to the cipherSuite, but both use RSA and on the iSaSiLk server response it seems everything is OK with the cipher...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like you said, I'm running out of ideas...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jan 2009 17:29:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005155#M1165318</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-13T17:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005156#M1165319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gonçalo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then the last trial to do is to open an OSS message and hope that it will not be considered as consulting...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jan 2009 12:37:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005156#M1165319</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-14T12:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005157#M1165320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Done that but still waiting for a reply.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your suggestions, p  o i n t  a w a r d e d to you and Sietze... (not the maximum 10 but maybe you can still remember something... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;  )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Julius Bussche on Jan 15, 2009 11:31 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jan 2009 22:44:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005157#M1165320</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-14T22:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005158#M1165321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I can't answer you. When I try, I get the phrase: "We are sorry but your message can not be posted since you have used forbidden words/phrases. Please edit your post according to the forum guidelines and re-post." but I don't know why.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 09:22:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005158#M1165321</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-15T09:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005159#M1165322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE level="1"&gt;&lt;/BLOCKQUOTE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Hello Olivier,&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; Done that but still waiting for a reply.... &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; Thanks for your suggestions, point awarded to you and Sietze... (not the maximum 10 but maybe you can still remember something... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;  )&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind advice: add a reference (URL) to this SDN thread - it might help to speed-up processing ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 10:29:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005159#M1165322</guid>
      <dc:creator>Wolfgang_Janzen</dc:creator>
      <dc:date>2009-01-15T10:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005160#M1165323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; but I don't know why.&lt;/P&gt;&lt;P&gt;Content filters against points begging. Legacy problem... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I fixed it with a work-around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 10:33:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005160#M1165323</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-15T10:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005161#M1165324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't beg for points. I don't care for it. I am sorry, I don't feel retyping everything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 11:02:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005161#M1165324</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-15T11:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPs connection from SAP WebAS</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005162#M1165325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know, but the content filters let the original post through for some reason, and when you tried to quote it combined with some word you used, it blocked your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The system filters for "p o i n t s" combined with "a w a r d e d".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The content filters are usefull, but also cause some silly hassles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry about that,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 11:07:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/https-connection-from-sap-webas/m-p/5005162#M1165325</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-15T11:07:34Z</dc:date>
    </item>
  </channel>
</rss>

