The call fails from SAP with the following error:
SOAP:1,023 SRT: Processing error in Internet Communication Framework: ("ICF Error when receiving the response: ICM_HTTP_SSL_ERROR")
We reviewed the certificate chain presented by the CloudHub 2 endpoint and imported the following certificates into SAP STRUST:
- CloudHub server certificate: *.xxxr.usa-e2.cloudhub.io
- Let's Encrypt YR1
- ISRG Root YR
- ISRG Root X1
The certificate chain validates successfully outside SAP.
However, SAP ECC still reports ICM_HTTP_SSL_ERROR when calling the MuleSoft endpoint.
Has anyone experienced this issue with SAP ECC and the newer Let's Encrypt certificate chain used by CloudHub 2?
Specifically, I would like to confirm:
- Which SAP STRUST PSE should contain the CA certificates for an outbound HTTPS SOAP call: SSL Client Anonymous or SSL Client Standard?
- Is the CloudHub leaf/server certificate required in STRUST, or should only the CA/intermediate certificates be trusted?
- Are there known compatibility issues between older SAPCRYPTOLIB versions and the newer YR1 / ISRG Root YR Let's Encrypt chain?
- Does SAP ICM need to be restarted/reloaded after updating the certificate list?
- Is there any special TLS/SNI configuration required when SAP ECC calls a CloudHub 2 endpoint?
MuleSoft itself is available and the endpoint can be reached successfully from other HTTPS clients.
Any guidance on what to check in SAP SMICM/STRUST or CloudHub 2 would be appreciated.
Thanks!
#MuleSoft DataWeave