SSO with X.509 Client Certificate
Prerequisite: SSL Setup
Set up mutual SSL between each component, all the way from the Fiori Client to the Fiori front-end server.
|
Task |
Description |
|---|---|
|
Configuring the client to trust SAP Web Dispatcher |
You can have the SAP Web Dispatcher server certificate signed by a well-known CA which is already in the truststore as populated by the device manufacturer, or have it signed by an internal CA. In the latter case, use an MDM solution such as Afaria to distribute the signing certificate to the clients. |
|
Configure SSL termination and reencryption. Configure the SAP Web Dispatcher server port. Configure the connection to SAP Mobile Platform Server. |
|
|
Replace the default self-signed server certificate with a CA-signed certificate. |
|
|
Import the Afaria CA signing certificate into the truststore so that Web Dispatcher will trust the user certificate presented by the client. |
|
|
Import the CA certificate used to sign the SAP Mobile Platform Server certificate into the truststore. |
|
|
Replace the default self-signed certificate with a CA-signed certificate. |
|
|
Map the Impersonator role to the subjectDN of the SAP Web Dispatcher client PSE. |
|
|
Import the CA certificate used to sign the Fiori front-end server certificate into the SAP Mobile Platform keystore. |
|
|
Create a technical user certificate to be used for mutual SSL between SAP Mobile Platform Server and the Fiori front-end server. |
|
|
Import the SAP Mobile Platform Server technical user certificate into the truststore. |
Example Application Configuration in SAP Mobile Platform
Client Configuration
For information on how to configure SAP Fiori initial settings and authentication, see Application Configuration and Onboarding and the Fiori Client documentation at http://help.sap.com/fiori-client.