SAP NetWeaver Application Server Java Security Guide
Before You Start
Technical System Landscape
User Administration and Authentication
User Administration and Standard Users
User Administration Tools
User Data Synchronization
Authentication Mechanisms and Single Sign-On Integration
Declarative and Programmatic Authentication
Login Modules and Login Module Stacks
Authentication Schemes
Integration in Single Sign-On Environments
Authorizations
Network Security
Transport Layer Security
Communication Channel Security
Using an Intermediary Server to Connect to the AS Java
Communication Security for the Web Container
Communication Security for the EJB Container
Communication Security for Web Services
Communication Security for Persistency Stores
Communication Security for Software Deployment
AS Java Ports
Data Storage Security
Dispensable Functions with Impacts on Security
Other Security Relevant Information
JMS Provider Security Aspects
Java Virtual Machine Security
Security Aspects for Database Connections
Destination Service
Session Security Protection
Improved Protection Versus Login-XSRF
Parallel HTTP Requests and Session Fixation Protection
Tracing and Logging
Logging and Tracing
Masking Security-Sensitive Data in the HTTP Access Log