cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Certificate based logon for Cloud application

former_member190457
Contributor
0 Likes
252

Hi all,

I'm developing a Cloud application deployed as a .war where I'd like to specify Certificate-based logon for all users.

From https://help.hana.ondemand.com/help/frameset.htm?e637f62abb571014857cb0232adc43a7.html I understand that this is not possible.

Is that right or anyone has a workaround/solution?

Thanks, regards

Vincenzo

View Entire Topic
Vlado
Product and Topic Expert
Product and Topic Expert
0 Likes

Hi Vincenzo,

Not exactly. You can specify CLIENT-CERT and it will work just as described for FORM, i.e. it will make a corresponding SAML2 request to the SAP ID service (or your custom identity provider if you have configured such).

Cheers,

--Vlado

former_member190457
Contributor
0 Likes

Hi Vlado

thanks for your help.

I would like users to login only with a certificate, so without typing user and password.

I'm browsing the docs for the FORM authentication to understand what it actually does.

Do you know if certificate based auth is possible?

Thanks,

Vincenzo

Vlado
Product and Topic Expert
Product and Topic Expert
0 Likes

Can you please provide some more details about your scenario? Which certificates would they use? Who is the issuer of the certificates?

Basically, the solution depends on whether SAP ID service knows about it and can validate the certificate and authenticate the user, or not.

Cheers,

--Vlado

former_member190457
Contributor
0 Likes

Hi Vlado,

I am an SAP colleague, I'd like users with SAP I/D/C-user certificate to logon without typing their user/pwd.

Can that be done? Please feel free to contact me privately by mail if you wish so.

Your help is much appreciated.

Thanks, Vincenzo

Vlado
Product and Topic Expert
Product and Topic Expert
0 Likes

Then it's easier. Just specify CLIENT-CERT in the web.xml and you are done.

SAP ID service will prompt the user for the certificate and will authenticate him/her after successful validation.