Creating a Trusted Relationship with Enterprise Search 
To permit searches using the identity (and thus the permissions) of the user logged on to the Search UI and to allow the user to access the data related to the search results directly in the back-end system, you must establish a trusted relationship between SAP NetWeaver Enterprise Search and the Application Server ABAP of the back-end system.
The Application Server ABAP of the back-end system must be configured to accept logon tickets. See the Checking Profile Parameters section.
You must work through the following steps in the SAP system for SAP NetWeaver Enterprise Search:
Run transaction STRUSTSSO2. To do this, you require authorization for client 000.
In the left tree view, navigate to the system on which SAP NetWeaver Enterprise Search is installed and double-click the entry.
In the upper area, Own Certificate, double-click the entry in the Owner field.
Choose the menu path and export the SAP certificate, specifying the name LogonTicketKeypair_Cert, to a location that can be reached from the back-end system.
Log on to the back-end ABAP system with an administrator user.
Run transaction STRUSTSSO2. To do this, you require authorization for client 000.
Note
The layout of the transaction window varies slightly, depending on the release of the SAP system.
On the left side, select the entry for the back-end system.
Choose the menu path .
The Import Certificate screen appears.
Select the file you exported beforehand and specify the file format of the file to be imported.
In the Certificates area, choose the Add to Certificate List command.
Choose Add to ACL, to add SAP NetWeaver Enterprise Search to the ACL list.
In the dialog box that appears, enter the SAP system ID of SAP NetWeaver Enterprise Search and the client 000.
Save your entry.
Start transaction RZ10 on the back-end ABAP system.
Choose the instance profile extended maintenance.
Choose Change.
Make sure that login/create_sso2_ticket is set to 2 and login/accept_sso2_ticket is set to 1.