cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Single Sign On Query

Debadata
Discoverer
0 Likes
454

Dear Team,

We want to implement SSO fr our customer on RISE, with multiple systems - SAP GUI, FIORI Apps, SF, C4C etc.

What's the best method. Please suggest.

Regards,

Debadata

Accepted Solutions (0)

Answers (2)

Answers (2)

Tobias_Lejczyk
Product and Topic Expert
Product and Topic Expert
0 Likes

Hi Debadata,

 

in general, you can distinguish between two scenarios:

1. SAP Gui
2. Browser based access (Fiori, most Cloud Applications, WebDynpro, ...)

 

For SAP Gui, to my knowledge, only the SAP solution using the Secure Login Client is supported in RISE. There, you need the CommonCryptoLib as a cryptographic library in the backend. You can use Kerberos, local x.509 client certificates (incl. SmartCards) or shortlived x.509 certificates from the Secure Login Service. The latter one allows for scenarios like Multifactor Authentication as well as an integration in the customers own authentication infrastructure.

For the Browser, the recommendation (https://discovery-center.cloud.sap/refArchDetail/ref-arch-cloud-leading-authentication) is to integrate with Cloud Identity Service (SCI) either via SAML2 or OIDC (sometimes you have the choice, sometimes the application only supports one or the other) and then integrate there with the customer authentication infrastructure using either some form of local authentication at SCI with MFA or certificates or WebAuthn, or use a corporate IdP as a central point of authentication integrating there with SAML2 or OIDC.

 

These are the most common scenarios, and as well the ones I have seen working in a lot of customer environments.

 

Best regards,
Tobias

tim_alsop
Active Contributor
0 Likes
The CyberSafe TrustBroker products are also widely used on SAP RISE and approved for use on SAP RISE. So, SAP Secure Login Client is not the only product available. These products offer SSO and MFA for both SAP GUI and Web access to SAP RISE systems.
tim_alsop
Active Contributor
0 Likes

You can use a product from SAP called SAP SSO (now called Secure Login Service for SAP GUI), or you can use a product from an SAP partner called TrustBroker. Most companies consider both products and decide which they prefer. Both can be used on SAP RISE systems. 

Thanks

Tim