Entering content frameProcedure documentation Configuring the System for Accepting Logon Tickets Locate the document in its SAP Library structure

Use

Accepting systems need to be able to verify the logon tickets and the issuing server’s digital signature. The following information is necessary for the verification:

The SSO administration wizard accomplishes these configuration tasks automatically. The rest of the configuration tasks and the steps you need to take to use the SSO administration wizard are described below.

Prerequisites

You can obtain the most recent version of the SAP Security Library from the sapserv<x> under /general/misc/security/SAPSECU/<platform>.

The SAP Cryptographic Library is available on the SAP Service Marketplace at http://service.sap.com/swcenter. Note however, the delivery of this library underlies German export regulations and is not available to all customers. For more information, see Using the Secure Sockets Layer Protocol.

Procedure

On all of the accepting system's application servers

  1. Set the profile parameter login/accept_sso2_ticket = 1. Set login/create_sso2_ticket = 0 unless the server should also be able to issue tickets. (Use DEFAULT.PFL.)
  2. For Releases 4.0 and 4.5, also set the profile parameter SAPSECULIB to the location (path and file name) of the SAP Security Library (or SAP Cryptographic Library).

On one of the accepting system's application servers

  1. Execute the SSO administration wizard (transaction SSO2).
  2. The SSO2 Administration screen appears.

  3. Enter the RFC destination or the <host name> and <system number> for the issuing server in the appropriate fields.

Note

Note the following:

The SSO administration report for the designated server is displayed.

The following information is shown in the report:

Red traffic lights in any of these areas indicate configurations that are not operational for using logon tickets.

  1. If the report indicates errors on the issuing server (for example, profile parameters are not set correctly), correct these errors on the issuing server and re-execute the SSO administration wizard on the accepting system.
  2. To initiate the configuration steps on the accepting system, choose Edit ® Activate Workplace (This graphic is explained in the accompanying text).

The following occurs:

Note

If the DIR_PROFILE directory is not globally accessible to all of the application servers in the accepting system, then you have to manually copy the SSO PSE to each application server’s DIR_PROFILE directory.

Note

All changes take place immediately and you do not have to explicitly save any data.

If any of the areas indicate errors, correct these errors and re-execute the SSO administration wizard.

Note

You can also add or delete entries from the access control list or certificate list by placing the cursor on the appropriate line and choosing Edit ® <function>.

Example

For example:

Note

You can also manually change the access control list (table TWPSSO2ACL) using the table maintenance transactions (for example, SM30).

You can also manually change the certificate list using the PSE maintenance transaction (PSEMAINT) or the trust manager (transaction STRUST).

The PSE maintenance transaction PSEMAINT is available for SAP Systems <= Release 4.6D and the trust manager (transaction STRUST) is available with the SAP Web Application Server.

Result

The accepting systems are able to accept logon tickets and verify the issuing server’s digital signature when they receive an logon ticket from a user.

Note

You may execute the SSO administration wizard at any time and as often as you wish.

 

 

 

Leaving content frame