Check the below points
Point 1
Check ur user id is there in R3 system or (the same userid as in portal).
If the same userid is not there . go for usermapping ,and try again .
Point 2
any way you did below work. could you please check once again
Setup parameters "icm/host_name_full ","login/accept_sso2"_ticket (parameter value "1") and "login/create_sso2_ticket" (value 2) – Already existing
3) Import the above frontend cert into backend (Strustsso2), added to certificate list and ACL.
4).Export certifcate from backend(ABAP) and import into Keystore.
Pls check the following Snotes 1405432& 1566201 & 0001405432