<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssl re-encryption : multiple certificates required? in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257189#M1384477</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your answer in regards to the shared PSE, I think this almost answers the question. &lt;/P&gt;&lt;P&gt;Should I generate the PSE in the WAS and export to the Web Dispatcher ot rather generate in Web Dispatcher(sapgenpse) and import into WAS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In regards to your first paragraph:&lt;/P&gt;&lt;P&gt;Unfortunately I was instructed to use re-encryption on SSL all the way to the WAS.&lt;/P&gt;&lt;P&gt;How heavy is the load caused by the web dispatcher in this case? Is it a case of marginal CPU load or should I have a seperate box for the WAS? Currently I have installed it on the same box as the CI? (The web dispatcher will only be used for load balancing, we have MS ISA servers as reverse proxies).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;&lt;P&gt;Adriaan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Nov 2009 07:48:50 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-11-09T07:48:50Z</dc:date>
    <item>
      <title>ssl re-encryption : multiple certificates required?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257187#M1384475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am setting up a Web Dispatcher for SSL. It must use re-encryption. (going live with E-recruiting)&lt;/P&gt;&lt;P&gt;Do I need a seperate generated certificate for the Web Dispatcher and the ABAP WAS backend?&lt;/P&gt;&lt;P&gt;I would prefer to make one single request to the CA and use the certificate for both the Web Dispatcher and thr ABAP WAS backend.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Adriaan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 07:01:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257187#M1384475</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-09T07:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: ssl re-encryption : multiple certificates required?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257188#M1384476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why does e-Recruiting require "re-encryption"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you terminating connections on the webdispatcher? This anyway means that you will need to have a high level of trust and security on the webdispatcher itself... and if you encrypt again then your webdispatcher might become a performance bottleneck in the design...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, if you create a certificate request for a shared PSE, then they will have the same identity and you can use the same response for both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 07:30:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257188#M1384476</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-09T07:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: ssl re-encryption : multiple certificates required?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257189#M1384477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your answer in regards to the shared PSE, I think this almost answers the question. &lt;/P&gt;&lt;P&gt;Should I generate the PSE in the WAS and export to the Web Dispatcher ot rather generate in Web Dispatcher(sapgenpse) and import into WAS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In regards to your first paragraph:&lt;/P&gt;&lt;P&gt;Unfortunately I was instructed to use re-encryption on SSL all the way to the WAS.&lt;/P&gt;&lt;P&gt;How heavy is the load caused by the web dispatcher in this case? Is it a case of marginal CPU load or should I have a seperate box for the WAS? Currently I have installed it on the same box as the CI? (The web dispatcher will only be used for load balancing, we have MS ISA servers as reverse proxies).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;&lt;P&gt;Adriaan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 07:48:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257189#M1384477</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-09T07:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: ssl re-encryption : multiple certificates required?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257190#M1384478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is much easier to do in STRUST than sapgenpse, but I have also read in a manual that you should not mix use of the two. No reason was given - perhaps someone else knows and has run into troubles with it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understand correctly, you are NOT using session termination as I originally thought, but rather using the webdispatcher as a load balancer and need to decrypt the https requests to know which server the user already is logged onto?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this is unnecessarily complicated... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are keeping the session connected, then why don´t you point your webdispatcher to the message server and let that balance the user load. It also natively knows which servers are available and is much easier to implement?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 18:06:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ssl-re-encryption-multiple-certificates-required/m-p/6257190#M1384478</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-09T18:06:31Z</dc:date>
    </item>
  </channel>
</rss>

