Show TOC

Procedure documentationAdding New SSL Access Points Locate this document in the navigation structure

 

You can use this procedure to add new SSL access points (ports). For example, you can open the default SSL port, which is 443.

Prerequisites

You have obtained the SAP Cryptographic Library and the corresponding license ticket and they are installed on the server. For more information, see Installing the SAP Cryptographic Library for SSL.

If the library and ticket are not yet installed in the correct place, you can use the Browse function to upload the files from the file system.

Procedure

  1. Start the SSL configuration tool in the SAP NetWeaver Administrator by following the path   Configuration Management   Security   SSL  .

  2. Select the instance for which you want to create a new access point. Choose the Edit pushbutton.

  3. In the SSL Access Points section, choose the Add pushbutton.

  4. Enter the number of the port which you want to open.

  5. Select the protocol to be used for the port.

  6. Select the Client Authentication Mode.

    The different modes have the following meaning:

    • Do Not Request - No certification is required and the server does not ask for one.

    • Request - The server asks the client to transfer a certificate. If the client does not send a certificate, authentication is performed using another method such as basic authentication (default setting).

    • Required - The client must transfer a valid certificate to the server, otherwise, access is denied.

  7. Select the keystore view that provides the server key pair and trusted CA certificates for the specified port:

  8. Choose the Save pushbutton.

    Note Note

    Before the changes take effect, you must restart the ICM.

    End of the note.

Result

When you create a new access point, the SSL configuration tool creates a keystore view for the specified port. The view contains the server key pair and trusted CA certificates to use for this port. The tool also automatically exports the view to a corresponding PSE file in the secudir.