Configuring the Trust Relationship for SAML Token Profiles Without Logon Ticket Configuraiton for Validation with the Ticket PSE


If you do not want to use logon tickets in your system landscape, you need to manually configure the trust relationship between the systems and exchange the certificates.


  1. Export the WS provider certificate.

    For more information, see the following:

  2. Import the WS provider's certificate into the WS consumer.

  3. Export the certificate of the WS consume.

    For more information, see the following:

  4. Import the WS consumer certificate into the WS provider.

  5. Include the imported certificates in the access control lists of systems, if necessary