cancel
Showing results for 
Search instead for 
Did you mean: 

SSO Error

Former Member
0 Kudos

hi Expert,

I am getting below error while doing SSO -

-> Miscellaneous failure

->A2210223:Server does not trust my certificate path target ="P:CN=SID"

Steps performed-

1) Service principle name (SPN) created in AD

2) Completed SNCWIZARD (Instance profile configuration done)

3) SU01- Maintained SNC name

4) Maintained SNC name in SAP GUI->Network

SAP is running on SUSE linu & not in domain.

User using Windows machine to connect to SAP.

Please advise.

Accepted Solutions (0)

Answers (2)

Answers (2)

Colt
Active Contributor

Hi Sury,

seems you are trying to configure SNC based on Kerberos but your client seems to connect with a certificate. Make sure SLC is using the Kerberos profile (selected) and the SNC Name in the profile parameter and Logon Pad is set this way:  snc/identity/as = p:CN=<SID>

If you had the plan to perform SSO with X.509 you need to start TA STRUST and check if there is a SNC certificate available with the given CN=<SID>. In such case you do not need any SPN. Please note SAP CCL supports X.509 and Kerberos for SNC in parallel. And also, you never have the need to join any SAP Server to your AD domain, as SAP SSO uses offline kerberos ticket validation.

Regards,

Carsten

Former Member
0 Kudos

Dear Sury,

The certificate verification failed because the certificate path is not complete (CA certificate is missing), or the root certificate is not trusted.

Regards,

Adrian