cancel
Showing results for 
Search instead for 
Did you mean: 

PSE ERROR ON SAPECC

Former Member
0 Kudos

Hi Gurus ,

From today morninig , i face the error message while login to our ECC server . Below i mentioned the error . So kindly give me the solution for this error .

Author

Express message text

SAPSYS

Validity of certificate from list with PSE type >System

PSE< ends in 2 days, for more information, see the SAP

System Log (transaction SM21)

Regards

Palani Selvan

Accepted Solutions (1)

Accepted Solutions (1)

former_member185031
Active Contributor
0 Kudos

In Your ECC System there must me some SSl certificate installed or something like that which will be expired in tw days that why you are getting this message.

Please check in STRUST

Regards,

Subhash

Answers (4)

Answers (4)

Former Member
0 Kudos

Hi Rohit

Here below i mentioned all the data from strustsso2

CN=X85

CN=X85

00

01.10.1997 00:00:00 to 01.01.2038 00:00:00

Kindly advice me .

Regards

Selvan

Former Member
0 Kudos

This message was moderated.

Former Member
0 Kudos

Hello Selvan,

Run the following report SSF_ALERT_CERTEXPIRE.

Go to se38,put the name of report SSF_ALERT_CERTEXPIRE and tell me the results

Rohit

Former Member
0 Kudos

System PSE PROG <SYST>

Own Certificate

CN=ID3 01.01.2038

Certificate List (Cert List)

1 = CN=X85 01.01.2038

2 = CN=SSO, O=sapmarkets, C=US 01.01.2038

3 = CN=DSZ, OU=IDES, O=mySAP.com Workplace, C=DE 01.01.2038

4 = CN=MEI 01.01.2038

5 = CN=ID3 01.01.2038

6 = CN=IDES Workplace Center, OU=IDES, OU=SAP AG, O=mySAP.com Workplace, C=DE 01.01.2038

7 = CN=JR3 18.07.2008

8 = CN=E6T 27.12.2006

9 = CN=US01 04.04.2007

10 = CN=EP7, O=SAP Training 02.02.2020

11 = CN=CORPORATEPORTAL 01.08.2007

12 = CN=IDES Portal 5.0 10.01.2007

13 = CN=HR Vertrieb demoportal 08.09.2007

14 = CN=SAPUK ZE6 Sales Portal Demo 17.09.2007

15 = CN=GFI Demo- & Technology-Center 29.09.2007

16 = CN=HR Vertrieb demoportal productiv 06.08.2007

17 = CN=SP4C, OU=SAP Training, O=SAP 02.01.2008

18 = CN=Portal, OU=IBSDI, O=SAP-AG, C=DE 28.07.2007

19 = CN=EP50, OU=Solution Centre productive, O=CRM GBU, C=DE 28.01.2007

20 = CN=EP6, OU=SPS, OU=SAP, O=SAP Trust Community, C=DE 01.03.2009

21 = CN=E6T, OU=Training, OU=SAP, O=SAP Trust Community, C=DE 25.11.2008

22 = CN=EP6, OU=PortalPlatformTeam, OU=EnterprisePortal, O=SAP Trust Community, 16.04.2008

Checking the PSE

Application server PSE:

ID: CN=ID3

Namespace:

Profiles: C:\usr\sap\<SID>\DVEBMGS00\sec\SAPSYS.pse

OK: file available, length: 14.851

OK: local PSE identical to original in database

OK: security toolkit available

Version

SSFLIBSO Version 1.555.17 ; SECUDE(tm) Version 5.4.28M-2 Copyright (c) SECUDE GmbH 1990-2001 #SAPSEC

OK: signature tested successfully

This is the report output, can i know if it will cause any problem; what i understood its only to connect from EP6 to ECC6 or vice-versa correct me if i m wrong. is there any other purpose of certificate.

by the way i know i need to renew my certificate for number 20th, but i dont know the steps to renew certificate. So if you can shed some light on the same that would be very helpfull.

Mani

Former Member
0 Kudos

hi mani,

is EP6 your portal system

if yes then the certificate of EP6 is itseld expiring,check in the visual admin of EP system,it will tell you that the certificate is expiring.

so you need to generate a new certificate of EP and import that in your ABAP system

that will work fine for you.

Let me know of any issues

Rohit

Former Member
0 Kudos

Can you give me some steps to follow, and i dont htink we hv visual Adminiistrator anymore from EP6, its all integrated into Netweaver administration. but if i go to "system administrator >>Keystore Administration". " i am not able to do anything it look like its disabled. it looks like i am missing some step to delete it first then create a new certificate.

so i think im right in the sequence, first create a certificate in EP6 and the download the certifictae and finally upload certificate using ECC6 corrrect me if i am wrong. i have Enterprise portal but i am not sure if i can connect to ECC6 from EP6 now, as the certificate i see on ECC6 does not looks like the same on Enterprise portal 6in Key administration.

appreciate you reply.

mani

Former Member
0 Kudos

As far as I know we can create the certificate from VA only and then we will have to dowmload the cert and then import it into ABAP system

Rohit

Former Member
0 Kudos

What is VA, and i think we need to that in SSL case but this is PSE. I am not much familiar with the same so it would be very nice of you if u can explain the same in micro fashion.

Mani

Former Member
0 Kudos

Hi Subash ,

Below i mentioned the details .

Owner CN=X85

Issuer CN=X85

Serial Number 00

Valid From 01.10.1997 00:00:00 to 01.01.2038 00:00:00

Check Sum

Regards

Selvan

Former Member
0 Kudos

Hi Subash ,

I saw the self signed certficatein certificae list . But in certificate below i mentioned the empty space only

Owner

Issuer

Serial Number

Valid From to

Check Sum

Kindly advice me

Reg

selvan

former_member185031
Active Contributor
0 Kudos

Just Double click on Certificate List

then it will show you the details,

Owner

Issuer

Serial Number

Valid From to

Check Sum

and check the valid from and valid to field.

Regards,

Subhash

Former Member
0 Kudos

Hello Selvan

Go to STRUSTSSO2

1.There you will see System PSE and then under that owner,do you see anything there

If yes,double click on that and then you will see under certificate the details,if not go to step 2

2. Go to certificate list->under owner do you find something,if yes,double click on it and check the details under certificate

3. else go to Logon ticket in the downmost part of screen,and check whether anything is there or not

Also is your system ABAP or ABAP+JAVA

Let me know the results of this

Rohit

former_member185031
Active Contributor
0 Kudos

Are you getting only one self signed certficatein certificae list or there are anything else such as

System PSE

SSL Standard

SSL Client

I think you have two different certificate installed in your system and one of them will be expired in two days.

Regards

Subhash

Former Member
0 Kudos

I am facing the same probelm,

i searched a lot but found somethign but i am not sure if its the way to do the same. I seen documentation [SAP help on certificate|http://help.sap.com/saphelp_nwce10/helpdata/en/75/c80b424c6cc717e10000000a155106/content.htm ] in which i got something like this i need to do, creat a new certifictae in EP 6 using "http://<portal>:<port number>/irj/portal/ >>system administrator >>Keystore Administration".

then down load the certificate from here and update it on ECC6 system using strust tcode.

but if i see owner of certificate its different on ECC (CN=<SID>) right now then that of owner on EP6 for current certificate. so i am afraid previous certificate is generated from EP6 or some other system.

So i am confused here should i go the same way as per document or i should be having the same Owner in the new certifictae request.

Its almost last day of my expiration.

Secondly i see different validity on ECC 6.0 and EP 6.0 and i am not even sure currently we are able to connect to SAP ECC from EP6, so does it effact my landscape if I wont update Certificate.

My main concern is will i be able to log on to EP6 directly or not?

i will appreciate any reply

Mani

Former Member
0 Kudos

Hi Subash ,

Kindly tell me , what i have to do in strust .

Reg

Selvan

former_member185031
Active Contributor
0 Kudos

You have to check the type of certificate in STRUST

Check what certificate has been installed. After two days you will not able to see the message but the certificate will not work i mean for example if you are using a SSL certificate then it will not work after two days, So you have to extend your certificate. but first of all just make sure what certificate has been installed there.