on 2016 Jul 19 9:03 AM
Hello,
We are currently setting up an SSO POC for our company. For connections that use the SAPGUI and AS ABAP the documentation explains quite clearly how set up the various scenarios. But I couldn't find out how to implement a connection via a web broswer to a Java-only NW installation. Can anyone advise please?
Also is there any particular advantage in using X509 cetrificates over Kerberos tokens in a Microsoft AD domain?
Many thanks oin advance for your help!
Request clarification before answering.
Hi,
we're using SLS, but we prefer the saml2.0 solution via identity federation (is a part of the SLS) instead of x.509 certificates. Single Logout is a very helpful feature!
Best regards
Kai
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Kai,
SAP Single Sign-On product offers Secure Login Server (SLS) that is a "lightweight PKI" and issues short term X.509 Client certificates. The service itself accepts SAML for authentication but always issues X.509 certificates.
SAP Single Sign-On product offers also a standard SAML Identity Provider that could be used for identity federation and issues standard SAML 2.0 assertions.
Regards,
Donka Dimitrova
Hello Donka,
exactly . But why use X.509 certificates for java stacks, if saml2.0 is already supported by them? By using saml2.0 it's very easy to update user attributes, assigned groups and permissions during logon. And closing all user sessions in a landscape by using SLO is security benefit (session hijacking). Thats why we decided to use saml2.0 instead of x.509 certs for java stacks.
regards
Kai
Hello Kai,
When there are Windows based UIs like SAP GUI for Windows, SNC is a must and SAML is not possible. Customers have to use Kerberos or X.509 in order to do the SSO or they have to exchange a SAML assertion for an X.509 client certificates with the Secure Login Server in order to get the required X.509 for the SAP GUI for Windows scenarios with the SNC.
Regards,
Donka
| User | Count |
|---|---|
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.