cancel
Showing results for 
Search instead for 
Did you mean: 

Solman 7.2 Hub Connectivity RFC SSL Handshake error to apps.support.sap.com

steven_bier
Active Participant
0 Kudos
11,394

Hello,

during solman_setup step 3.2 Hub Connectivity a error occured by the SSL Handshake to apps.support.sap.com in RFC SAP-SUPPORT_PORTAL.

Error Trace ICM:

[Thr 140082282628864] SSL_get_state()==0x2120 "TLS read server hello A" [Thr 140082282628864] *** ERROR during secussl_read() from SSL_read()==SSL_ERROR_SSL [Thr 140082282628864] session uses PSE file "/usr/sap/SO1/DVEBMGS00/sec/SAPSSLA.pse" [Thr 140082282628864] secussl_read: SSL_read() failed (536875072/0x20001040) [Thr 140082282628864] => "received a fatal TLS handshake failure alert message from the peer" [Thr 140082282628864] >> ---------- Begin of Secu-SSL Errorstack ---------- >> [Thr 140082282628864] 0x20001040 | SAPCRYPTOLIB | SSL_read [Thr 140082282628864] SSL API error [Thr 140082282628864] received a fatal TLS handshake failure alert message from the peer [Thr 140082282628864] 0xa0600266 | SSL | ssl3_read_bytes [Thr 140082282628864] received a fatal TLS handshake failure alert message from the peer [Thr 140082282628864] 0xa0600266 | SSL | ssl3_connect [Thr 140082282628864] received a fatal TLS handshake failure alert message from the peer [Thr 140082282628864] 0xa0600266 | SSL | ssl3_read_bytes [Thr 140082282628864] received a fatal TLS handshake failure alert message from the peer [Thr 140082282628864] << ---------- End of Secu-SSL Errorstack ---------- [Thr 140082282628864] No certificate request received from Server [Thr 140082282628864] SSL NI-hdl 79: local=10.180.66.178:23994 peer=155.56.96.48:443 [Thr 140082282628864] <<- ERROR: SapSSLSessionStartNB(sssl_hdl=1700030)==SSSLERR_SSL_READ [Thr 140082282628864] *** ERROR => SSL handshake with APPS.SUPPORT.SAP.COM:443 failed: SSSLERR_SSL_READ (-58) [Thr 140082282628864] SAPCRYPTO:SSL_read() failed

I play with the Cipher Suites parameters but can´t find a solution.

Thanks Steven

View Entire Topic
alexandrepoitras
Explorer

Go to transaction RZ11 and make sure that profile parameter ssl/client_ciphersuites is set to 918:PFS:HIGH.

If not, you may change it in RZ10 and restart system after setting the parameter.

Let the community know if it works for you.