SAP NetWeaver Application Server ABAP Security Guide
User Authentication
Authentication and Single Sign-On
Logon and Password Security in the SAP System
Password Rules
Security Measures Related to Password Rules
Password Storage and Transport
Profile Parameters for Logon and Password (Login Parameters)
Secure Network Communications (SNC)
Client Certificates
SAP Logon Tickets
Pluggable Authentication Services
User Types
Protecting Standard Users
Defining a New Superuser and Deactivating SAP*
Preventing Unauthorized Logons
Recognizing and Preventing Multiple Dialog User Logons
Security Measures When Using SAP Shortcuts
Additional Information on User Authentication
SAP Authorization Concept
Overview
Organizing Authorization Administration
Organization if You Are Using the Profile Generator
Setting Up Administrators
Setting Up Role Maintenance
Authorization Objects Checked in Role Maintenance
Organization without the Profile Generator
Creating and Maintaining Authorizations/Profiles Manually
Authorization Checks
Reducing the Scope of Authorization Checks
Searching for Deactivated Authority Checks
Globally Deactivating Authorization Checks
Protective Measures for Special Profiles
Authorization Profile SAP_ALL
Authorization Profile SAP_NEW
User Information System
Central User Administration
Security Aspects of the CUA
Additional Information About the SAP Authorization Concept
Network Security for SAP Web AS ABAP
SAP Web AS ABAP Ports
Protecting Your Productive System (Change & Transport System)
The SAP System Landscape
The Three-Tier System Landscape
The Common Transport Directory
Using the TMS Quality Assurance Approval Procedure
Configuring the System Landscape for Changes
Release 3.1
As of Release 4.0
Defining the Transport Process
Transport Routes
The Transport Process
Responsibilities and Their Corresponding Authorizations
Roles and Responsibilities
Authorizations
Security for the RFC Connections
Default
TMS Trusted Services
Secure Network Communications
Protecting Security-Critical Objects
Protecting the System Profile Parameter Files
Protecting the Table for Maintaining System Clients (Table T000)
Protecting Other Security-Critical Objects
Emergency Changes in the Productive System
Additional Information on the Change and Transport System
Security Aspects When Using Business Objects
SAP Business Partner Security
SAP Product Security
Secure Store & Forward Mechanisms (SSF) and Digital Signatures
General Information
Protecting Keys
Protecting the Application Server’s Keys
Additional Information on SSF and Digital Signatures
Special Topics
Logical Operating System Commands
Restrict Authorizations for Maintaining External Commands
Restrict Authorizations for Executing External Commands
Additional Information on Logical Operating System Commands
Batch Input
An Overview of the Batch Input Process
Protecting the Batch Input Sessions
Protecting Disclosure of the SAPconnect RFC User
Preventing or Logging List Downloads
Internet Graphics Service Security