Hi,
I've used the SNCWIZARD to configure SNC SSO via the Secure logon client, and used SPNego to configure the keytab, however we don't want to enable Spnego via HTTP.
Does anyone know if it is possible to disable SPNego (via RZ10 parameter) but still use the SPNEGO transaction to maintain the keytab, or do we need to create a separate SAPSNCKERB.pse file?
Many thanks,
Jason
Request clarification before answering.
Hello Jason,
You will not be able to use the transaction to configure the keytab for SNC if SPNego is disabled.
Regards,
Donka Dimitrova
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Well, actually it's the other way round:
If you use t-code SPNEGO to create a keytab, then SPNego will be activated.
So, if you do not like SPNego to be activated, you must not use t-code SPNEGO to create a keytab.
That's actually independent from the SNC library - in order to be able to use SPNego you have to use a(ny) Kerberos-based SNC library, however (since SPNego and SNC are sharing the same mappings). The t-code SNCWIZARD, however, will only work when using the CommonCryptoLib as SNC library.
This has changed (recently) - see SAP Note 2287976, providing a solution.
Hi Donka,
Can you please help me? on below discussion? Error in SSO with kerberos SNCWIZARD method.
http://scn.sap.com/thread/3958917
Regards,
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.