SAP Knowledge Base Article - Public

2565122 - FAQ on SSL Certificates for RMK Career Sites


Most common questions on SSL certificates for RMK sites.


SAP SuccessFactors Recruiting Marketing


  1. Is the portal where the certificate will be used in IIS (Internet Information Services)? No. The certificate will be used in Apache.
  2. Will the certificate be installed in a single server or multiple servers? The certificate will be installed on F5 loadbalancer, which has the list of all Apache servers mapped to it.
  3. What's the software used for the server? Other.
  4. Wha certificate type should be provided to the Cloud Product Support? A certificate bundle (i.e root and intermediate certs as well).
  5. What certificate formats are accepted : the recommended format is .cer/.crt but we can also accept pfx
  6. How to create an SSL certificate for the application server? For a production report server, obtain an SSL certificate signed by a known CA, such as VeriSign, Geotrust, or Entrust. SSL certificates signed by a known CA automatically work with the browser to access the server.
  7. How is the DNS record on the SAP side determined? The DNS i.e. is owned & decided by RMK Ops team at the time of DNS record addition and is kept standard to identify customer names quickly. It has nothing to do with information in Command center.
  8. Will a new cert be required if changes are made to the RMK config (domain change, DCchange)? Yes, a new cert will then need to be requested.
  9. Will a new cert be required if changes are made to the connected Bizx instance? No, the cert is only linked to the RMK instance.
  10. Which port is been used for the creating of the SSL certificate? The customer's RMK Career site will use 443 (HTTPS) port to come to our environment.
  11. Which application where the certificate is hosted? During SSL setup for the customer, we create dedicate VIP over the LB(LoadBalancer) for the customer's RMK URL and  we will install the certificate on it.
  12. What is the OS version, hostName, IP address of the Load Balancer been used? The OS version is LoadBalancer - BigF5 .
    P.S - The hostName , IP address are internal details which cannot be shared with customer due to internal security purpose of SAP .
  13. What is the server type where the SSL ceritificate is hosted? The SSL certificate will be installed on BigF5 Loadbalancer not on any server. i.e. the HTTPS termination will be happened on the LB level
  14. Is OCSP Stapling supported? OCSP Stapling cannot be supported within our Cloud Landscapes at the moment. Our advice is to acquire a SSL Certificate with included SCT information.
  15. Is there anything needed to do about the * Certificate Renewal? No action is required for stage/test environments. SSL certificates for all stage servers are managed by SAP

See Also

2231401 - Certificate Renewal - Recruiting Marketing
2563741 - Unable to Access the Production RMK Career Site - Recruiting


SSL certificate, IIS, single server, FAQ, OCSP , KBA , LOD-SF-RMK , Recruiting Marketing , How To


SAP SuccessFactors Recruiting all versions