logo

Are you need IT Support Engineer? Free Consultant

SAP Bydesign– Change of M-User / Tenant Certificate Issuer

  • By Sanjay
  • 09/10/2026
  • 12 Views



Symptom

Third-party integrations communicating with SAP Business ByDesign (ByD) using M-User / Tenant certificates may experience authentication or communication issues after the certificate issuer is changed, if the new intermediate certificate is not available in the trust store of the external system.

Background

The certificate issuer for SAP ByD M-User / Tenant certificates is being changed.

The issuer will transition as follows:

 

Current

New

Intermediate Issuer

SAP Passport CA G2

SAP Cloud Client CA

The SAP Cloud Client CA is the new intermediate CA certificate in the certificate chain used for the M-User / Tenant certificate.

Important

The Root CA certificate remains unchanged.

There is no change to the existing Root CA. Only the intermediate issuer in the certificate chain is changing from SAP Passport CA G2 to SAP Cloud Client CA.

Timelines

The change is tentatively planned for the CMP window of November 14th – 15th 2026.

The exact implementation timing is subject to the final change schedule.

Customers are recommended to complete the required trust-store updates before the planned change window.

Environment

SAP Bydesign

Cause

If you have third-party integrations that use the SAP ByD M-User / Tenant certificate for certificate-based authentication, the external system may need to trust the new intermediate CA certificate.

If the new SAP Cloud Client CA certificate is not available in the relevant trust store, the third-party system may not be able to establish a trusted certificate chain after the issuer change.

This can potentially result in authentication or communication failures for the affected integrations.

Resolution

Action Required

If you have third-party integrations using ByD M-User / Tenant certificates, please perform the following actions:

  1. Download the SAP Cloud Client CA intermediate certificate from the SAP Global PKI repository: – https://aia.pki.co.sap.com/aia/SAP%20Cloud%20Client%20CA.crt
  2. Add/import the certificate into the appropriate trust store / trust list used by the third-party integration.
  3. Ensure that the certificate is configured as a trusted intermediate CA certificate.
  4. Verify that the SAP Cloud Root CA certificate remains trusted.
  5. If applicable, validate the affected integration after importing the new certificate.

    It is recommended to complete this activity before the November 14th – 15th 2026 CMP window to avoid potential communication disruption when the new issuer becomes active.

    Certificate Chain

    Current certificate chain:

    M-User / Tenant Certificate
    ↓
    SAP Passport CA G2  – Intermediate CA
    ↓
    SAP Cloud Root CA – Root CA

    Certificate chain after the change:

    M-User / Tenant Certificate
    ↓
    SAP Cloud Client CA – Intermediate CA
    ↓
    SAP Cloud Root CA – Root CA

    Only the intermediate CA changes. The Root CA remains unchanged.

Frequently Asked Questions

What is changing?

The intermediate certificate issuer for the ByD M-User / Tenant certificate is changing from

SAP Passport CA G2 to SAP Cloud Client CA.

Is the Root CA changing?

No. The Root CA remains unchanged. Only the intermediate CA issuer is changing.

Who needs to take action?

Customers with third-party integrations that use or validate the ByD M-User / Tenant certificate should review their integration trust stores and add the new SAP Cloud Client CA certificate.

Do I need to remove SAP Passport CA G2?

No immediate removal is required as part of this change.

Customers should add the new SAP Cloud Client CA certificate to the relevant trust store. The existing SAP Passport CA G2 certificate may be retained to support certificates issued under the existing chain during the transition.

Where can I get the new certificate?

The SAP Cloud Client CA intermediate certificate can be downloaded from the SAP PKI certificate repository using the link provided below:

https://aia.pki.co.sap.com/aia/SAP%20Cloud%20Client%20CA.crt

What happens if I do not update the trust store?

If the external system does not trust the new intermediate CA, certificate-based communication with ByD may fail once the new issuer becomes active.

Does this affect all ByD customers?

The impact depends on the customer's integration architecture and whether third-party systems validate the ByD M-User / Tenant certificate chain using a locally maintained trust store or trust list.

Customers using such integrations should review their configuration and take the required action.

SAP Cloud Client CA – Intermediate Certificate

Customers with affected third-party integrations can download the SAP Cloud Client CA intermediate certificate from the SAP Global PKI repository and import it into the relevant trust store/trust list before the planned certificate issuer change.

SAP Cloud Client CA certificate: https://aia.pki.co.sap.com/aia/SAP%20Cloud%20Client%20CA.crt





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Chat with us on WhatsApp!