HTTP Transport Level
Authentication
When you use HTTP transport level authentication for Web services, the authentication information is contained in the HTTP header. Thereby, the authentication mechanisms for consuming and providing WS for SAP NetWeaver components rely on the authentication infrastructure for Web based access over HTTP.
HTTP transport level authentication enables you to use point-to-point security and authentication that is designed for the client-server communication patterns for Web-based access over the HTTP communication protocol. HTTP transport level authentication for SAP NetWeaver uses the same communication channel for access and authentication infrastructure as authentication for Web-based access, therefore similar security considerations apply.
For more information about the security considerations for the corresponding Web-based authentication mechanisms, see the following sections in Authentication for Web-based access:
● Basic Authentication (User ID and Password)
● X.509 Certificates
● Logon Tickets