Hello All,
What is the best practice to setup authentication between API Management and Cloud Integration in scenarios where APIM must trigger a CPI iFlow?
I normally prefer using certificate based authentication by setting up a keystore in APIM and use that in the API provider that is configured for CPI. In CPI, I upload the public certificate of the keystore in the service key. However, we must purchase a certificate keypair signed by a authorised certificate authority or use a S-User generated certificate on SAP Passport. I am not aware if there is any other way to setup a key pair. Interested to know if someone can share their experience here.
I am aware that you can also use OAuth with CPI buy you must create policies inside API proxy to authenticate. Hence, I prefer the certificate based because there is no need to add additional policies in the proxy. I am curious to know how you setup this authentication in your projects?
Thanks in advance!
Request clarification before answering.
Now a days SAP generated certificate can be used. There is no need to purchase certificates. This option is mentioned in the documentation as "SAP certificate" See Client Certificate Authentication for Integration Flow Processing | SAP Help Portal. This was detailed in the blog post Cloud Integration on CF - How to Setup Secure HTTP... - SAP Community
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.