Enable JAVA SNC Certificate monitoring in FRUN

As part of many SAP landscapes, Secure Network Communication (SNC) is used to establish secure communication between ABAP and Java systems. If your environment is running with SNC-based communication between ABAP and ME/MII Java systems using SNC certificates stored in Java security directory.

While SAP Focused Run (FRUN) provides extensive monitoring capabilities, we identified a monitoring gap: there is no standard FRUN template available to monitor validity of Java SNC certificates. This means an expired certificate could go unnoticed until communication failures begin occurring between connected systems.

To address this gap, we developed a custom monitoring solution in SAP Focused Run that automatically tracks Java SNC certificate validity, calculates remaining days until expiration, and generates alerts before certificate expires.

Business Challenge

Communication between ABAP and Java systems relies on SNC certificates for secure authentication and encryption.

Java SNC certificate was deployed in the following location:
/usr/sap//J**/sec/SAPSNCS.pse

Although certificate is critical for secure communication, there was no proactive monitoring mechanism available in Focused Run to track its validity.

This created following risks:

Unplanned certificate expiration
ABAP to Java communication failures
Potential business process disruption
Manual monitoring effort
Lack of centralized visibility

Objective was therefore to provide proactive monitoring and alerting through SAP Focused Run.

Solution Overview

Implemented solution performs following functions:

Reads SNC certificate from Java PSE file.
Extracts certificate expiry date.
Calculates number of days remaining before expiration.
Generates output in JSON format.
Sends value to Focused Run through a custom metric.
Raises alerts when configured thresholds are reached.

Architecture Overview

SAPSNCS.pse
│
▼
sapgenpse export_own_cert
│
▼
OpenSSL Certificate Parsing
│
▼
Remaining Days Calculation
│
▼
JSON Output Generation
│
▼
FRUN Custom Metric
│
▼
Alerting & Notification

SNC Certificate Location

SNC certificate used by the Java system is stored in:
/usr/sap//J*/sec/SAPSNCS.pse

This PSE file contains the certificate information required for SNC communication.

Extracting Certificate Expiry Date

SAP utility sapgenpse can export certificate directly from PSE file.

sapgenpse export_own_cert -p SAPSNCS.pse | openssl x509 -noout -enddate

Example output: notAfter=Sep 29 15:45:21 2027

This date is then used to calculate remaining certificate validity.

Custom Monitoring Script

Following shell script was developed to calculate remaining days before certificate expiry.

#!/bin/bash
SAPGENPSE=”sapgenpse”
PSE_FILE=”SAPSNCS.pse”
expiry_date=$(
$SAPGENPSE export_own_cert -p “$PSE_FILE” 2>/dev/null |
openssl x509 -noout -enddate |
cut -d= -f2
)
 
expiry_epoch=$(date -d “$expiry_date” +%s)
current_epoch=$(date +%s)
 
diff_days=$(( (expiry_epoch – current_epoch) / 86400 ))
 
echo “{“type”:”integer”,”name”:”NumDays”,”value”:$diff_days}” \

/tmp/NUMDAYS.json

Sample Output

generated JSON file contains the certificate validity in days.

JSON
{
“type”:”integer”,
“name”:”NumDays”,
“value”:30
}

This output can be consumed directly by SAP Focused Run custom monitoring metrics.

Creating a Custom Metric in FRUN

Step 1: Create a Custom Monitoring Script

Deploy the script on the managed host where SAPSNCS.pse exists.

Example location:

Shell

/usr/sap/SID/J**/sec/calc_sapsnc_validity.sh

Step 2: Configure Simple Diagnostics Agent Script Metric

Create a new metric.

Example:

ParameterValue
Metric NameSNC Certificate Validity
Collection TypeScript
Scriptcalc_sapsnc_validity.sh
JSON AttributeNumDays
Metric TypeNumeric

Custom agent metric was configured in SAP Focused Run to collect generated JSON value.

Metric periodically collects remaining validity days and displays them centrally in FRUN monitoring dashboards.

This provides sufficient lead time for certificate renewal activities before the certificate reaches its expiration date.

Monitoring Benefits

This implementation delivers several operational benefits:

Closes a monitoring gap in SAP Focused Run Provides centralized certificate visibility

Closes a monitoring gap in SAP Focused Run
Provides centralized certificate visibility
Eliminates manual certificate validation checks
Enables proactive alerting
Reduces risk of ABAP-Java communication failures
Improves overall operational readiness
Prevents service disruptions caused by expired SNC certificates

Lessons Learned

During implementation, one challenge encountered was script compatibility after transferring files from Windows to Linux systems. Script initially contained Windows CRLF line endings, resulting in execution errors.

Converting script to UNIX format resolved the issue:
dos2unix calc_sapsnc_validity.sh

Conclusion

Java SNC communication is a critical component for secure integration between ABAP and Java systems. Since SAP Focused Run does not provide a standard monitoring template for Java SNC certificate validity, organizations may lack visibility into upcoming certificate expirations.

By implementing a lightweight custom monitoring solution using sapgenpse, OpenSSL, and SAP Focused Run custom metrics, we successfully introduced proactive monitoring and alerting for Java SNC certificates.

This approach is simple to implement, easy to maintain, and significantly reduces risk of communication outages caused by expired SNC certificates.

Have you implemented custom certificate monitoring in SAP Focused Run or SAP Solution Manager? Feel free to share your experience and monitoring approaches in the comments.

Author: Gaurav Dwivedi

Gaurav Dwivedi is an SAP Basis professional specializing in SAP Basis Admin operations, monitoring, SAP Focused Run, and automation within the SAP ecosystem. He is passionate about making the SAP world more automated and efficient, and actively shares practical, hands‑on technical knowledge through blogs and community engagement.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.