Re: SSO for success factor using SAML2.0 error
Hello Benita That's great !! Please mark the thread as "Answered". Regards,Tapan
View ArticleRe: How to default a trusted SAML 2.0 identity provider
found the answer: SAML2 -> Local Provider -> Service Provider Settings -> Selection Mode -> Automatic
View ArticleSingle Sign-On Not Working
Today I updated my Gui instalation from GUI730 to GUI740 with NWBC5.0 and afterwords the SSO is not working anymore. Is there another update that is required to make in order for this functionality to...
View ArticleRe: Single Sign-On Not Working
You may have selected all SAP GUI features, including SNC Client Encryption. This changes the SNC product configuration, i.e. the system environment variable "SNC_LIB".To check this, open a DOS box and...
View ArticleRe: Single sign on using windows user id to SAP Enterprise portal (with...
Tapan, Thanks. If we decide to not do user mapping and configure single sign on, I presume the system would do single sign-ons for user with same id and prompt the logon screen for users with...
View ArticleRe: Single sign on using windows user id to SAP Enterprise portal (with...
Hello Krish Yes your understanding is correct. Regards,Tapan
View ArticleRe: HANA to ECC SSO Configuration
Hello 1. For procedure for connecting HANA XS apps and ABAP system using SPNego/Keberos: SAP Note 1837331 - HOWTO HANA DB SSO Kerberos/ Active Directory -> Guide Attached...
View ArticleRe: Steps required to change password of SPN account supporting NW SSO Client...
Hello Stephen You need to use SAPGENPSE to create the keytab file and PSE file again. We need to generate keytabl file everytime after changing anything with Service User. In addition, 1. also add...
View ArticleRe: Single Sign-On Not Working
Yes, indeed I installed not all but some features including that one, I had my SSO Client reinstalled and it's working fine now. And yes, I'm using SAP SSO Secure Login Client. Thanks! -- Jorge
View ArticleHow to replace X509 by SAML2
Hello,As of today we are connecting to CRM 7.0 system using X509 certificate and assuming all is done properly user can login without having to enter any credentials.In near future we want to basicaly...
View ArticleRe: Steps required to change password of SPN account supporting NW SSO Client...
Thanks Tapan! To avoid any interuption to the Kerberos authentication, I am hoping to be able to first create the new keytab with new password before actually applying the new password to the SPN...
View ArticleSAP SSO does not work for Remote systems accessing with Windows AD
Dear All,I have a problem with SSO accessing the remote systems defined following the instructions of those...
View ArticleUser Authentication -> Microsoft Azure Active Directory / FortiAuthenticator
Hi all, Does SAP actually support Microsoft Windows Azure Active Directory (AAD) and FortiAuthenticator for user authentication? If not when? Azure Active Directory User Authentication, Two-factor...
View ArticleSAP SSO using existing PKI (Microsoft Certificate Server)
Am looking to implement SAP SSO leveraging an existing PKI. The PKI is a Microsoft Certificate Server.SAP SSO would be used for SAP GUI for Windows, portal, NWBC.According to the SSO install guide, it...
View ArticleSAP Single Sign-On help for different AD and SAP user
Hi Experts, We have to implement SSO for one of our customers where we have ECC, EP, BI &GRC systems. They are looking to achieve this using Kerberos with SNC for AS-ABAPKerberos with SPNEGO for...
View ArticleRe: SAP Single Sign-On help for different AD and SAP user
You can use transaction SNC1 to map users, if the SAP user and AD user are same. if not, I suggest you use a scripting tool such as ECATT. The mapping is stored in a table called USRACL (maintained in...
View ArticleRe: SAP Single Sign-On help for different AD and SAP user
Hi Srikanth,In your case, I think you can create a custom attribute in AD, for instance named "SAPID" to store SAP user ID in AD. For SPNego SSO to AS JAVA, you can choose to map this attribute instead...
View ArticleRe: SAP SSO using existing PKI (Microsoft Certificate Server)
Hi Dan, Your understanding is correct. You do not need SSO server as long as you have certificates on both end user and ABAP server sides. The purpose of SSO server is only to help to convert the...
View ArticleRe: How to replace X509 by SAML2
Hi Fabien, You need to check the configuration of your CRM's SSL setting. When SSL is enabled, there are two options. The default one is asking for a certificate, which in your case, is incorrect. The...
View ArticleSAML 2.0 Multiple Authentication contexts
Hello, I'm trying to set up a prototype for a SAML 2.0 scenario. The set up includes NW SSO as the SAML Identity Provider and a NW 7.4 Server as the Service Provider. One of the requirement is to have...
View Article