August 10, 2026 at 5:54 pm
hi , our business partner is asking s4 sap api's for receivable info and asking the jdbc adapter in sap's cloud middle ware to send a delete and insert to our sql staging table. his pc is not on our network.
our staging table sits on a 2022 std edition vm instance of sql server.
he uses a tunnel. we've confirmed the windows creds he passes are set up properly in the OS and sql. he continually gets failed logins. he appends our domain name on everything. i told him our vm / os is notorious for requiring encryption. i asked if he is encrypting. his response was "only if its pgp encrypted". i dont know what that means.
does the community have any advice?
August 10, 2026 at 6:01 pm
this is one of the earlier errors.

August 10, 2026 at 6:18 pm
when he changed to tcp ssl from tcp on the tunnel , he got this. he is actually targeting port 1433.

August 10, 2026 at 7:12 pm
our partner just saw something that suggests windows auth isnt allowed with this adpter. its tough to decipher because reading it one way it almost sounds like thats dependent on the compatibility level/version of the adapter. and the doc refers to "on prem database" which our vm isnt.

August 11, 2026 at 12:46 am
I don't work with this type of thing but my response should "bump" your post closer to the top again.
--Jeff Moden
Change is inevitable... Change for the better is not.
August 11, 2026 at 12:00 pm
im starting to wonder if a jdbc driver / adapter needs to be installed on the vm as well so these 2 endpoints can communicate. and even if we have one already, if not configured just right can even do this handshake.
August 11, 2026 at 5:38 pm
im told no to needing a jdbc driver on the vm.
in the mean time, our partner steered me away from AD logins in favor of sql logins. and he somehow wrapped something (connection?) in a java program instead of the cpi middleware.
that program gave him a more specific error , perhaps one being masked by his middleware which uses a try catch. it said he needs to change the pswd. grudgingly i did that and the java program worked. he's trying the new pswd in his middleware. stay tuned.
i hope we dont need to change the pswd every time he connects.
i checked all the settings recommended by ai and saw one that maybe we'll ask our infrastructure guys about later. it is titled "opening the vm firewall" and reads like this "Add an inbound port rule in the VM's guest operating system firewall (and network security groups if hosted on Azure/AWS) to allow incoming traffic on TCP port 1433."
August 12, 2026 at 11:52 am
here is an update. our peer installed a "one version older driver" (than 11 something) to try getting around any overly restrictive handshake issues between sap's cpi adapter and our sql vm. for this first time it didnt fail but he had to kill it after 3 hrs of nothing happening on only 15000 inserts. to be totally honest we dont know what our dba was doing in the meantime so there may have been an update to the vm as well...our dba was doing something while we were on the call. i got a look at this cpi adapter on this call and basically now know he draws ssis like transforms right there in the cloud on this cpi command console. i cant imagine where that older version of the driver gets installed for a cloud based tool like this but perhaps on the machine hosting the tunnel cpi insists on using. at the moment i cant reboot that vm but certainly we'll sneak that in and try cpi again. in the mean time we are talking about some alternatives including targeting ftp flat file folders. we'd try an on prem sql as a target but i dont think on prem is going to be around here forever. we are also talking about coldfusion using (i think) the output of the cpi api calls to handshake directly with our vm with no tunnel between. i hope i said that correctly as sometimes i have to read between the lines when i only hear what people are doing without seeing for myself.
Viewing 8 posts - 1 through 8 (of 8 total)
You must be logged in to reply to this topic. Login to reply