How To Fix 00787 - Caution: Certificate-based logon is rule-based


SAP Error Message - Details

  • Message type: E = Error

  • Message class: 00 -

  • Message number: 787

  • Message text: Caution: Certificate-based logon is rule-based

  • Show details Hide details
  • What causes this issue?

    The system was configured for the use of the rule-based certificate
    logon (login/certificate_mapping_rulebased = 1).
    In this case, the mapping table USREXTID is not evaluated. It does not
    make sense to maintain mapping entries in the table USREXTID.

    System Response

    The system issues an error message and will not allow you to continue with this transaction until the error is resolved.

    How to fix this error?

    Procedure for System Administrators


    Error message extract from SAP system. Copyright SAP SE.


Smart SAP Assistant

  • What is the cause and solution for SAP error message 00787 - Caution: Certificate-based logon is rule-based ?

    The SAP error message "00787 Caution: Certificate-based logon is rule-based" typically indicates an issue related to the configuration of certificate-based authentication in an SAP system. This error arises when the system is set up to use certificate-based logon, but the rules governing this logon method are not properly configured or are not being met.

    Cause:

    1. Configuration Issues: The system may not have the correct configuration for certificate-based authentication. This could include missing or incorrect entries in the profile parameters or the SSL configuration.
    2. Rule-Based Logon: The system is expecting a specific set of rules to be followed for certificate-based logon, and these rules may not be satisfied. This could involve user roles, permissions, or specific attributes that need to be present in the certificate.
    3. Certificate Issues: The certificate being used may not be valid, may not be trusted by the SAP system, or may not contain the necessary attributes required for authentication.

    Solution:

    1. Check Configuration: Review the configuration settings for SSL and certificate-based authentication in the SAP system. Ensure that all necessary parameters are correctly set in the instance profile.
    2. Review Logon Rules: Check the rules defined for certificate-based logon. This may involve looking at the security policies in place and ensuring that the user’s certificate meets the required criteria.
    3. Validate Certificates: Ensure that the certificates being used are valid, trusted, and contain the necessary attributes. You may need to check the certificate chain and ensure that the root and intermediate certificates are correctly installed in the SAP system.
    4. User Roles and Permissions: Verify that the user attempting to log in has the appropriate roles and permissions assigned to them in the SAP system.
    5. Consult Documentation: Refer to SAP documentation or support notes related to certificate-based authentication for specific configuration steps and troubleshooting tips.

    Related Information:

    • SAP Notes: Check for any relevant SAP Notes that may address this specific error or provide additional guidance on configuring certificate-based logon.
    • SAP Community: Engage with the SAP Community forums to see if other users have encountered similar issues and what solutions they have found.
    • Security Configuration: Familiarize yourself with the security configuration settings in SAP, particularly those related to SSL and authentication methods.

    If the issue persists after following these steps, it may be beneficial to consult with your SAP Basis team or reach out to SAP support for further assistance.

    • Do you have any question about this error?


      Upgrade now to chat with this error.


Instant HelpGet instant SAP help. Start your 7-day free trial now.


Related SAP Error Messages

Click the links below to see the following related messages:
  • 00786 This certificate has explicitly not been authorized for logon
    Self-Explanatory Message Since SAP believes that this specific error message is 'self-explanatory,' no more information has been given.The majority of...

  • 00785 
    Self-Explanatory Message Since SAP believes that this specific error message is 'self-explanatory,' no more information has been given.The majority of...

  • 00788 Number of failed password logon attempts: & (see long text)
    What causes this issue? One or more failed attempts made to log on to the system with a password and your user name. Failed logon attempts could be c...

  • 00789 
    Self-Explanatory Message Since SAP believes that this specific error message is 'self-explanatory,' no more information has been given.The majority of...

Click on this link to search all SAP messages.


Rating
ERPlingo simplifies finding the accurate answers to SAP message errors. I now use every week. A must have tool for anyone working with SAP! Highly recommended!
Rate 1
Kent Bettisworth
Executive SAP Consultant