!--a11y-->
Secure Network Communications 
Because the user authentication occurs externally and not within the SAP system itself, you must use Secure Network Communications (SNC) between the ITS AGate and the ticket-issuing application server. When using SNC, the data transfer is encrypted so that the logon ticket cannot be stolen or manipulated.

We also recommend the following:
· If you use an external mechanism that takes place on the Web server, and the ITS is a dual host installation, then we also recommend using SNC for the connection between the WGate and the AGate.
· We also recommend using SNC for the connections between the ITS components and application servers for systems that accept logon tickets.
· For connections that use the HTTP protocol, for example, connections to an SAP Web Application Server, we recommend using the Secure Sockets Layer (SSL) protocol instead of SNC.
SNC requires the use of an external security product to provide the protection. For server-to-server connections such as the connection between the application server and the AGate, you can use the SAP Cryptographic Library, which is available on the SAP Service Marketplace for authorized customers at http://service.sap.com/swcenter.
Otherwise, you must use an SAP-certified partner product. For a list of these products, see the SAP Software Partner Program at http://www.sap.com/softwarepartner. Search in the Software Partner Directory using the software category Network Security.
See also:
· SNC User’s Guide
·
Using the SAP Cryptographic Library for
SNC
These documents are available on the SAP Service Marketplace at http://service.sap.com/security.
