Hi All,
Let me know what are the minimum steps required for SSO configuration so to access Transaction iviews from portal .
I have some documents , but those also include SSO with BI . But I want to do SSO only to ECC .
Regards,
Surya
Request clarification before answering.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Surya,
steps given by GLM, are sufficient for SSO.
Just check the dates when exporting the certificates and the user names in java stack and ABAP stack i.e Portal and R/3 must be same.
The other simplest way is to go for SSO with user mapping which doesn't require these exporting of certificates and you don need to have same user name also. Let me know if you eed any more info on this.
Regards,
Yogesh...
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Deepa is correct.
The wiki is at the top (next to the forums link). From there go into portal.
Or just go straight to here:
https://wiki.sdn.sap.com/wiki/x/vik
Paul
Hi,
A.Single Sign-On using SAP logon tickets without user mapping
1)Users must have the same user IDs in all SAP systems that are accessed via SSO with SAP logon tickets.
2) If the SAP user IDs are the same as the portal user IDs, user mapping is not required. You need to perform the following steps:
a) Configure Portal Server for SSO with SAP Logon Tickets
b) Configure SAP Systems to Accept and Verify SAP Logon Tickets
B: Single Sign-On using SAP logon tickets with user mapping
If users have different users IDs in the SAP Systems than in the portal, you must define a SAP reference system and map each user's user ID to their user ID in the reference system.
You must perform the following steps:
1.Define an SAP Reference System for User Data
2. Configure Portal Server for SSO with SAP Logon Tickets
3. Configure SAP Systems to Accept and Verify SAP Logon Tickets
SAP logon tickets contain information about the authenticated user. They do not contain any passwords.
logon tickets contain the following items:
u2022 Portal user ID and one mapped user ID for external applications
u2022 Authentication scheme
u2022 Validity period
u2022 Information identifying the issuing system
u2022 Digital signature
Procedure
1) Download verify.der from keystore of the portal
2)Upload verify.der in Tran: STRUSTSSO2
3) Check that the following instance profile parameters are active
login/accept_sso2_ticket is 1
login/create_sso2_ticket is 0
Points Are Welcome
Thanks
SubbaRao Chinta
1) Export the J2EE signing certificate to Cluster-> Server -> Services->Key Storage->Runtime->
TicketKeystore->SAPLogonTicketKeypaircert. (or you can download the certificate by logging on as System Admin role and then System Admin tab ->System Config->Key Store...certificate name is verify.der) Then I imported this file successfully into R/3 (ECC 6.0) using STRUSTSSO2.
2) Set the profile parameter login/accept_sso2_ticket to the value 1 in every instance profile
3) Also set the fully qualified domain name of the server in transaction RZ10
Thanks,
GLM
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.