SAP Note 499386 - Invalid logon ticket for CA certificates

Component : Secure Store and Forward -

Solution : https://service.sap.com/sap/support/notes/499386 (SAP Service marketplace login required)

Summary :
This SAP Note addresses an issue where the system rejects a logon using an SAP Logon Ticket, with a syntax error message indicating a non-interpretable ticket. The ticket-system, previously functional for a year, suggests the problem is not due to configuration but linked to certificate validity: certificates from SAP_CA expire after one year, rendering any issued logon tickets invalid post their expiration. Solution requires regenerating a PSE via transaction PSEMAINT or STRUST and resubmitting a certificate request to SAP or another CA.

Key words :
longer validity periods, sap logon ticket, ticket-based logon, validity period expires, logon ticket, validity period, validity reason, logon tickets, system rejects, error message

Related Notes :

912229
588297Warnings about security certificates in the system log
572035Warning about expired security certificates
389186Services rendered by the SAP Trust Center Service
177895Refitting the mySAP.com Single Sign-On capability