Heads-up: Amazon Simple Email Services (SES) change Certificates
Relevant to all SAP Hybris Marketing Customers who send their marketing emails via Amazon SES:
Beginning of January 2018 Amazon has started to exchange Root Certificates and sent out corresponding mails to there customers.
If customers ignore these emails hence do not upload the new certificates various issues when trying to send E-mails via Amazon SES might occur:
- Test send does not work
- Start of campaign does not work
- Check report shows errors for HTTP destination in Provider section
- Camapaign execution stops or is slow
- Application Log shows ‘HTTP request failed’ errors like ‘SSL handschake with email.xxx.amazonaws.com or ‘ICM_HTTP_SSL_PEER_CERT_UNTRUSTED’
For more information, see Blog “Amazon SES and the Amazon Trust Services Migration” https://aws.amazon.com/blogs/ses/669-2/
- Go to page https://www.amazontrust.com/repository/ and download the Root Certificates there (all of them via the corresponding DER link)
- Afterwards upload those certificates via “Maintain Certificate Trust List App” to the SAP Hybris Marketing System
Hello Matthias Reiner,
Thank you so much for this blog.
I was able to get it to work on YMKT on-premise Version after recreating the whole SES configuration, which involved SES Certification upload step.
Whereas in YMKT cloud I was not aware where and how to upload the Certificate. Your blog here helped me. Thank you so much.
To download the certificate, you might as well refer this blog to download the certificate, which you can then upload it using the "Maintain Certificate Trust List App".