<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Config UME with ABAP+LDAP datasource in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479239#M224478</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Edgar Hussmann  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have exactly the same problem, also opened an OSS call without satisfying result (SAP´d only tried to sell their consulting).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[/thread/897899 &lt;A href="original link is broken"&gt;&lt;/A&gt;;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you manage to get your scenario running? Can you provide us your ume-xml as an example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely, Simon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jun 2008 08:41:34 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-06-03T08:41:34Z</dc:date>
    <item>
      <title>Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479231#M224470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are implementing an EP installation. We want to reuse the abap role assignment for the portal roles and we require a SSO solution based on SPNego.&lt;/P&gt;&lt;P&gt;Now we can implement each on it's own fine. The question is how we can connect the ume to use both abap and ldap datasource. I opened an OSS about it and they said it's possible, supported but I'm on my own when it comes to implementing it (or consulting offcourse).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone had experience with this configuration or can provide me with the datasource schema file?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank in advance,&lt;/P&gt;&lt;P&gt;Eric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jul 2006 11:07:41 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479231#M224470</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-07-30T11:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479232#M224471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understanding is that SAP does not currently support simultaneous ABAP and LDAP data sources. What SAP does support is an ABAP backend with LDAP synchronization:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04s/helpdata/en/0c/632441cd87a12be10000000a1550b0/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04s/helpdata/en/0c/632441cd87a12be10000000a1550b0/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not think that helps you with your authentication problem though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would importing the ABAP roles into the portal help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04s/helpdata/en/0c/632441cd87a12be10000000a1550b0/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04s/helpdata/en/0c/632441cd87a12be10000000a1550b0/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2006 07:11:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479232#M224471</guid>
      <dc:creator>MichaelShea</dc:creator>
      <dc:date>2006-07-31T07:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479233#M224472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to an OSS message I opened, this is indeed possible and similar scenarious are even described in the ADM200 course.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Imporitng roles into the portal is no good for me since I need the users which are assigned to these roles and not the name of the roles. This must be dynamic and not batched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2006 09:50:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479233#M224472</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-07-31T09:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479234#M224473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Michael replied such configuration is not supported by SAP at the moment. You should be able to achieve that though, by doing the following:&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;customization of the datasource xml file that you use, adding two datasources: ldap and abap. You can achieve that by using the provided templates, i.e. copy and paste from dataSourceConfiguration_abap.xml and dataSourceConfiguration_[your ldap server].xml the relevant datasource sections.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt; &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;Configure UME to use that customized xml file&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt; &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;Configure the LDAP connection configuration in the private section of the  LDAP datasource as explained here:&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw2004s/helpdata/en/4e/4d0d40c04af72ee10000000a1550b0/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw2004s/helpdata/en/4e/4d0d40c04af72ee10000000a1550b0/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;UL&gt;&lt;LI level="1" type="ul"&gt;&lt;P&gt;Configure the ABAP connection as explained here:&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw2004s/helpdata/en/4e/4d0d40c04af72ee10000000a1550b0/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw2004s/helpdata/en/4e/4d0d40c04af72ee10000000a1550b0/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that restart and you should be able to use the two systems as user stores. &lt;/P&gt;&lt;P&gt;Let me remind you again that this is not supported by SAP that is why you should do that configuration on your own risk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Ilian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jan 2007 20:38:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479234#M224473</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-01-11T20:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479235#M224474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please do the below setting for LDAP and ABAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;b&amp;gt;LDAP settings (only when ldap persistence is used)&amp;lt;/b&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ume.ldap.access.server_name : /H/sapgate1.wdf.sap.corp/S/3299/H/p102397.ume.wdf.sap.corp&lt;/P&gt;&lt;P&gt;ume.ldap.access.server_port         :  389&lt;/P&gt;&lt;P&gt;ume.ldap.access.user                    : cn=administrator, cn=users, dc=ume, dc=wdf, dc=sap, dc=corp               &lt;/P&gt;&lt;P&gt;ume.ldap.access.password           :  admin&lt;/P&gt;&lt;P&gt;ume.ldap.access.base_path.user  :  DC=ume, DC=wdf, DC=sap, DC=corp&lt;/P&gt;&lt;P&gt;Ume.ldap.access.base_path.grup :  dc=ume, dc=wdf, dc=sap, dc=corp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;b&amp;gt;Abap Settings (only when Abap Persistence is used)&amp;lt;/b&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Take one ABAP system: Ex: System Name: B4T, Client Num: 000&lt;/P&gt;&lt;P&gt;2. Login with user, who has admin rights.&lt;/P&gt;&lt;P&gt;3. Create user &amp;#147;J2EE_ADMIN&amp;#148; using &amp;#147;SU01&amp;#148; transaction.&lt;/P&gt;&lt;P&gt;4. Assign role &amp;#147;SAP_J2EE_ADMIN&amp;#148; (note: assign all roles).&lt;/P&gt;&lt;P&gt;5. Create user &amp;#147;J2EE_GUEST&amp;#148; using &amp;#147;SU01&amp;#148; transaction.&lt;/P&gt;&lt;P&gt;6. Assign role &amp;#147;SAP_J2EE_GUEST&amp;#148;.&lt;/P&gt;&lt;P&gt;7. Create communication user &amp;#147;COMUSER&amp;#148; using &amp;#147;SU01&amp;#148; transaction; usertype: communications.&lt;/P&gt;&lt;P&gt;8. Assign role&amp;#148; SAP_BC_JSF_COMMUNICATION&amp;#148;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ume.persistance.data_source_configuration:     dataSouceConfiguration_abap.xml&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;r3.connection.master.ashost                  /H/sapgate1.wdf.sap.corp/S/3299/H/ls4079&lt;/P&gt;&lt;P&gt;          &lt;/P&gt;&lt;P&gt; r3.connection.master.client                        :                  000  &lt;/P&gt;&lt;P&gt;          &lt;/P&gt;&lt;P&gt;  r3.connection.master.sysnr                       :                  09 &lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt; r3.connection.master.user                          :                 comuser (the sapjsf or communication user which we created in backend system)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  r3.connection.master.password                 :                test (it is the password of the com user which is in the backend system)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 05:39:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479235#M224474</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-01-12T05:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479236#M224475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Eric,&lt;/P&gt;&lt;P&gt;If you want, I can give an example Schema content that I'm using&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2007 13:36:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479236#M224475</guid>
      <dc:creator>HuseyinBilgen</dc:creator>
      <dc:date>2007-08-15T13:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479237#M224476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hussein Bilgen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´m concerned with the same problem (UME-Source = ABAP ; SSO via ADS-LDAP with SPNEGO).&lt;/P&gt;&lt;P&gt;Can you send me the example schema?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is there in the meantime a solution provided by SAP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edgar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2008 11:55:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479237#M224476</guid>
      <dc:creator>edgar_humann</dc:creator>
      <dc:date>2008-02-07T11:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479238#M224477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appologise in advance for this being a bit of s vendor sales pitch, but I think it is important and useful to many people who have posted in this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My company has a product which implements Integrated Windows Authenticaiton using SPNEGO protocol, but our product does not requrie any changes to data source. The product also uses C based Kerberos libraries rather than the somewhat dated Kerberos protocol support in Java SDK which is used by SAP SPNEGO login module. We can support any configuration of datasource required, so are not dependant on UME LDAP configuration. As far as I am aware the reason why SAP SPNEGO login module uses UME and LDAP data source is so it can determine the SAP user id after the user has been authenticated using Kerberos credentials. Our product uses a different approach - we map the principal/account name of the authenticated user onto a SAP id using one of many methods. At moment latest version of our product supports 2 methods of mapping, and we plan to add more. The 2 mapping methods are described below:&lt;/P&gt;&lt;P&gt;1. If user has authenticated as username@REALM we assume that their SAP user name = USERNAME (e.g. username converted to upper case). This method seems to be ok for many SAP customers.&lt;/P&gt;&lt;P&gt;2. If user has authenticated as username@REALM we look in USRACL table on ABAP system for a match, and if we find one we will know the SAP user id to use when creating the SSO2 ticket. This method of mapping is suited to customers who are also using SAP GUI SNC SSO and are therefore already maintaining the USRACL table mapping via SU01 t-code on ABAP system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate that this is vendor specific and not describing a SAP solution, but it is clear from this thread that people are trying to make SAP product do things it cannot - this is why vendors like us develop such solutions so we can fill the gaps &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need any more info on our product, please contact me using the email address in my SDN business card.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2008 12:12:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479238#M224477</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-07T12:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479239#M224478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Edgar Hussmann  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have exactly the same problem, also opened an OSS call without satisfying result (SAP´d only tried to sell their consulting).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[/thread/897899 &lt;A href="original link is broken"&gt;&lt;/A&gt;;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you manage to get your scenario running? Can you provide us your ume-xml as an example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely, Simon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 08:41:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479239#M224478</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-06-03T08:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479240#M224479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.	Download the SPNegoWizard_645.zip (for 7.0) SPNegoWizard_640 (for 6.40)from SAP Note 994791 and unzip it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.	Adjust the user running the SAP system in Active Directory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.	Copy the EAR and XML Files from the SPNegoWizard.ZIP file to a temporary directory on the server.&lt;/P&gt;&lt;P&gt;4.	Open up the Visual Administrator.  Logon with the admin ID.&lt;/P&gt;&lt;P&gt;5.	SID -&amp;gt;Server -&amp;gt; Services -&amp;gt; Deploy&lt;/P&gt;&lt;P&gt;6.	Open the Config Tool. (Yes to using DB settings)&lt;/P&gt;&lt;P&gt;7.	Select UME LDAP Data&lt;/P&gt;&lt;P&gt;8.	Browse to the XML file you copied earlier. (dataSourceConfiguration_ads_readonly_db_with_krb5.xml) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Click the upload button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9.	Select the Configuration file you just uploaded.  Click OK on the Warning message.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;10.	Setup the Connection details as specified below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server Name: xxxxxx&lt;/P&gt;&lt;P&gt;Server Port: xxxxxxx&lt;/P&gt;&lt;P&gt;User: SAPService&amp;lt;SID&amp;gt;@domain.com&lt;/P&gt;&lt;P&gt;Password:  xxxxxx&lt;/P&gt;&lt;P&gt;Use UME unique id with unique LDAP attribute (checked): samaccountname&lt;/P&gt;&lt;P&gt;User Path: dc=&amp;lt;domain&amp;gt;,dc=com&lt;/P&gt;&lt;P&gt;Group Path: ou=xxxxxx,ou=xxxx,dc=xxxx,dc=xxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;11.	Click the Test Connection button you should see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click Close when done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;12.	Click the Test Authentication button, enter NT user ID and NT password, and click the authenticate button and you should get a success message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;13.	Select cluster-data   Global Server Configuration  services  com.sap.security.core.ume.service&lt;/P&gt;&lt;P&gt;14.	Edit the ume.admin.addattrs.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Add the values: krb5principalname;kpnprefix;dn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click the Set button.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;15.	Click the Save button or File -&amp;gt; Apply.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;16.	Close the Config tool and restart the JAVA engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;17.	After the engine is restarted, continue on with the Kerberos configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;18.	Open up the SP Nego Wizard by going to the following URL: &lt;A href="http://&amp;lt;server&amp;gt;:&amp;lt;port&amp;gt;/spnego" target="test_blank"&gt;http://&amp;lt;server&amp;gt;:&amp;lt;port&amp;gt;/spnego&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;19.	Logon with the Administrator user ID.&lt;/P&gt;&lt;P&gt;20.	Select the check boxes for the u201CService user is created and configured in Active Directoryu201D and u201CUME configuration includes SPNego specific settingsu201D&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click the Next button &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;21.	Click the Add Kerberos Realm button and enter your domain name (e.g. company.com)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;22.	For the Realm Configurationu2019s KDCs (Key Distribution Centers) put in &amp;lt;KDC host&amp;gt; and 88 for the port (the port should already be filled in.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;23.	In the KPN (Kerberos Principal Name) section enter the Service User Name &amp;amp; Password.&lt;/P&gt;&lt;P&gt;Service User: SAPService&amp;lt;SID&amp;gt;		&lt;/P&gt;&lt;P&gt;Password: xxxx&lt;/P&gt;&lt;P&gt;Leave LDAP Host - blank&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;24.	Click the Next button &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;25.	Select Prefix Based for the Resolution Mode and Click Next &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;26.	In Policy Configuration we want to create a new policy called spnego.  Tick Basic password Fallback (when SSO do not work) and tick SSO with Logon Tickets.  Click the Next button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;27.	Click Finish on the Confirmation screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;28.	Close the browser and restart the engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;29.	After the engine has finished restarting, continue with the final steps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;30.	Open up the Visual Administrator.  Logon as the Administrator ID.&lt;/P&gt;&lt;P&gt;31.	SID  Server  Services  Security Provider&lt;/P&gt;&lt;P&gt;32.	Go into change mode by clicking the change button.&lt;/P&gt;&lt;P&gt;33.	On the Runtime tab  Policy Configurations tab  Select ticket from the Components list.&lt;/P&gt;&lt;P&gt;34.	On the Authentication tab for the ticket component  select Authentication Template: spnego&lt;/P&gt;&lt;P&gt;35.	Now go to the useradmin service (http://&amp;lt;server&amp;gt;:&amp;lt;port&amp;gt;/useradmin) to test the Kerberos SSO.  You should get signed on without entering a user name or password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are done!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 20:30:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479240#M224479</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-06-03T20:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Config UME with ABAP+LDAP datasource</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479241#M224480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ankur Agrawal  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for this guide. I´d like to be shure about the following criterias before implementing this:&lt;/P&gt;&lt;P&gt;- Roles from the ABAP Backend will still be converted into Portal Roles automatically, similar to the scenario when we configure the ABAP Backend as UME-Datasource&lt;/P&gt;&lt;P&gt;- User can have similar or different userid´s on the DataSources (Mapping required if they are different)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really doubt about the rolles beeing loaded automatically. Do you know this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely, Simon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jun 2008 07:26:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/config-ume-with-abap-ldap-datasource/m-p/1479241#M224480</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-06-04T07:26:00Z</dc:date>
    </item>
  </channel>
</rss>

