SAP Knowledge Base Article - Preview

1745538 - "Error: -> Certificate chain incomplete, no certificate found for issuer: " during import of CSR response

Symptom

  • Using the Key Storage management functions of the SAP NetWeaver Administrator (NWA), you have created/chosen a key pair to use for SSL and generated a Certificate Signing Request which was sent to a Certificate Authority (CA) of your choice
  • When you import the CSR response from the CA an error message is displayed in the Key Storage UI:

Error: -> Certificate chain incomplete, no certificate found for issuer: <Distinguished Name (DN) of the certificate signer>

  • In the developer traces of the AS Java the following exception can be found written with severity 'error'

 java.security.cert.CertificateException: Certificate chain incomplete, no certificate found for issuer: <DN of the certificate signer>
 at com.sap.engine.services.keystore.impl.coder.CSRCoder.orderCertificateChain(CSRCoder.java:205)
 at com.sap.engine.services.keystore.impl.coder.CSRCoder.signEntryWith(CSRCoder.java:129)
 at com.sap.engine.services.keystore.jmx.bean.ViewManager.signEntry(ViewManager.java:359)


Certificate chain incomplete, no certificate found for issuer: " during import of CSR response"> Read more...

Environment

Netweaver Application Server Java all versions

Product

SAP NetWeaver Application Server for Java all versions

Keywords

x.509 TLS PSE private public PKI security , KBA , BC-JAS-SEC-CPG , Cryptography , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP ONE Support launchpad (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.