Show TOC

 X.509 Certificates

 

If you have implemented a public-key infrastructure (PKI) for user authentication in your organization, you can use X.509 certificates by configuring the required back-end systems (ABAP or SAP HANA) to accept X.509 certificates.

Authentication with X.509 certificates provides the following advantages:

  • It does not require an issuing system during logon, which means that it works well in internet-facing scenarios.

  • It is also supported for logon to the SAP GUI. Using X.509 certificates for both SAP GUI and HTTP access simplifies the Single Sign-On setup within your system landscape.

X.509 certificates must be distributed to the workstations and devices that are used to access SAP Fiori apps. For mobile devices, this distribution can be performed centrally by a mobile device management software, for example SAP Afaria.

Recommendation Recommendation

As X.509 certificates remain valid for a relatively long time, we recommend that you minimize the security risk by implementing a method to revoke the certificates, for example if a mobile device is lost.

End of the recommendation.

Configuration

For information about the configuration that is required for X.509 certificates, see:

  • For SAP NetWeaver 7.31: Start of the navigation path http://help.sap.com/nw731Information published on SAP site Next navigation step Application Help Next navigation step Function-Oriented View Next navigation step Security Next navigation step User Authentication and Single Sign-On Next navigation step Integration in Single Sign-On (SSO) Environments Next navigation step Single Sign-On for Web-Based Access Next navigation step Using X.509 Client Certificates Next navigation step Using X.509 Client Certificates on the AS ABAP Next navigation step Configuring the AS ABAP to use X.509 Client Certificates End of the navigation path.

  • For SAP NetWeaver 7.4: Start of the navigation path http://help.sap.com/nw74Information published on SAP site Next navigation step Application Help Next navigation step Function-Oriented View Next navigation step Security Next navigation step User Authentication and Single Sign-On Next navigation step Integration in Single Sign-On (SSO) Environments Next navigation step Single Sign-On for Web-Based Access Next navigation step Using X.509 Client Certificates Next navigation step Using X.509 Client Certificates on the AS ABAP Next navigation step Configuring the AS ABAP to use X.509 Client Certificates End of the navigation path.