How to import Certificates X.509 Certificates, PKCS#12 , PKCS#8 in SAP Process Integration PI system

Опубликовано: 03 Июнь 2026
на канале: The SAP Basis
5,680
54

Symptom:

The Certificates Authority provided by the server have expired or have changed and you need to import the new ones in PI system for the server authentication.
In XPI_Inspector debug trace tool, in the result.html file, if you click in the Communication channel name, you can see a warning that the certificate authority is not trusted in "Is Remote SSL Server Certificate Trusted" section:

Environment

PI Release Independent
SAP NetWeaver
SAP Process Integration
SAP NFE


Reproducing the Issue

Use the XPI Inspector trace using Example 50 or 11 to trace the error as per instructions in SAP Note 1514898 XPI Inspector for troubleshooting XI
Open the resulting zip file
Go to result.html
result.html
Click on the Communication Channel link or scroll down to the relevant section


Resolution:

For NetWeaver PI 7.0x releases:

Go to the Visual Administrator - Cluster tab - SID- Server * - Services - Key Storage - Runtime tab - TrustedCAs.
Select the TrustedCAs view and click Load button.
Import the certificates provided by the server.

For NetWeaver PI 7.1x and higher releases: Go to Netweaver Administrator -Configuration tab - Security - Certificates and Keys - Key Storage tab TrustedCAs.
Select the TrustedCAs view and click Import Entry button. Import the three certificates provided by the server.

How to get the missing certificates

It is possible to get the missing certificates directly from the XPI_Inspector tool. The certificates will be saved in the "certs" folder.

You can download the certificates by clicking in the link Certificate: #x:


It is also possible to get the certificates directly with the server provider or by accessing the webservice via browser and getting the certificates collected by the browser.

Note: Once the Keystore has been updated with the certificates, you will need to restart the channel to reflect the changes.

In this video we shall see that How to import Certificates X.509 Certificates, PKCS#12 , PKCS#8 in SAP Process Integration PI system by following the below mentioned SAP note.

https://launchpad.support.sap.com/#/n...

#TheSAPBasis
#X509
#PKCS8
#PKCS12

Keywords

How to import server certificates in PI system, expired, Nfe, certs, certificate, nota fiscal eletronica, peer certificate reject by chain verifier, connection reset, certificate authority, CA, NF-e, trustedca, trustedcas, certificates, bad certificate, SEFAZ, AFIP, Process Integration 7.0, PI 7.0, PI 7.01, PI 7.02, Process Integration 7.10, PI 7.10, Process Integration 7.11, PI 7.11, Process Integration 7.30, PI 7.30, Process Integration 7.31, PI 7.31, Process Orchestration 7.40, PI 7.40, PO 7.40, Process Orchestration 7.50, PI 7.50, PO 7.50, NetWeaver, XI, keystore