Do you have any question about this error?
Stop googling SAP errors. Use our Free Essentials plan instead - no credit card needed. Start Now →
Message type: E = Error
Message class: SLDAP_ICM - ICM LDAP Plugin: Messages
Message number: 012
Message text: SSL client identity &1 (with PSE file name "&2") cannot be used
The provided SSL client identity &V1& cannot be used to establish a
secure connection.
This check verifies:
For the SSL client identity &V1&, a PSE file name "&V2&" can be created
(when the former content was empty, this step failed).
For the PSE file name "&V2&", exactly one entry can be found in the
database table of PSE file headers (SSF_PSE_H).
For an SSL client identity regularly maintained in transaction STRUST,
those checks should pass.
The creation of the ICM LDAP plug-in-based connection was canceled.
The system issues an error message and will not allow you to continue with this transaction until the error is resolved.
Error message extract from SAP system. Copyright SAP SE.
SLDAP_ICM012
- SSL client identity &1 (with PSE file name "&2") cannot be used ?The SAP error message SLDAP_ICM012 indicates an issue with the SSL client identity, specifically that the SSL client identity cannot be used with the specified PSE (Personal Security Environment) file. This error typically arises in scenarios where SSL/TLS communication is required, such as when connecting to an LDAP server or other secure services.
Causes:
- Invalid or Missing PSE File: The PSE file specified may not exist, may be corrupted, or may not be accessible by the SAP system.
- Incorrect Configuration: The SSL client identity may not be correctly configured in the SAP system, leading to issues when trying to establish a secure connection.
- Certificate Issues: The certificate associated with the SSL client identity may be expired, not trusted, or not properly installed.
- Permissions: The user under which the SAP system is running may not have the necessary permissions to access the PSE file.
- Mismatched SSL/TLS Versions: The SSL/TLS version being used may not be compatible with the server or the client.
Solutions:
Check PSE File:
- Verify that the PSE file exists at the specified location and is not corrupted.
- Use transaction STRUST in the SAP GUI to check the PSE configuration and ensure that the correct PSE file is being used.
Recreate PSE:
- If the PSE file is corrupted or misconfigured, consider recreating it. You can do this in transaction STRUST by selecting the appropriate options to create a new PSE.
Update Certificates:
- Ensure that the certificates in the PSE are valid and not expired. If necessary, import new certificates into the PSE.
Check Permissions:
- Ensure that the SAP system has the necessary permissions to access the PSE file. This may involve checking file system permissions on the server.
Review SSL/TLS Configuration:
- Check the SSL/TLS settings in the SAP system and ensure they are compatible with the server you are trying to connect to. This may involve adjusting settings in the ICM (Internet Communication Manager) configuration.
Test Connection:
- After making changes, test the connection to the LDAP server or the service you are trying to access to ensure that the issue is resolved.
Related Information:
If the issue persists after trying the above solutions, consider reaching out to SAP support for further assistance, providing them with detailed logs and error messages for better diagnosis.
Get instant SAP help. Sign up for our Free Essentials Plan.
SLDAP_ICM011
Invalid combination of security protocol &1 and client identity
Self-Explanatory Message Since SAP believes that this specific error message is 'self-explanatory,' no more information has been given.The majority of...
SLDAP_ICM010
The ICM LDAP plug-in is not available in this system (SAP Note 2785547)
What causes this issue? In this system, the ICM LDAP plug-in is not available.System Response The ICM LDAP plug-in cannot be used yet.How to fix thi...
SLDAP_ICM013
STARTTLS negotiation with directory service "&1" results in error &2&3&4
What causes this issue? The ICM LDAP plug-in has successfully established a connection to the directory service, but the STARTTLS negotiation to prom...
SLDAP_ICM014
Search in directory service "&1" returns search result reference "&2&3&4"
What causes this issue? The directory service has responded a search request with a response that contains not only result entries, but also search r...
Click on this link to search all SAP messages.