Monday, January 28, 2013

NetWeaver Portal not behaving with Internet Explorer SSL and TLS settings…


NetWeaver Portal not behaving with Internet Explorer SSL and TLS settings…
Recently on a client site we ran into issues with the internal users being unable to connect to the portal while using the same SSL (3.0) and TLS (1.0, 1.1, or 1.2) settings necessary for other SAP or 3rd party applications.  This may be related to Microsoft security updates KB2585542 and KB2618444, though the client does not have record of applying these.

This is specific to Internet Explorer 8 or higher.
The errors you may receive include “connection timed out” and “page cannot be displayed” though others have seen spurious other generic error messages.

There are two possible solutions:
1. Update your AS Java to the latest Support Package.  Unfortunately this was not an option at this client site, so we had to go with the work-around below.

2. To implement the workaround change the SSL server configuration as follows:
- Open Visual Administrator and log in
- Select Dispatcher -> Services -> SSL Provider
- Select the line with port number corresponding to your web server (default 5xx01)
- remove all cipher suites except the following:
  SSL_RSA_WITH_RC4_128_SHA

Keep in mind, if you implement this work-around, remember to add the appropriate TLS cipher suites back when you update AS Java.

Hope this helps…