SFTP connection fails in integration hub due to certificate trust issues

Our integration hub SFTP connection in SAP CX 2105 is failing with a certificate trust error. We’re trying to export customer data to an external SFTP server for our data warehouse integration, but the connection fails immediately with ‘certificate trust validation failed’.

The SFTP server uses a self-signed certificate, and we’ve tried importing it into what we thought was the correct trust store, but the error persists. The connection test in integration hub shows: “Unable to establish secure connection - server certificate not trusted”.

We’ve verified the SFTP server is accessible (we can connect using FileZilla with the same certificate), so the issue is specifically with how SAP CX integration hub is handling SFTP certificate management. The connection configuration looks correct - hostname, port, username are all valid.

This is blocking our nightly data export jobs. Anyone know the proper way to configure trust store for SFTP connections in the integration hub? We need help with SFTP certificate management and integration hub connection setup.

Let me provide a complete solution covering SFTP certificate management, trust store configuration, and integration hub connection setup for your scenario.

SFTP Certificate Management: The certificate trust validation failure occurs because SAP CX 2105 integration hub has strict certificate validation requirements for SFTP connections, especially with self-signed certificates. Here’s the proper certificate management approach:

  1. Export the complete certificate chain from your SFTP server:
openssl s_client -connect sftp.server.com:22 -starttls ftp -showcerts > sftp_cert_chain.pem
  1. Verify the certificate is in proper PEM format (should start with -----BEGIN CERTIFICATE-----). If you have a DER format certificate, convert it:
openssl x509 -inform der -in certificate.der -out certificate.pem
  1. For self-signed certificates, extract both the server certificate and create a trust anchor. Since it’s self-signed, the server cert IS the CA cert:
openssl x509 -in sftp_cert_chain.pem -out server_cert.pem
  1. Verify certificate details match your SFTP connection:
openssl x509 -in server_cert.pem -text -noout

Check that the CN (Common Name) or SAN (Subject Alternative Name) matches the hostname you’re using in integration hub configuration.

Trust Store Configuration: SAP CX 2105 uses separate trust stores for different integration types. For SFTP connections through integration hub, you must use the ‘Integration Services Trust Store’:

  1. Navigate to: SAP CX Administration > Security > Certificate Management > Trust Stores

  2. Select ‘Integration Services Trust Store’ (NOT System Trust Store or External Services Trust Store)

  3. Import the certificate:

    • Click ‘Import Certificate’
    • Upload the PEM format certificate file
    • Set alias: “sftp-server-cert” (descriptive name)
    • Category: Select ‘SFTP/FTP Servers’
    • Trust level: Set to ‘Trusted’
  4. Verify import success:

    • Check that certificate appears in trust store list
    • Verify expiration date is valid
    • Confirm alias is correctly set
  5. For certificate chains (if using CA-signed cert instead of self-signed), import in this order:

    • Root CA certificate first
    • Intermediate CA certificates (if any)
    • Server certificate last
  6. After import, you MUST restart the integration hub service:

    • Navigate to: Administration > System > Services
    • Select ‘Integration Hub Service’
    • Click ‘Restart’ (not just reload)
    • Wait 2-3 minutes for service to fully restart

Integration Hub Connection Setup: Now configure the SFTP connection properly in integration hub:

  1. Navigate to: Integration Hub > Connections > Create New Connection

  2. Connection type: Select ‘SFTP’

  3. Configure connection parameters:


Connection Name: DataWarehouse_SFTP
Host: sftp.server.com (MUST match certificate CN/SAN exactly)
Port: 22
Username: your_sftp_user
Authentication: SSH Key or Password
SSL/TLS: Enable
Certificate Validation: Enable (do not disable this)
Trust Store: Integration Services Trust Store
  1. Critical hostname matching:

    • If certificate CN is “sftp.server.com”, use exactly that in Host field
    • Do NOT use IP address if certificate has hostname CN
    • Do NOT use aliases or different subdomain names
  2. Advanced SFTP settings:


SSH Host Key Verification: Enable
Preferred Encryption: aes256-ctr,aes192-ctr,aes128-ctr
Connection Timeout: 30 seconds
Keep-Alive: Enable
  1. Test the connection:

    • Click ‘Test Connection’ button
    • Should now succeed with “Connection established successfully”
    • If still fails, check integration hub logs: /var/log/sap-cx/integration-hub.log
  2. Configure data export job:

    • Create scheduled job for nightly export
    • Use the configured SFTP connection
    • Set export path on SFTP server
    • Configure retry logic for transient failures

Troubleshooting Steps if Still Failing:

  1. Enable detailed SSL/TLS logging:

    • Administration > System > Logging
    • Set log level DEBUG for: com.sap.cx.integration.sftp.ssl
    • Set log level TRACE for: com.sap.cx.integration.connection
  2. Check logs for specific certificate validation errors:


tail -f /var/log/sap-cx/integration-hub.log | grep -i certificate
  1. Common issues and fixes:

    • “Certificate CN mismatch”: Use exact hostname from certificate CN in connection config
    • “Certificate expired”: Renew certificate and re-import to trust store
    • “Unable to find valid certification path”: Import complete certificate chain including root CA
    • “SSL handshake failed”: Check SFTP server supports TLS 1.2 or higher
  2. Verify certificate is active in integration hub:

    • Query trust store API: GET /api/v1/security/truststore/integration
    • Confirm your certificate alias appears in response

After completing these steps, your SFTP connection should work correctly. The key points are: use the Integration Services Trust Store (not System), restart the integration hub service after import, and ensure hostname in connection config exactly matches certificate CN. Test thoroughly before scheduling production data export jobs.


This draft is based on general SAP Customer Experience (SAP CX) knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

Self-signed certificates require special handling in SAP CX. You need to import the certificate into the SAP CX trust store, not just the integration hub configuration. The trust store location varies depending on your deployment model (cloud vs on-premise). For cloud deployments, you typically need to use the SAP CX administration console to upload the certificate.

I’ve dealt with SFTP certificate issues before. The problem is usually that the certificate chain isn’t complete. Even though you’re using a self-signed cert, SAP CX might be looking for intermediate certificates. Try exporting the full certificate chain from your SFTP server (including root and any intermediate certs) and import all of them into the trust store. Also make sure you’re importing to the correct trust store - SAP CX has separate trust stores for different connection types.

I exported the full certificate chain and tried importing it through the SAP CX admin console under Security > Trust Store Management. The import seemed to succeed, but the SFTP connection still fails with the same error. I’m wondering if there’s a specific trust store for SFTP connections that I’m missing? The admin console shows multiple trust stores (System, Integration, External Services).

You need to import the certificate into the ‘Integration’ trust store specifically, not the System trust store. The integration hub uses its own trust store for outbound connections. After importing, you also need to restart the integration hub service for the changes to take effect. In SAP CX 2105, there’s a known issue where trust store updates don’t propagate immediately to active connections.

Make sure the certificate format is correct. SAP CX integration hub expects certificates in PEM format for SFTP connections. If your certificate is in DER or other formats, convert it first using openssl. Also check the certificate’s CN (Common Name) matches the hostname you’re using in the SFTP connection configuration - mismatches will cause trust validation to fail even if the cert is in the trust store.