cancel
Showing results for 
Search instead for 
Did you mean: 

Single Sign On after Systemcopy dosn´t work

Former Member
0 Kudos

Hello,

i have a problem with single sign on.

What we did. We installed a new testportal (EP 6.0 SP 15) with a Systemcopy from our old testportal.

Every thing works fine, but only single sign on dosn´t work.

We deleted the old SSO Ticket in the SAP-Backend-System and imported the new SSO Ticket (from the new testportal) into the SAP-System.

The result is: From the old portal Single Sign on works. But from the new portal i get the SAP-Login-Screen.

What can i do?

Thank you

Martin

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Hello Martin. Firs of all try to check your SAPLogonTicketkeypair-cert in your new portal

(system administration --> system configuration --> Keystore Administration )

and folow by Mr. Walter recomendation, about "creating a new SAPLogonTicketkeypair".

But this will be not enough, as you try to connect second Portal to same backend, you need to change in your portal using "configtool" --> "login.ticket-client" for example to 001 (by default is set to 000, it should differ from your first portal), stop AS JAVA change in configtool, start AS JAVA. Only after this export your "verify.der" and import in backend (P.S. on stage where you add your certificate in Required Client ACL, you need to specify this "login.ticket-client" number ,when you will ask to specify it.

Regards.

Former Member
0 Kudos

Hi Martin,

After the system copy I would suggest creating a new SAPLogonTicket keypair on the new portal, and add the public certificate to the certificate list and ACL of the backend:

http://help.sap.com/saphelp_nw04s/helpdata/en/75/c80b424c6cc717e10000000a155106/content.htm

As the SSO tickets are generated using this keypair it appears that your ticket is not 'recognized' as coming from the new portal. Note that if your new portal has a different SID you need it to add it to the ACL with this new SID. If you exchange the certificate you need to add the ACL entry again as well.

Best regards,

Walter