<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: SAP SSL handshake failed in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634309#M158078</link>
    <description>&lt;P&gt;That was just a guess with the cipher suite, maybe not the best &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
  &lt;P&gt;One more question - did you import to STRUST the full certification path? I mean also the certificate of the CA that signed the certificate for the website. &lt;/P&gt;</description>
    <pubDate>Wed, 11 Apr 2018 16:45:15 GMT</pubDate>
    <dc:creator>BJarkowski</dc:creator>
    <dc:date>2018-04-11T16:45:15Z</dc:date>
    <item>
      <title>SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaq-p/634302</link>
      <description>&lt;P&gt;I'm trying to retrieve data from an open data api. I have downloaded the certificate from the site and imported it into STRUST (SSL Client Anonymous). Then I created a HTTP connection to external server in SM59. In the beginning it worked fine, until last week when the api changed its URL and so its DNS. Ofcourse it could no longer be reached by the current host. So I did above steps again for the new URL (changed everything accordingly like hostname etc. in SM59), but this time I receive following error: SSL handshake with 'hostname:port' failed: SSSLERR_CONN_CLOSED (-10)#Remote Peer has closed the network connection##SapSSLSessionStartNB()==SSSLERR_CONN_C LOSED##&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Anyone has an idea on how to solve this?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 13:45:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaq-p/634302</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-03T13:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634303#M158072</link>
      <description>&lt;P&gt;Hello Sven,&lt;/P&gt;
  &lt;P&gt;Have you imported the new SSL server certificate to the anonymous PSE (STRUST)?&lt;/P&gt;
  &lt;P&gt;And is the SM59 still configured to use the anonymous PSE too (under the "technical settings" tab)?&lt;/P&gt;
  &lt;P&gt;Did anything else change at the remote website? Like, now the website requires authentication using a client certificate?&lt;/P&gt;
  &lt;P&gt;Simulating the issue with the ICM running on trace level 2 and providing the trace might help us to identify other possibilities.&lt;/P&gt;
  &lt;P&gt;Regards,&lt;/P&gt;
  &lt;P&gt;Isaías&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 22:40:30 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634303#M158072</guid>
      <dc:creator>Isaias_SAP</dc:creator>
      <dc:date>2018-04-06T22:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634304#M158073</link>
      <description>&lt;P&gt;Hello Isaias&lt;BR /&gt;&lt;BR /&gt;Yes I imported the new SSL server certificate to the anonymous PSE. In SM59 I configured everything correctly. I've been looking into it the past days and I think that the new remote site requests a key of the certificate which isn't provided. I came to this conclusion because at the moment without key it is even impossible to send a request to the site via Postman. I'm gonna try and generate a key via the command prompt and see if I can reach retrieve a request via Postman.&lt;BR /&gt;&lt;BR /&gt;Let me know if you have any other ideas that I could try.&lt;/P&gt;
  &lt;P&gt;&lt;BR /&gt;&lt;/P&gt;
  &lt;P&gt;Kind reagrds&lt;/P&gt;
  &lt;P&gt;Sven Swennen&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2018 13:46:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634304#M158073</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-10T13:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634305#M158074</link>
      <description>&lt;P&gt;Hello Sven,&lt;/P&gt;
  &lt;P&gt;A level 2 trace of the ICM could help us verifying whether we can suggest anything else.&lt;/P&gt;
  &lt;P&gt;You can increase its trace level through the transaction SMICM, then perform a "connection test" at SM59 and reduce the trace level as soon as the issue is simulated.&lt;/P&gt;
  &lt;P&gt;Besides attaching the trace file to this thread, we would need the name of the target server.&lt;/P&gt;
  &lt;P&gt;Kind regards,&lt;/P&gt;
  &lt;P&gt;Isaías&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2018 20:17:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634305#M158074</guid>
      <dc:creator>Isaias_SAP</dc:creator>
      <dc:date>2018-04-10T20:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634306#M158075</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Only thing the trace is outputting at level 1 is the Remote peer has closed the network connection.&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;So not really helpful. &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;The traces at higher levels don't output any errors.&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Seems like it is an issue with the certificate. But I don't know how to solve it.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/128831-capture.png" /&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Kind regards&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Sven &lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 08:52:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634306#M158075</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-11T08:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634307#M158076</link>
      <description>&lt;P&gt;Can you connect to the target host through browser? &lt;/P&gt;
  &lt;P&gt;I would also check the SSL config on the target (for example using it: &lt;A href="https://www.ssllabs.com/ssltest/)" target="test_blank"&gt;https://www.ssllabs.com/ssltest/)&lt;/A&gt;.&lt;/P&gt;
  &lt;P&gt;This might also be a cipher issue - maybe you need to enable other cipher suite on AS.&lt;/P&gt;
  &lt;P&gt;Check SAP Note 2570499 - How to adjust the supported SSL cipher suites in AS ABAP&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 08:59:41 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634307#M158076</guid>
      <dc:creator>BJarkowski</dc:creator>
      <dc:date>2018-04-11T08:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634308#M158077</link>
      <description>&lt;P&gt;Thanks for the response&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Yes I can connect to the target host via browser.&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Could you explain what you mean by other cipher suite? and how I can know if I need another one? I'm not familiar with certificates so I don't really get what you mean.&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;But if it has anything to do with following:&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/128834-capture.png" /&gt;&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;I can tell you that it is the same as another certificate which is working at the moment.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;UPDATE:&lt;/P&gt;
  &lt;P&gt;Could it be that this is the problem? the other certificate that works at the moment has this enabled.&lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/128836-capture.png" /&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Kind regards&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Sven &lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 09:48:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634308#M158077</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-11T09:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634309#M158078</link>
      <description>&lt;P&gt;That was just a guess with the cipher suite, maybe not the best &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
  &lt;P&gt;One more question - did you import to STRUST the full certification path? I mean also the certificate of the CA that signed the certificate for the website. &lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 16:45:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634309#M158078</guid>
      <dc:creator>BJarkowski</dc:creator>
      <dc:date>2018-04-11T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634310#M158079</link>
      <description>&lt;P&gt;Hello Sven,&lt;/P&gt;
  &lt;P&gt;The trace says "Failed to verify peer certificate. Peer not trusted".&lt;/P&gt;
  &lt;P&gt;This would mean that SAP does not trust the certificate it received from the remote server.&lt;/P&gt;
  &lt;P&gt;You would need to either import the certificate itself, or import the certificate of the "issuer" (the CA - Certification Authority - that signed the certificate).&lt;/P&gt;
  &lt;P&gt;The screenshot does not show whether the client or anonymous PSE ("SAPSSLC.pse" and "SAPSSLA.pse", by default) was in use. So, maybe import the certificate at both, to be on the safe side, as this would not cause any issues.&lt;/P&gt;
  &lt;P&gt;&lt;A href="https://wiki.scn.sap.com/wiki/x/6BliGg" target="_blank"&gt;This wiki page&lt;/A&gt; might help.&lt;/P&gt;
  &lt;P&gt;Kind regards,&lt;/P&gt;
  &lt;P&gt;Isaías&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 21:46:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634310#M158079</guid>
      <dc:creator>Isaias_SAP</dc:creator>
      <dc:date>2018-04-11T21:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634311#M158080</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;The screenshot doesn't show it but I'm certain the anonymous PSE is used. To be sure I also imported it all in standard but without success. Since I'm really stuck I'll provide the link from where I'm trying to get data: &lt;A href="https://public.brussels-parking-guidance.com/Datex/Export?publication=dynamic" target="test_blank"&gt;https://public.brussels-parking-guidance.com/Datex/Export?publication=dynamic&lt;/A&gt; . &lt;BR /&gt;I'm not to familiar with certificates so for you question of the CA certificate I tried following: I downloaded all the certificates of the site (DST Root, The X3 and the one of the site itself, see screenshot). Then I added them to STRUST by importing them. &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/127951-capture.png" /&gt;&lt;/P&gt;
  &lt;P&gt;Afterwards I created a new HTTP connection to external server in SM59 and filled in all the required fields as host I put &lt;A href="http://public.brussels-parking-guidance.com/"&gt;public.brussels-parking-guidance.com&lt;/A&gt; and path prefix /Datex/Export?publication=dynamic. By logon &amp;amp; security I activated SSL certificate and put it on anonymous (I also configured the proxy correct). But for some reason it is not trusting the certificate.&lt;/P&gt;
  &lt;P&gt;Is this the correct way?&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Kind reagrds&lt;BR /&gt;Sven&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 07:38:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634311#M158080</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-12T07:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634312#M158081</link>
      <description>&lt;P&gt;I'm not familiar with certificates so since I'm really stuck I'll let you know what I did. I need to get data of following site: &lt;A href="https://public.brussels-parking-guidance.com/Datex/Export?publication=dynamic"&gt;https://public.brussels-parking-guidance.com/Datex/Export?publication=dynamic&lt;/A&gt; . I downloaded following certificates of the site (DST, X3 and the one of the site itself).&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/attachments/127955-capture.png" /&gt;&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;I imported all these certificates into STRUST in the anonymous and standard PSE. Afterwards I created a new HTTP connection to external server in SM59 and filled in all the required fields as host I put public.brussels-parking-guidance.com and path prefix /Datex/Export?publication=dynamic. By logon &amp;amp; security I activated SSL certificate and put it on anonymous (I also configured the proxy correct). But for some reason it is not trusting the certificate.&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Is this the correct way to do it?&lt;/P&gt;
  &lt;P&gt;EDIT: if you want also check above response, I added a level 2ICM trace file there if it helps.&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Kind reagerds&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Sven Swennen&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 07:55:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634312#M158081</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-12T07:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634313#M158082</link>
      <description>&lt;P&gt;Hello Sven,&lt;/P&gt;
  &lt;P&gt;For the purposes of SSL trust, importing the certificate of "Let's Encrypt Authority X3" would suffice, but it would be recommended to import the "DST Root CA X3" too. &lt;/P&gt;
  &lt;P&gt;There is no need to import the last one ("public.brussels-parking-guidance.om").&lt;/P&gt;
  &lt;P&gt;Based on the SM59 settings you have mentioned (which seem correct), you would need to import those two certificates at the Anonymous PSE file.&lt;/P&gt;
  &lt;P&gt;To confirm that everything is correct with it, logon at operating system level as "SIDadm" and execute the following command:&lt;/P&gt;
  &lt;PRE&gt;&lt;CODE&gt;sapgenpse maintain_pk -l -p &amp;lt;path to anonymous PSE - SAPSSLA.pse&amp;gt;&lt;/CODE&gt;&lt;/PRE&gt;
  &lt;P&gt;You should see the "DST Root" and the other "X3" certificates listed at the output.&lt;/P&gt;
  &lt;P&gt;If you see them there, try restarting the ICM (transaction SMICM, menu Administration -&amp;gt; ICM -&amp;gt; Exit Soft/Hard -&amp;gt; Local).&lt;/P&gt;
  &lt;P&gt;Depending on the SAP NetWeaver release in use, restarting the ICM manually would be required, so it reloads the PSE files.&lt;/P&gt;
  &lt;P&gt;Regards,&lt;/P&gt;
  &lt;P&gt;Isaías&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:46:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634313#M158082</guid>
      <dc:creator>Isaias_SAP</dc:creator>
      <dc:date>2018-04-12T12:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634314#M158083</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Did it all except for the operating system level (I have no authorization to do this).&lt;/P&gt;
  &lt;P&gt;Unfortunately still having the same error. It's starting to look like this one just isn't going to work.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Thanks for all the help, if you got any other ideas feel free to still share them so I can test them :).&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Kind regards&lt;/P&gt;
  &lt;P&gt;Sven Swennen&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:18:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634314#M158083</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-12T13:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634315#M158084</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
  &lt;P&gt;Can you provide the complete "dev_icm" trace file?&lt;/P&gt;
  &lt;P&gt;Kind regards,&lt;/P&gt;
  &lt;P&gt;Isaías&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:52:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634315#M158084</guid>
      <dc:creator>Isaias_SAP</dc:creator>
      <dc:date>2018-04-12T13:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634316#M158085</link>
      <description>&lt;P&gt;Hi Isaias,&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;I tried to replicate the issue and I also encounter it.&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;Here my smicm logs (level 3)&lt;/P&gt; 
  &lt;PRE&gt;&lt;CODE&gt;[Thr 140608096933632] Thu Apr 12 14:05:07:547 2018
[Thr 140608096933632]      in: cred_hdl = 7fe1d405c670
[Thr 140608096933632] -&amp;gt;&amp;gt; SapSSLSetTargetHostname(sssl_hdl=7fe1a8001690, &amp;amp;hostname=7fe1a8001500)
[Thr 140608096933632] &amp;lt;&amp;lt;- SapSSLSetTargetHostname(sssl_hdl=7fe1a8001690)==SAP_O_K
[Thr 140608096933632]      in: hostname = "public.brussels-parking-guidance.com"
[Thr 140608096933632] -&amp;gt;&amp;gt; SapSSLSessionStartNB(sssl_hdl=7fe1a8001690, flags=00000000, timeout=80000, &amp;amp;IOstat=7fe1dfab7f30)
[Thr 140608096933632] NiIBlockMode: leave blockmode for hdl 96 FALSE
[Thr 140608096933632] NiIHdlGetStatus: hdl 96/sock 31 ok, no data pending
[Thr 140608096933632]   SapISSLUseSessionCache(): Creating NEW session (0 cached)
[Thr 140608096933632] CCL[SSL]: Cli-0000000C: Have no session to be resumed. Performing full handshake [ssl3_client_hello]
[Thr 140608096933632] CCL[SSL]: Cli-0000000C: ClientHello: Offering protocol version 3.1 (TLSv1.0) [ssl3_get_client_hello_version]
[Thr 140608096933632] CCL[SSL]: Cli-0000000C: ClientHello: no session resumption requested (empty session ID) [ssl3_client_hello]
[Thr 140608096933632] CCL[SSL]: Cli-0000000C: Summary: Offering 6 cipher suite(s) and SCSV(s):
[Thr 140608096933632]     &amp;lt; 0&amp;gt; : TLS_RSA_WITH_AES128_CBC_SHA
[Thr 140608096933632]     &amp;lt; 1&amp;gt; : TLS_RSA_WITH_AES256_CBC_SHA
[Thr 140608096933632]     &amp;lt; 2&amp;gt; : TLS_RSA_WITH_3DES_EDE_CBC_SHA
[Thr 140608096933632]     &amp;lt; 3&amp;gt; : TLS_RSA_WITH_RC4_128_SHA
[Thr 140608096933632]     &amp;lt; 4&amp;gt; : TLS_RSA_WITH_RC4_128_MD5
[Thr 140608096933632]     &amp;lt; 5&amp;gt; : Signaling cipher suite value (SCSV) secure renegotiation (RFC5746)
[Thr 140608096933632]  [ssl_cipher_suites_to_bytes]
[Thr 140608096933632] CCL[SSL]: Cli-0000000C: Sending SSLv3/TLS ClientHello [ssl3_client_hello]
[Thr 140608096933632]   SSL:SiSend(sock=  31)== 0 (SI_OK)       (out=60 of 60)
[Thr 140608096933632]   SSL:SiRecv(sock=  31)==13 (SI_ETIMEOUT) (in=0, max=16)
[Thr 140608096933632]     &amp;gt; SSL:SiPoll(sock=31, evt=R, timeout=80000 ms)
[Thr 140608096933632]   &amp;lt;   SSL:SiPoll(sock=31, evt=R, slept  =  19 ms) Ready
[Thr 140608096933632]   SSL:SiRecv(sock=  31)==12 (SI_ECONN_BROKEN) (in=0, max=16)
[Thr 140608096933632]   SSL_get_state()==0x2120 "TLS read server hello A"
[Thr 140608096933632]   SSLSessionStart: new SSL session (TLSv1.0) no CertRequest
[Thr 140608096933632]   Stop! Required server certificate not present
[Thr 140608096933632] &amp;lt;&amp;lt;- SapSSLSessionStartNB(sssl_hdl=7fe1a8001690)==SSSLERR_CONN_CLOSED
[Thr 140608096933632] -&amp;gt;&amp;gt; SapSSLSessionLastError(sssl_hdl=7fe1a8001690, &amp;amp;rc=7fe1dfab7f20, &amp;amp;rc_name=7fe1dfab7f40, &amp;amp;rc_desc=7fe1dfab7f50, &amp;amp;rc_detail=7fe1dfab7f60)
[Thr 140608096933632] DpSesGetWorkerType: return workerType DIA for T6_U108
[Thr 140608096933632] RqQQueueGetNumberOfRequests: Queue &amp;lt;T6_U108_M0&amp;gt; in slot 45 contains 0 requests of type DIA
[Thr 140608096933632] DpSesGetTasks: found 0 open tasks for T6_U108_M0
[Thr 140608096933632] DpSesGetWorkerType: return workerType DIA for T6_U108
[Thr 140608096933632] RqQQueueGetNumberOfRequests: Queue &amp;lt;T6_U108_M1&amp;gt; in slot 41 contains 0 requests of type DIA
[Thr 140608096933632] DpSesGetTasks: found 1 open tasks for T6_U108_M1
[Thr 140608096933632] *** ERROR =&amp;gt; SSL handshake with public.brussels-parking-guidance.com:443 failed: SSSLERR_CONN_CLOSED (-10)
[Thr 140608096933632] Remote Peer has closed the network connection&amp;lt;br&amp;gt;&lt;/CODE&gt;&lt;/PRE&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;I thought it may be related to SSL/TLS version, so I checked it with profile parameter&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;ssl/client_ciphersuites = 208:HIGH:MEDIUM&lt;/P&gt;
  &lt;P&gt; &lt;/P&gt;
  &lt;P&gt;But it didn't change anything. Sorry for interrupting in your answer, but I hope this will help to solve Sven issue.&lt;/P&gt;
  &lt;P&gt;BTW. I'm 99,99% sure my config is correct - I added all certs, restarted ICM etc. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 14:10:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634316#M158085</guid>
      <dc:creator>BJarkowski</dc:creator>
      <dc:date>2018-04-12T14:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634317#M158086</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;This is the end of the level 2 ICM trace.&lt;/P&gt;
  &lt;P&gt;Let me know if this is what you wanted to see (I couldn't upload the whole file since it is 30MB and SCN only allows 1MB)?&lt;/P&gt;
  &lt;P&gt;&lt;A href="https://answers.sap.com/storage/temp/128015-icm-end.txt"&gt;icm-end.txt&lt;/A&gt;&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Kind reagrds&lt;/P&gt;
  &lt;P&gt;Sven Swennen&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 14:41:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634317#M158086</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-12T14:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634318#M158087</link>
      <description>&lt;P&gt;Hi Sven,&lt;/P&gt;
  &lt;P&gt;Interesting question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; had me googling and I have got it to bypass the error SSSLERR_CONN_C LOSED message.&lt;/P&gt;
  &lt;P&gt;By setting the parameter mentioned in this note to true on my NPL demo system 751&lt;/P&gt;
  &lt;P&gt;2124480 - ICM / Web Dispatcher: TLS Extension Server Name Indication (SNI) as client&lt;/P&gt;
  &lt;P&gt;&lt;EM&gt;"To enabled SNI seticm/HTTPS/client_sni_enabled to "true". This parameter is dynamic."&lt;/EM&gt;&lt;/P&gt;
  &lt;P&gt;If your interested &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; my googling was a result of trying and failing with openssl client connections ( to see another non browser connection.)&lt;/P&gt;
  &lt;P&gt;The errors in this connection led me to these &lt;A href="https://security.stackexchange.com/questions/101965/ssl3-error-when-requesting-connection-using-tls-1-2/102018#102018"&gt;links&lt;/A&gt; which mentioned&lt;A href="https://en.wikipedia.org/wiki/Server_Name_Indication"&gt; Server Name Indication&lt;/A&gt; (SNI) as a way of using more certificates on one IP address. Which must be the case for "&lt;A href="http://public.brussels-parking-guidance.om/"&gt;public.brussels-parking-guidance.om&lt;/A&gt;" and the SAP parameter is required.&lt;/P&gt;
  &lt;P&gt;Hope it helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
  &lt;P&gt;Cheers&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Robert&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 20:51:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634318#M158087</guid>
      <dc:creator>Robert_Russell1</dc:creator>
      <dc:date>2018-04-12T20:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634319#M158088</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
  &lt;P&gt;I could simulate the issue using an internal test system.&lt;/P&gt;
  &lt;P&gt;I was discussing this case with a BC-SEC-SSL colleague, and then I saw Robert's update.&lt;/P&gt;
  &lt;P&gt;I performed some tests and it worked for me. Thus, setting "icm/HTTPS/client_sni_enabled = TRUE" should be the solution.&lt;/P&gt;
  &lt;P&gt;Thank you, Robert! Well done :-).&lt;/P&gt;
  &lt;P&gt;Regards,&lt;/P&gt;
  &lt;P&gt;Isaías&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Notify: &lt;SPAN class="mention-scrubbed"&gt;db8ac33b71d34a778adf273b064c4883&lt;/SPAN&gt; , &lt;SPAN class="mention-scrubbed"&gt;svenswennen&lt;/SPAN&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 21:30:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634319#M158088</guid>
      <dc:creator>Isaias_SAP</dc:creator>
      <dc:date>2018-04-12T21:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634320#M158089</link>
      <description>&lt;P&gt;Wow! Congrats Rob!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 21:45:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634320#M158089</guid>
      <dc:creator>BJarkowski</dc:creator>
      <dc:date>2018-04-12T21:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SSL handshake failed</title>
      <link>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634321#M158090</link>
      <description>&lt;P&gt;Hello Robert&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Thanks for the answer. I'm new to SAP and I want to verify if I'm going to do this correctly. For this paramater am I correct that I have to go to RZ10, fill in the profile I'm using and then create this parameter (because I don't see the parameter in any of the profiles)?&lt;/P&gt;
  &lt;P&gt;Or am i completely incorrect and is "icm/HTTPS/client_sni_enabled = TRUE" found somewhere else? I tried googling it but it only says what it is and does but not where to modify it.&lt;/P&gt;
  &lt;P&gt;&lt;/P&gt;
  &lt;P&gt;Kind regards&lt;/P&gt;
  &lt;P&gt;Sven Swennen&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 12:17:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/sap-ssl-handshake-failed/qaa-p/634321#M158090</guid>
      <dc:creator>SvenS</dc:creator>
      <dc:date>2018-04-13T12:17:18Z</dc:date>
    </item>
  </channel>
</rss>

