<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP AS JAVA Cross domain SSO in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-cross-domain-sso/m-p/8074671#M1613942</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are 2 possible ideas as workaround :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;If the last part of the 2 domains is the same, you can use Domain Relaxing ( ume.logon.security.relax_domain.level  in Visual Admin). For exemple; 1rst FQDN is websiteA.townA.company.com and 2nd FQDN is crm.townB.company.com, you would have to use ume.logon.security.relax_domain.level = 2)&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;You can install a Reverse Proxy (SAP Web Dispatcher for exemple ) for one system in the domain of the other system.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So URL wise, the 2 systems will be in the same domain and the SAP Logon Ticket cookie will work for SSO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jul 2011 10:44:08 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2011-07-15T10:44:08Z</dc:date>
    <item>
      <title>SAP AS JAVA Cross domain SSO</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-cross-domain-sso/m-p/8074670#M1613941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the one side I have a website (A) with the ability to authenticate users which also allows them to do some password self service in the event of forgotten passwords and such. On the other side I have a SAP CRM Java Web Shop deployment where I want to reuse websites (A) authentication processes in the SAP CRM Java Web Shop so that if a user authenticates against website (A) they are trusted by SAP CRM Java Web Shop and authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I donu2019t know is how to do this for websites in different domains and hosted by physically different parties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to link the external authentication process to the SAP AS JAVA system via a SSO configuration supported by SAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Willem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 10:19:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-cross-domain-sso/m-p/8074670#M1613941</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-07-15T10:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS JAVA Cross domain SSO</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-cross-domain-sso/m-p/8074671#M1613942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are 2 possible ideas as workaround :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;If the last part of the 2 domains is the same, you can use Domain Relaxing ( ume.logon.security.relax_domain.level  in Visual Admin). For exemple; 1rst FQDN is websiteA.townA.company.com and 2nd FQDN is crm.townB.company.com, you would have to use ume.logon.security.relax_domain.level = 2)&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;You can install a Reverse Proxy (SAP Web Dispatcher for exemple ) for one system in the domain of the other system.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So URL wise, the 2 systems will be in the same domain and the SAP Logon Ticket cookie will work for SSO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 10:44:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-cross-domain-sso/m-p/8074671#M1613942</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-07-15T10:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAP AS JAVA Cross domain SSO</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-cross-domain-sso/m-p/8074672#M1613943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to check the option of using SAML 2.0 authentication in case both parties support it. With SAML 2.0 you do not need systems to be in the same domain.&lt;/P&gt;&lt;P&gt;AS Java supports SAML 2.0 from 7.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Single Sign-On with SAML 2.0 wiki page|http://wiki.sdn.sap.com/wiki/display/Security/Single&lt;EM&gt;Sign-On&lt;/EM&gt;with&lt;EM&gt;SAML&lt;/EM&gt;2.0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt; Desislava&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Desislava Petkova on Aug 29, 2011 4:45 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Aug 2011 14:45:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-as-java-cross-domain-sso/m-p/8074672#M1613943</guid>
      <dc:creator>former_member269672</dc:creator>
      <dc:date>2011-08-29T14:45:46Z</dc:date>
    </item>
  </channel>
</rss>

