Need help here
We are configuring an SM59 HTTP destination from an on-premise SAP S/4HANA system to an SAP Cloud Integration runtime endpoint in the Cloud Foundry environment.
The destination is configured as follows:
  • Connection type: G – HTTP Connection to External Server
  • Target: <CI-runtime-host>.it-cpi023-rt.cfapps.eu20-001.hana.ondemand.com
  • Port: 443
  • SSL: Active
  • SSL client: ANONYM
  • SAP kernel: 793, patch 331
  • CommonCryptoLib: 8.5.61
  • TLS version shown in the trace: TLS 1.2
The CI certificate chain has been imported into the relevant STRUST PSE. Other HTTPS destinations using the same ANONYM SSL configuration are working from this S/4 system.
However, the connection test fails with the following error:
SSL handshake with <CI-runtime-host>:443 failed:
SSSLRC_CONN_CLOSED (-10)
Remote Peer has closed the network connection
SapSSLSessionStartNB()==SSSLRC_CONN_CLOSED
SSL::SiRecv() failed rc==SSSLRC_CONN_CLOSED
SSL_get_state()==0x2120 "TLS read server hello A"
The ICM trace confirms that:
  • The hostname is resolved.
  • A TCP connection to the target IP on port 443 is established.
  • TLS 1.2 Client Hello is sent.
  • SNI contains the correct CI runtime hostname.
  • The connection closes while S/4 is waiting for the TLS Server Hello.
Relevant trace:
SSL_get_state()==0x2120 "TLS read server hello A"
SecuSSL_SessionStartNB():
incomplete initial SSL/TLS handshake
SSL handshake with <CI-runtime-host>:443 failed:
SSSLRC_CONN_CLOSED (-10)
Remote Peer has closed the network connection
session-specific ciphersuites=566:PFS:HIGH::EC_P256:EC_HIGH
AnonClient SSL
TLSextSNI server_name="<CI-runtime-host>"
We have also tested by setting the HTTP version to HTTP/1.1, but the same TLS handshake error continues.
Since the connection is closed before the Server Hello and server certificate are received, we are unable to confirm whether the issue is related to the SAP ICM TLS configuration, cipher compatibility, the network path, or a specific requirement for the SAP Cloud Integration Cloud Foundry endpoint.
Has anyone encountered this error while connecting from an ABAP system to an SAP Cloud Integration runtime endpoint?
In particular, we would like to understand:
  1. Are any specific TLS cipher-suite settings required for SAP BTP Cloud Foundry runtime endpoints?
  2. Are there any known compatibility issues with SAP kernel 793/CommonCryptoLib 8.5.61?
  3. Can this behaviour occur due to a proxy or TLS-inspection component, even though the TCP connection to port 443 is established?
  4. Is there any additional SM59 or ICM configuration required for this SAP Cloud Integration endpoint?
Any guidance on the exact trace or configuration that should be checked would be helpful.
0
0 comments
Nischay Venugopal
1
Need help here
powered by
SAP Integration Academy
skool.com/sap-integration-experts-2910
You don't see us, but we make everything work. Welcome the world of Integrations!
Build your own community
Bring people together around your passion and get paid.
Powered by