2025 Feb 24 5:18 AM - edited 2025 Feb 24 5:41 AM
Hi Experts,
I want to know where to check client certificate uploaded for mtls. As per the help sap help mentioned after creating incident to enable mtls we need to share client certificate with sap in the shared drive provided by sap. I want to know where can we see that path which sap uploaded the client certificate.
Regards
Venkat.
Request clarification before answering.
Hi Venkat,
Thankfully, this is mostly Self-Service now. SAP Integration Suite - Configuring Additional Virtual Host
I am in contact with SAP at the moment to discuss some of these topics; however, the full chain of the public certificate must be loaded into the Configure > APIs > Certificates Tab in .pem or .der format and must be in leaf + intermediate(s) + root certificate order.
Once loaded there and your Virtual Host configured for mTLS, anyone who has the keypair of your public certificate should be able to access a proxy deployed on this VirtualHost.
One big caveat that I still have questions on:
I have received confirmation from SAP "certificate authentication" only checks to make sure the Intermediate/Root certificate matches a reference in the Certificates loaded into your trust store. Meaning you may have loaded a certificate for Customer A signed by a CA (i.e. Digicert). This means if Customer B uses the same CA as Customer A, they will also have access to an API Proxy on your VirtualHost even though you didn't load Customer B's certificate.
I tested this with SAP Integration Suite Certificates from two different environments (both signed by Digicert) and was able to make API Proxy calls for a certificate I didn't load to the trust store.
Therefore, the way around this is to create a RaiseFault policy that checks the content of the certificate; however, the only way to do this is by creating an SAP Ticket to enable the Client and Connection Properties on your VirtualHost.
All-in-all a bit cumbersome process; but mostly self-service.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 6 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.