Stop googling SAP errors. Use our Free Essentials plan instead - no credit card needed. Start Now

Close

How To Fix TRUST013 - Certificate no longer has signature (use restriction)


SAP Error Message - Details

  • Message type: E = Error

  • Message class: TRUST - Certificate Management

  • Message number: 013

  • Message text: Certificate no longer has signature (use restriction)

  • Show details Hide details
  • What causes this issue?

    Certificates entered in the certificate list of a PSE no longer have a
    signature and can therefore only be used for verifying digital
    signatures. The certificate itself can no longer be verified.
    The certificate you want to export comes from the certificate list of
    the PSE and its use is therefore restricted (as described above).

    System Response

    The system issues an error message and will not allow you to continue with this transaction until the error is resolved.

    How to fix this error?

    Note that the exported certificate is only suitable for import into a
    certificate list of a PSE.

    Procedure for System Administrators


    Error message extract from SAP system. Copyright SAP SE.


Smart SAP Assistant

  • What is the cause and solution for SAP error message TRUST013 - Certificate no longer has signature (use restriction) ?

    The SAP error message TRUST013 indicates that a digital certificate is no longer valid due to a signature restriction. This typically occurs when the certificate has been revoked, expired, or is otherwise deemed untrustworthy by the system.

    Causes:

    1. Expired Certificate: The certificate has reached its expiration date and is no longer valid.
    2. Revoked Certificate: The certificate has been revoked by the Certificate Authority (CA) due to security concerns or other reasons.
    3. Signature Algorithm Issues: The certificate may use a deprecated or insecure signature algorithm that is no longer accepted by the system.
    4. Trust Relationship Issues: The certificate may not be trusted by the SAP system due to missing root or intermediate certificates in the trust store.

    Solutions:

    1. Check Certificate Validity:

      • Verify the expiration date of the certificate. If it is expired, you will need to obtain a new certificate.
      • Check if the certificate has been revoked by consulting the Certificate Revocation List (CRL) or using Online Certificate Status Protocol (OCSP).
    2. Update the Certificate:

      • If the certificate is expired or revoked, request a new certificate from the Certificate Authority (CA).
      • Install the new certificate in the SAP system.
    3. Update Trust Store:

      • Ensure that the root and intermediate certificates are correctly installed in the SAP trust store. This can be done using transaction STRUST.
      • Import the necessary certificates into the trust store if they are missing.
    4. Check Signature Algorithm:

      • If the certificate uses an outdated signature algorithm (like SHA-1), consider reissuing the certificate with a more secure algorithm (like SHA-256).
    5. Reconfigure SSL/TLS Settings:

      • If applicable, review and update the SSL/TLS settings in the SAP system to ensure compatibility with the new certificate.

    Related Information:

    • Transaction STRUST: This transaction is used to manage the SSL certificates and trust relationships in SAP.
    • Certificate Authorities (CAs): Understand the role of CAs in issuing and managing digital certificates.
    • SAP Notes: Check for any relevant SAP Notes that may provide additional guidance or patches related to certificate management and the TRUST013 error.
    • Documentation: Refer to SAP documentation on security and certificate management for best practices and detailed procedures.

    By following these steps, you should be able to resolve the TRUST013 error and restore the functionality that relies on the digital certificate.

    • Do you have any question about this error?


      Upgrade now to chat with this error.


Instant HelpGet instant SAP help. Sign up for our Free Essentials Plan.


Related SAP Error Messages

Click the links below to see the following related messages:
  • TRUST012 Unknown error
    Self-Explanatory Message Since SAP believes that this specific error message is 'self-explanatory,' no more information has been given.The majority of...

  • TRUST011 No entry found
    What causes this issue? The system cannot find an entry with the specified key in the database.System Response The system issues an error message an...

  • TRUST014 Cannot import certificate from SAP Workplace Certification Authority (CA)
    Self-Explanatory Message Since SAP believes that this specific error message is 'self-explanatory,' no more information has been given.The majority of...

  • TRUST015 Data saved
    Self-Explanatory Message Since SAP believes that this specific error message is 'self-explanatory,' no more information has been given.The majority of...

Click on this link to search all SAP messages.


Rating
ERPlingo's SAP support assistant is amazing. Saves me countless hours trying to solve complex SAP issues myself. It's a real game changer!
Rate 1
Thomas Michael
SAP Consultant, Author & Speaker