Symptom
Third-party integrations communicating with SAP Business ByDesign (ByD) using M-User / Tenant certificates may experience authentication or communication issues after the certificate issuer is changed, if the new intermediate certificate is not available in the trust store of the external system.
Background
The certificate issuer for SAP ByD M-User / Tenant certificates is being changed.
The issuer will transition as follows:
Current | New | |
Intermediate Issuer | SAP Passport CA G2 | SAP Cloud Client CA |
The SAP Cloud Client CA is the new intermediate CA certificate in the certificate chain used for the M-User / Tenant certificate.
Important
The Root CA certificate remains unchanged.
There is no change to the existing Root CA. Only the intermediate issuer in the certificate chain is changing from SAP Passport CA G2 to SAP Cloud Client CA.
Timelines
The change is tentatively planned for the CMP window of November 14th – 15th 2026.
The exact implementation timing is subject to the final change schedule.
Customers are recommended to complete the required trust-store updates before the planned change window.
Environment
SAP Bydesign
Cause
If you have third-party integrations that use the SAP ByD M-User / Tenant certificate for certificate-based authentication, the external system may need to trust the new intermediate CA certificate.
If the new SAP Cloud Client CA certificate is not available in the relevant trust store, the third-party system may not be able to establish a trusted certificate chain after the issuer change.
This can potentially result in authentication or communication failures for the affected integrations.
Resolution
Action Required
If you have third-party integrations using ByD M-User / Tenant certificates, please perform the following actions:
- Download the SAP Cloud Client CA intermediate certificate from the SAP Global PKI repository: – https://aia.pki.co.sap.com/aia/SAP%20Cloud%20Client%20CA.crt
- Add/import the certificate into the appropriate trust store / trust list used by the third-party integration.
- Ensure that the certificate is configured as a trusted intermediate CA certificate.
- Verify that the SAP Cloud Root CA certificate remains trusted.
- If applicable, validate the affected integration after importing the new certificate.
It is recommended to complete this activity before the November 14th – 15th 2026 CMP window to avoid potential communication disruption when the new issuer becomes active.
Certificate Chain
Current certificate chain:
M-User / Tenant Certificate
↓
SAP Passport CA G2 – Intermediate CA
↓
SAP Cloud Root CA – Root CACertificate chain after the change:
M-User / Tenant Certificate
↓
SAP Cloud Client CA – Intermediate CA
↓
SAP Cloud Root CA – Root CAOnly the intermediate CA changes. The Root CA remains unchanged.
Frequently Asked Questions
What is changing?
The intermediate certificate issuer for the ByD M-User / Tenant certificate is changing from
SAP Passport CA G2 to SAP Cloud Client CA.
Is the Root CA changing?
No. The Root CA remains unchanged. Only the intermediate CA issuer is changing.
Who needs to take action?
Customers with third-party integrations that use or validate the ByD M-User / Tenant certificate should review their integration trust stores and add the new SAP Cloud Client CA certificate.
Do I need to remove SAP Passport CA G2?
No immediate removal is required as part of this change.
Customers should add the new SAP Cloud Client CA certificate to the relevant trust store. The existing SAP Passport CA G2 certificate may be retained to support certificates issued under the existing chain during the transition.
Where can I get the new certificate?
The SAP Cloud Client CA intermediate certificate can be downloaded from the SAP PKI certificate repository using the link provided below:
https://aia.pki.co.sap.com/aia/SAP%20Cloud%20Client%20CA.crt
What happens if I do not update the trust store?
If the external system does not trust the new intermediate CA, certificate-based communication with ByD may fail once the new issuer becomes active.
Does this affect all ByD customers?
The impact depends on the customer's integration architecture and whether third-party systems validate the ByD M-User / Tenant certificate chain using a locally maintained trust store or trust list.
Customers using such integrations should review their configuration and take the required action.
SAP Cloud Client CA – Intermediate Certificate
Customers with affected third-party integrations can download the SAP Cloud Client CA intermediate certificate from the SAP Global PKI repository and import it into the relevant trust store/trust list before the planned certificate issuer change.
SAP Cloud Client CA certificate: https://aia.pki.co.sap.com/aia/SAP%20Cloud%20Client%20CA.crt
Source link


