SAP Web Application Server Security Guide
SAP Web AS Network and Communication Security
SAP Web AS Security Guide for ABAP Technology
User Authentication
Authentication and Single Sign-On
Logon and Password Security in the SAP System
Password Rules
Security Measures Related to Password Rules
Password Storage and Transport
Profile Parameters for Logon and Password (Login Parameters)
Secure Network Communications (SNC)
Client Certificates
SAP Logon Tickets
Pluggable Authentication Services
User Types
Protecting Standard Users
Defining a New Superuser and Deactivating SAP*
Preventing Unauthorized Logons
Recognizing and Preventing Multiple Dialog User Logons
Security Measures When Using SAP Shortcuts
Additional Information on User Authentication
SAP Authorization Concept
Overview
Organizing Authorization Administration
Organization if You Are Using the Profile Generator
Setting Up Administrators
Setting Up Role Maintenance
Authorization Objects Checked in Role Maintenance
Organization without the Profile Generator
Creating and Maintaining Authorizations/Profiles Manually
Authorization Checks
Reducing the Scope of Authorization Checks
Searching for Deactivated Authority Checks
Globally Deactivating Authorization Checks
Protective Measures for Special Profiles
Authorization Profile SAP_ALL
Authorization Profile SAP_NEW
User Information System
Central User Administration
Security Aspects of the CUA
Additional Information About the SAP Authorization Concept
Network Security for SAP Web AS ABAP
Protecting Your Productive System (Change & Transport System)
The SAP System Landscape
The Three-Tier System Landscape
The Common Transport Directory
Using the TMS Quality Assurance Approval Procedure
Configuring the System Landscape for Changes
Release 3.1
As of Release 4.0
Defining the Transport Process
Transport Routes
The Transport Process
Responsibilities and Their Corresponding Authorizations
Roles and Responsibilities
Authorizations
Security for the RFC Connections
Default
TMS Trusted Services
Secure Network Communications
Protecting Security-Critical Objects
Protecting the System Profile Parameter Files
Protecting the Table for Maintaining System Clients (Table T000)
Protecting Other Security-Critical Objects
Emergency Changes in the Productive System
Additional Information on the Change and Transport System
Secure Store & Forward Mechanisms (SSF) and Digital Signatures
General Information
Protecting Keys
Protecting the Application Server’s Keys
Additional Information on SSF and Digital Signatures
Special Topics
Logical Operating System Commands
Restrict Authorizations for Maintaining External Commands
Restrict Authorizations for Executing External Commands
Additional Information on Logical Operating System Commands
Batch Input
An Overview of the Batch Input Process
Protecting the Batch Input Sessions
Protecting Disclosure of the SAPconnect RFC User
Preventing or Logging List Downloads
Internet Graphics Service Security
SAP Web AS Security Guide for Java Technology
Overview of Security for J2EE Application Types
Users and User Management
Users and Passwords
Standard Users and Groups
Storing the Password for the Administrator
Users Changing Their Own Data
User Authentication
Protecting Sessions Security
Monitoring and Logging of User Information
Authorizations
Network Security for the J2EE Engine
Java Virtual Machine Security
Disabling Optional Services on the J2EE Engine
Security Aspects for the Database Connection
Security on the JMS Service
Security Guide for the SAP System Landscape Directory
Securing HTTP(S) Connections to the SLD
Securing RFC/JCo Connections to the SLD
Network Topology for the SLD Server
Using Logon Tickets for Single Sign-On
Security Aspects When Using Remote Administration
Security Aspects When Using HTTP and Web Container Tracing
Internet Transaction Server Security
Defining SAP Transactions as Internet Applications
The Architecture of the Internet Transaction Server (ITS)
A Secure Network Infrastructure for the ITS
Protecting the Server and Network Components
Protecting the Web Server
Protecting the AGate Server
Protecting the SAP system Application Servers
TCP Ports Used by the ITS
Using the SAProuter
Using Other Firewall Components
Example Network Setup
An Example Network Setup (with Client LAN)
Using Additional Security Mechanisms / Providing Privacy
Authenticating Users
Authenticating Internet Users (Service Users)
Authenticating Named Users With User ID and Password
Authenticating Named Users Using X.509 Client Certificates
Security Measures When Using Client Certificates
Authenticating Named Users with Single Sign-On
Protecting Session Integrity
Security-Relevant Settings for IACs
SAP Web AS with Integrated ITS
Additional Information on SAP Internet Applications and the ITS
SAP Interactive Forms by Adobe Security Guide
Technical System Landscape
User Administration and Authentication
User Management
Authorizations
Network and Communication Security
Communication Channel Security
Communication Destinations
Data Storage Security
Other Security-Relevant Information
Trace and Log Files
Security Aspects with SAP Web AS System Management
Security Guide for the Solution Manager Diagnostics
Technical System Landscape: Security-Relevant Interfaces
User Authorization and Client Authentication
Users and Roles
Trace and Log Files
Background Processing
Defining Users for Background Processing
Specifying the Execution of External Programs from Job Steps
Authorizations Used in Background Processing
Security Guide for ADK-Based Data Archiving
Security Guide for XML-Based Data Archiving
Auditing and Logging
The Audit Info System (AIS)
The Security Audit Log
Example Filters
The System Log
Statistic Records in CCMS
Logging of Specific Activities
Application Logging
Logging Workflow Execution
Logging Using Change Documents
Logging Changes to Table Data
Logging Changes Made Using the Change & Transport System
Logging Changes Made to User and Authorization Information
Additional Information on Auditing and Logging
Virus Protection and SAP GUI Integrity Checks