cancel
Showing results for 
Search instead for 
Did you mean: 

SLS Client Error 0x04: Unknown or untrusted Secure Login Server user certificate issuer rejected

Former Member
0 Kudos

Hi All,

Need your expert advise in solving the SLS Login issue when i enable SSL at F5.

We have installed Secure Login Server and completed Configuration successfully.

Initially for our testing in our Quality system, we installed and configured SSL at WebAs Java Server. SSO works fine by launching SAP Logon Pad after installing the Root CA (Secure Login Administration Console --> Certificate Management --> Certificate Management --> PKI structure --> SAP Root CA) in the client browser.

Similarly SSO worked fine when installed Root CA from Production Server to Client browser with SSL enabled at WebAs Java. Due to some security issue, our hosting team decided to use F5 LB to host the url instead of WebAs Java Url

So our configuration looks as below

End user Login to F5 Url (SSL) --> SSL Offloading happens at LB and routed to  --> SLC Url (http url)

F5 Url :- https://F5Url.Company.org:443/SecureLoginServer/webclient/webclient.html?profile=dfabd45c4-d2ef-4fbe...  

SLC Url :- http://javaserver.Company.org:50000/SecureLoginServer/webclient/webclient.html?profile=dfabd45c4-d2e...

In the above case, After installing F5 Url (SSL) Root Certificate at client browser and when access the SLC, getting the below error

Client Error 0x04: Unknown or untrusted Secure Login Server user certificate issuer rejected

Along with F5 SSL Root CA, if I install SLS Root CA (Secure Login Administration Console --> Certificate Management --> Certificate Management --> PKI structure --> SAP Root CA) in the client browser, SSO works fine.

Our Security team says not to install SLS Root CA, as our SSL is enabled only at F5.


Can you please let me know what could be the issue.

Regards

Ponnusamy

Accepted Solutions (0)

Answers (1)

Answers (1)

donka_dimitrova
Contributor
0 Kudos

Hello Ponnusamy,

When you have problems with the Secure Login Server or Secure Login Client you can always search for troubleshooting in the Secure Login Implementation guide:

http://help.sap.com/download/sapsso30/secure_login_impl_guide_en.pdf 

Page 332:

Error code: Client Error 0x04 -> 

Error Message: Unknown or untrustworthy Secure Login Server user certificate issuer is rejected. -> Description: PKI checking error. A root CA from the user CA of the Secure Login Server must be available in the Microsoft Trusted Root Certification Authorities. Note This error only occurs in Microsoft Windows and Mac OS operating systems. If this error occurs, proceed as described in chapter 6.4.2.3 PKI Check before Storing in a Client Certificate Store [page 171]

Regards,

Donka Dimitrova