System Security
System Security for SAP Web AS ABAP Only
Trust Manager
Getting Started with the Trust Manager
The PSE Types
System PSE
SNC PSE
SSL Server PSE
SSL Client PSEs
File PSE
SSF Application PSEs
Creating PSEs and Maintaining the PSE Infrastructure
Checking the Local Status of Distributed PSEs
Creating or Replacing a PSE
Maintaining PSEs and Managing Certificates
Maintaining the Certificate List
Maintaining Certificates in the Database
Adding a Certificate to the Database
Removing a Certificate From the Database
Retrieving a Certificate From the Database
Deactivating Certificates in the Database
Example
Configuring the SAP Web AS for Supporting SSL
Creating the SSL Server PSE
Generating Certificate Requests for the SSL Server PSEs
Sending the Certificate Requests to a CA
Importing the Certificate Request Response
Maintaining the SSL Server PSE's Certificate List
Creating the Standard SSL Client PSE
Creating the Anonymous SSL Client PSE
Creating Individual SSL Client PSEs
Specifying that a Connection Should Use SSL
Testing the SSL Configuration
Making Sure the SSL Port is Set up Correctly
Testing the Connection for SSL Server Authentication
Testing the Connection for SSL Client Authentication
Terminology and Abbreviations
Certificate List
Certification Authority (CA)
Credentials
Logon Ticket
Personal Security Environment (PSE)
Private Key
Public Key
Public-Key Certificate
Public-Key Infrastructure (PKI)
Public-Key Technology
SAP Cryptographic Library (SAPCRYPTOLIB)
SAP Security Library (SAPSECULIB)
Secure Sockets Layer (SSL) Protocol
Secure Store & Forward (SSF)
SSO Personal Security Environment (SSO PSE)
System PSE
Verification PSE
Security Audit Log (BC-SEC)
The Design of the Security Audit Log
Comparing the Security Audit Log and the System Log
Maintaining Static Profiles
Changing Filters Dynamically
Defining Filters
Displaying the Audit Analysis Report
Reading the Audit Analysis Report
Deleting Old Audit Files
Security Alerts in the CCMS Alert Monitor
Viewing Security Alerts
Reading Security Alerts Using BAPIs
The Audit Log Display Options
Example Filters
Secure Storage (ABAP)
Checking Entries
Choosing Your Own Key
Switching Keys
Migrating Encrypted Data After Changing Installation Number
System Security for SAP Web AS Java Only
Key Storage Service
Managing Key Storage Views
Managing Entries
Creating a Key Pair and Public-Key Certificate
Managing the Credentials and Trusted Certificates to Use SSL
Managing Code Based Permissions
Managing Cryptography Providers
Managing Protection Domains
Web Services Security
Secure Storage for Application-Specific Data
Replacing an Application’s Secret Key
Secure Storage in the File System
Deploying the SAP Java Cryptographic Toolkit
Managing Secure Storage in the File System
Managing Login Sessions
Virus Scan Interface
Architecture of the Virus Scan Interface
ABAP-Specific Configuration
Setting Up the Virus Scan Interface
Defining Scanner Groups
Defining Virus Scan Servers
Application-Server-Starter or Self-Starter
Virus Scan Server as an Application-Server-Starter
Installing a Virus Scan Server as a Self-Starter
Operating the Self-Starter
Configuring the Self-Starter
Defining Virus Scan Profiles
Delivered Virus Scan Profiles
Delivered Parameters
Implementing a BAdI for Virus Scanners
Using Signals to Control the Virus Scan Server
Problem Analysis for the Virus Scan Server
Testing the Installation of the Virus Scan Server
Integrating the Virus Scan Interface into Customer Developments
Commented Example Program
Java-Specific Configuration
Setting Up Virus Scan Providers
Defining Scanner Groups
Defining Virus Scan Providers
Defining Virus Scan Profiles
Delivered Virus Scan Profiles
Delivered Parameters
Problem Analysis for the Virus Scan Provider
Testing the Installation of the Virus Scan Provider
Interfaces and Classes of the Virus Scan Provider API
Example Program for the Virus Scan Provider
Checking User Input for Program Commands