Quantcast
Channel: SAP NetWeaver Administrator
Viewing all articles
Browse latest Browse all 185

SNC - Secure Network Communication Configuration between Enterprise Portal to BW system

$
0
0

SNC - Secure Network Communication   Configuration between Enterprise Portal to BW system

 

 

Pre-Requisites:

 

Parameters to be checked before the configuration

  • login/accept_sso2_ticket    = 1
  • login/create_sso2_ticket    = 2 (recommended) or 1
  • snc/enable  = 1
  • icm/host name full. (SMICM – to check fully qualified hostname )

    

check https://help.sap.com  for the parameter values

  • snc/force_login_screen
  • snc/identity/as
  • snc/gssapi_lib
  • snc/permit_insecure_start
  • snc/r3int_rfc_qop
  • snc/r3int_rfc_secure
  • snc/accept_insecure_r3int_r
  • snc/accept_insecure_rfc
  • snc/accept_insecure_cpic
  • snc/accept_insecure_gui

 

STEP1:

Login to portal as a “administrator “ user  goto  http://<hostname:port/nwa

->click “configuration “ tab ->click “certificate and keys”

Note : parameter snc/enable=1 (to activate the SNC)

Login to portal as administrator  ->click  configuration  tab ->click  certificate and keys

 

1.jpg

 

Click the Ticket Key store entry listed under tab Key storage then select "SAPLogonTicketKeypair-cert "

 

2.jpg

 

Then click Export Entry Select Binary .x.509 format and Save it locally

 

3.jpg

 

STEP 2:

 

Login to ABAP system default client: XXX  Goto transaction STRUSTSSO2

 

4.jpg

 

Click  System PSE and then click   import certificate

 

5.jpg

Select the format Binary then click "Add to Certificate to List" then click "Add to ACL"

Fill portal SID and client 000 below

6.jpg

 

 

STEP3

 

Goto STRUSTSSO2 click System PSE -> click <FQDN > right side check the portal certificate info.

7.jpg

 

 

Create SNC SAP Cryptolib PSE file  right click the SNC SAP Cryptolib  

 

8.jpg

Remove the default values of Org(opt) & comp/org and maintain the below values and SAVE

 

9.jpg

 

10.jpg

 

Now select SNC SAP Crypto pse and Double click the CN=<SID>, O=GM, C=US 

 

11.jpg

 

Press Export button   and export to your machine. 

Use the name <SIDof BW system>.cert

 

12.jpg

 

Select “Base64” as <SID>.cert

 

 

STEP4

 

Login to the Portal Server on the OS level (sidadm)

Goto file path:  /usr/sap/<SID>/JCXX/sec directory

Check the shared library and environmental variable are set 

/usr/sap/SID/JCXX/sec 

 

13.jpg

Set the environment variable for the path usr/sap/<SID>/JC<nn>/sec

<SID>adm> export SECUDIR=/usr/sap/<SID>/J<nn>/sec

 

 

STEP5:

Create the SAP_<any name for example J2EE>.pse file using the command

sapgenpse get_pse -p SAP_J2EE.pse -x j2eepin "CN=<SID>, O=<organization 2 letters>, C=<country code 2 letters>"

14.jpg

 

STEP6:

 

Then execute,

Sapgenpse  seclogin –p <please give any pse file name>.pse –x j2eepin –O <SID>adm

 

15.jpg

 

STEP7:

Generate the Portal SNC certificate with the command:

Sapgenpse export_own_certificate –p <pse name> -o <portal certificate>

  1. Ex. Sapgenpse export_own_cert –p <pse name>  –o <portal certificate>

 

17.jpg

 

STEP8:

Then  upload the SAP ECC certificate into Portal PSE with the command

  1. Ex. sapgenpse maintain_pk –p < please give any pse file name>.pse -a <SID BW system name>.cert

18.jpg

 

STEP9:

Transfer (Ftp) the file <SID>.cert from Portal Server to your machine

Login to BW system -> goto STRUSTSSO2 -> click SNC SAPCrypto -> double click

Then click  to import the file 

19.jpg

20.jpg

Then click  and finally save it

Before starting the following profile parameters need to be set in respective ABAP systems :

21.jpg

 

STEP10:

 

then Goto ->  SM30 and type the VSNCSYSACL and press Display

22.jpg

 

Select “ E” for external system

 

23.jpg

24.jpg

 

STEP11:

Goto SM30 and Enter USRACLEXT in Table/View field and press Display

25.jpg

Press “New Entries” and Add the SNC Name for Portal and “save” it

26.jpg

 

 

STEP12:

Creation of system’s in Portal System Administration->System landscape ->

 

27.jpg

Portal content -> SystemLandscapeRight click->System Landscape->  New -> 

28.jpg

Select option  then click  Next

 

STEP13:

How to get system information for web application server as and ITS

Goto se37 then press f8

Then provide the info :

FM name : RSBB_URL_PREFIX_GET

I_HANDLERCLASS : CL_RSR_WWW_HTTP

Clear the clear the I_message server entry -> execute (F8)

 

For getting the ICM info :

Goto se37

FM name : RSBB_URL_PREFIX_GET

I_HANDLERCLASS : CL_HTTP_EXT_ITS

Then clear   I_message server   entry -> execute (F8)

" save" the details and provide the system alias name 

Choose “next” and then “finish”

System is created now

 

 

STEP14:

 

System Landscape->click under this node you may find your newly created system ->right click the new system created ->click properties

 

Enter the SNC parameters in the system data container

 

Then conduct a system connection test , and this successfull test completes the SNC configuration between Enterprise Portal and BW system

 

Note : Login with the user same as in backend Don’t provide any user  and click the button “test”


Viewing all articles
Browse latest Browse all 185

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>