Importing certificates for an HTTPS connection
To enable a direct HTTPS connection between the SAP system and the AEB data center, you need the ‘Root-SSL’ and ‘Intermediate’ certificates issued by AEB.
New certificates as from September 21, 2025
From September 21, 2025, new certificates will be used for communication with rz3.aeb.de.
Make sure to install the new certificates prior to this date. At the time of the changeover, the trust store in the SAP system will automatically recognize that the new certificates are to be used.
Type of certificate | Previous certificate | New certificate from September 21, 2025 |
---|---|---|
Intermediate | DigiCert SHA2 Extended Validation Server CA | DigiCert Global G2 TLS RSA SHA256 2020 CA1 |
Root | DigiCert High Assurance EV Root CA | DigiCert Global Root G2 |
You can open the required certificates in the Chrome browser using the following links and save them locally as a file.
- EV Root:
- https://www.digicert.com/CACerts/DigiCertHighAssuranceEVRootCA.crt
- EV Intermediate:
- https://www.digicert.com/CACerts/DigiCertSHA2ExtendedValidationServerCA.crt
- Global Root G2:
- https://cacerts.digicert.com/DigiCertGlobalRootG2.crt.pem
- Global Intermediate:
- https://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt.pem
Alternatively, you can also download the certificates from https://www.digicert.com/kb/digicert-root-certificates.htm. Search there for the following names:
- DigiCert High Assurance EV Root CA
- DigiCert SHA2 Extended Validation Server CA
- DigiCert Global Root G2
- DigiCert Global G2 TLS RSA SHA256 2020 CA1
Importing certificates into the SAP system
- To install the certificates, start the transaction STRUST. Switch to change mode.
- Double-click on SSL CLIENT (default). For setup via the SOAMANAGER, the certificates must also be loaded into the SSL CLIENT (anonymous).
- In the Certificate field group, click the Import certificate button.
- In the window that opens, select binary for the File format option.
- Select the appropriate file with the certificate for import.
- Next, click Add to certificate list.
- Go to the PSE menu and select Distribute All.
- The certificate is now distributed and installed on all application servers.
- Please note for systems with Netweaver AS ABAP version 7.01 and older: To update the imported certificates in the ICM, start the transaction SMICM, go to the Administration menu, and select ICM – Exit Soft – Global.