cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Cloud Platform connectivity

0 Kudos

Hello, experts.

I'm a newby to SCP and I have an issue with connection of my SCP subaccount to on-premise system. I had a SCP subaccount in the Neo environment until November 13 and I'd setup the connection using one of the guides that I'd found on sap.blogs. But on November 13 the Neo environment has been terminated and now I have to create a new subaccount and set a new connection up. And here I have a problem. I use the same guide trying to set the connection up but my SAP cloud connector cannot connect to my new subaccount.

This is how my new SCP cockpit looks like:

безымянныи1.jpg

This is the error that I get trying to create a new subaccount in my SAP cloud connector:

The ljs_trace.log contains the following entry:

2020-11-27 23:09:43,890 +0300#ERROR#com.sap.scc.ui#http-bio-8333-exec-7# #SCC handshake failed: 401 — Unauthorized

Can anyone, please, help me and is it even possible now to connect SAP cloud platform subaccount to on-premise system?

Thank you in advance.

View Entire Topic
pjcools
Active Contributor
0 Kudos

Hi notif93 sounds like the S or P userid does not have the Cloud Connector Admin role assigned in the Members area of the new subaccount you just created. I would check this first and ensure the S or P user you are using from the Cloud Connector to sign into and connect to the Neo subaccount is 1) a member of the subaccount and 2) is assigned the Cloud Connector Admin role.

Let's see how you go and if this fixes the problem please mark as Best Answer so this can be closed.

Thanks & Kind Regards

Phil Cooley

Hi, Phil.

Thanks for Your answer. I've checked the roles of the new subaccount. The CC Admin role is assigned:

roles.jpg

Btw, I did not change the user. As I've mentioned above, the connectivity was setup for my previous subaccount in the Neo environment. The roles are the same. The problem has arised after the termination of Neo environment. Maybe the connection should be setup in some other way in the new environment?

Thank You.

pjcools
Active Contributor

Hi notif93

OK, this makes sense now - you are connecting to a Cloud Foundry account - not Neo. Can you please share screenshots of what you are entering when trying to connect please. There is definitely some issue with the userid or subaccount ID that you are entering. So for that user, did you assign a role collection to your user via the identity provider? If you can please share this assignment as well that would be great.

Thanks & Kind Regards

Phil Cooley

0 Kudos

Hello, Phil

In my new Cloud Foundry subaccount I've assigned role collections via identity provider (see the below screenshot):

cockpit.jpg

I'm trying to create a new subaccount in my Cloud Connector. I enter Europe (Frankfurt) region, my subaccount ID (from SCP Cockpit), my username, the password. Please, see the below screenshot.

cloudconnector.jpg

Then I hit Save and get the error message 417 like I've mentioned in my original question.

Please, see the below logs. Can it be the problem with the certificate?

20-12-05 12:45:27,622 +0300#WARN#com.sap.scc.config#http-bio-8443-exec-8#          #Creating an sslContextProvider for account 1111111111111111111111111@hanatrial.ondemand.com
without SSLContext. Keystore did not contain a certificate.|

2020-12-05 12:45:27,624 +0300#INFO#com.sap.scc.security#http-bio-8443-exec-8#     #Will retrieve Connectivity CA certificate from SAP Cloud Platform|

2020-12-05 12:45:27,624 +0300#INFO#com.sap.scc.security#http-bio-8443-exec-8#      Executing Http Get request to
https://connectivitycertsigning.hanatrial.ondemand.com:443/certificate/management/v1/trusted/ca/acco...

2020-12-05 12:45:27,958 +0300#INFO#com.sap.scc.security#http-bio-8443-exec-8#         #Returned Http Response with code 401|

2020-12-05 12:45:27,960 +0300#INFO#com.sap.scc.config#http-bio-8443-exec-8#        #Stopping service channels on 1111111111111111111111@hanatrial.ondemand.com|

2020-12-05 12:45:27,960 +0300#WARN#com.sap.scc.rt#http-bio-8443-exec-8#          #Tunnel account:///1111111111111111111111111 is inoperative. SccEndpoint com.sap.scc.config.TunnelSccEndpoint@33333333 ok, and context == null|

2020-12-05 12:45:28,003 +0300#ERROR#com.sap.scc.ui#http-bio-8443-exec-8#         #SCC handshake failed: 401 —
Unauthorized

com.sap.scc.servlets.SccHandshakeException:
SCC handshake failed: 401 — Unauthorized

                at
com.sap.scc.cert.HttpCertificateManagementService.processRequest(HttpCertificateManagementService.java:140)

                at
com.sap.scc.cert.HttpCertificateManagementService.executeGetRequest(HttpCertificateManagementService.java:94)

                at
com.sap.scc.cert.HttpCertificateManagementService.getConnectivityAgentCA(HttpCertificateManagementService.java:65)

Thanks.

Best regards,

Anatoli