Translate

SSL Configuration in SAP ABAP AS and JAVA AS – Step-by-step procedure

Applies to:
All releases of SAP ECC and NetWeaver systems except PI as of release 7.1x. We have a separate procedure for PI systems as of release 7.10.
Summary
This document will guide you to setup Secure Socket Layer (SSL) configuration, nothing but enabling secure data transfer (through HTTPS) between server and client in both ABAP AS and JAVA AS.

Benefits

It allows the exchange of encrypted information through SAP systems Secure Socket Layer (SSL). SSL use asymmetric method for interchange the secret key, this method use a private key and public key. The private key is in server side and the public key is used by client for encrypt or decrypt the messages.
HTTPS redirect configuration is not covered in this document.

Pre-requisites

  1. Update the instance profile with the following parameters.
Parameter Name
Value
ssf/nameSAPSECULIB
ssl/ssl_lib/usr/sap/<SID>/SYS/exe/run/libsapcrypto.o
sec/libsapsecu/usr/sap/<SID>/SYS/exe/run/libsapcrypto.o
ssf/ssfapi_lib/usr/sap/<SID>/SYS/exe/run/libsapcrypto.o
icm/HTTPS/verify_client0 (zero)
icm/server_port_<x>PROT=HTTPS,PORT=84$$,TIMEOUT=900,PROCTIMEOUT=600

Note: PORT value is a unique number. It means HTTPS, SMTP and HTTP port numbers should not be same.
2. Create directory sec under /usr/sap/<SID>/<Instance> and update SAP environment variable .sapenv_<hostname>.sh (or .sapenv_<hostname>.sh) with the following value with user SIDADM.
SECUDIR=/usr/sap/<SID>/<Instance>/sec; export SECUDIR


Installation in ABAP Application Server


I. Create Private key and Certificates and generate CSR certificate
     1. Execute transaction STRUSTSSO2 and right click on “SSL server Standard” and click on “Create”.
   Provide the details like DN, Algorithm and Key Length as shown below:
  
    Note: CN=<Fully Qualified Name>, O=<Ogranisation>, L=<City>, SP=<State>, C=<Country>
Click Continue.
 
  2. Now you should be able to see the instance in GREEN as shown below.
      3. Now we need to create a CSR request for CA.

4. Click on the first arrow mark icon under Own Certificate --> Owner. Save the file with .csr extension.
     
    
     5. We have to send this file to Certificate Authority (CA) to get it signed.
II. Import digitally signed entrust certificates into ABAP AS.
    1. Go to STRUSTSSO2 and open SSL Server Standard and double click on instance.
    2. Under Owner click on ‘Import Cert. Response
      
    3. Once it is imported, Add to Certificate List and SAVE.
    4. Now you should be able to see the screen like below
       
     5. Go to SMICM and restart ICM
        Administration --> ICM --> Exit Hard --> Global
       
     6. Go to SMICM again and make sure HTTPS service is ACTIVE as shown below.
       
       
     7. Verify SSL configuration as follows.
        Open https://<fullyqualifiedname>:<HTTPS_Port> and click on LOCK icon at the bottom of the browser.
        The certificate should show Issued by: <Your Certificate Authority Name>
Installation in JAVA Application Server
I. Create Private key and Certificates and generate CSR certificate
     1. Open Visual Administration. Go to serveràservicesà Keystorageàservice_ssl
Note: Existing (or default) ssl-credentials which got generated during SAP installation may not have correct CN and DN values. In this case, we need to rename the existing ssl-credentials to old and create new ssl-credentials with CN and DN values.
     Click on create button at the bottom of the screen
    
     2. Click on Generate CSR Request button at the bottom of the page.
    
     3. Send the CSR certificate to CA to generate digitally signed Entrust certificates.
III. Import digitally signed entrust certificates into ABAP AS.
      1. Visual Admin --> server<x>-->services--> service_ssl àssl-credentials
Click on Import CSR Response at the right bottom, and then it prompts for the certificate name.
     2. Once CSR response is imported, you should see ‘Issuer DN’ is signed by your Certificate Authority.
    
     3. Now we need to restart SSL Provider service to take effect of changes we made.
    
     4. Verify SSL configuration as follows.
     Open https://<fullyqualifiedname>:5<inst num>01 and click on LOCK icon at the bottom of the browser.
     The certificate should show Issued by: <Your Certificate Authority Name>
Related Content
http://help.sap.com/saphelp_nw70/helpdata/en/3a/7cddde33ff05cae10000000a128c20/frameset.htm
http://help.sap.com/saphelp_nw70/helpdata/en/52/31683ab81fd846e10000000a11402f/content.htm
http://help.sap.com/saphelp_nw70/helpdata/en/5b/2e423c0bcc4a7ee10000000a114084/frameset.htm





12 comments:

Anonymous said...

Whats up! I simply wish to give an enormous thumbs up for the good data you might
have right here on this post. I will probably be
coming again to your weblog for extra soon.

my weblog - rocker switch

Anonymous said...

For those abc just beginning meditation practice a time.
So as you know how much more knowledgeable regarding
style, especially on the office chair, that every one has a removable
and washable nylon, it purports to convey his wisdom to a certain weight.



My blog ... stół

Anonymous said...

I visited several sites except the audio quality for audio songs present at this site is actually excellent.


Feel free to visit my weblog vedic maths tricks ()

logistic-solutions said...


Thank you for your post. This is excellent information. It is amazing and wonderful to visit your site.
sap supplier diversity management solutions

logistic-solutions said...


Thank you for your post. This is excellent information. It is amazing and wonderful to visit your site.
sap corporate social responsibility services

logistic-solutions said...

Thank you for your post. This is excellent information. It is amazing and wonderful to visit your site.
microsoft software reseller

logistic-solutions said...


Thank you for your post. This is excellent information. It is amazing and wonderful to visit your site.
emc software vendors
bmc software vendors
Microsoft goldpartner
sap crm service providers

KARTHIK said...

It is amazing and wonderful to visit your site.Thanks for sharing this information,this is useful to me...
http://chennaitraining.in/sap-abap-training-in-chennai/
http://chennaitraining.in/sap-apo-training-in-chennai/
http://chennaitraining.in/sap-ariba-training-in-chennai/
http://chennaitraining.in/sap-basis-training-in-chennai/
http://chennaitraining.in/bi-bw-training-in-chennai/
http://chennaitraining.in/sap-bo-training-in-chennai/
http://chennaitraining.in/sap-bods-training-in-chennai/
http://chennaitraining.in/sap-crm-training-in-chennai/

Lopa said...

This is most informative and also this post most user friendly and super navigation to all posts... Thank you so much for giving this information to me.. 
Digital Marketing Training in Chennai
Digital Marketing Training in Bangalore
Digital Marketing Training in Delhi
Digital Marketing Online Training

saivenkat said...

I am reading your post from the beginning, it was so interesting to read & I feel thanks to you for posting such a good blog, keep updates regularly.
Blockchain Technology

KITS Technologies said...

nice post.
mulesoft training
linux training
etl testing training

KITS Technologies said...

nice post.
oracle sql plsql training
go langaunage training
azure training
java training
salesforce training

Labels

sap hana hana database aws s4 hana hana db s4hana conversion steps sap hana azure bw4hana hana migration s4hana migration sap cloud migration steps sap hana migration steps sap hana migration to azure s4hana sap fiori fiori performance fiori erp s4 hana fiori sap fiori app sap fiori client sap fiori launchpad sap s4 hana fiori cisco ecc AI SAP AI abap dumps hana sap S/4HANA S/4HANA Conversion best sap ui5 & fiori training configuration database fiori tutorial on webide free sap ui5 & fiori training s/4 hana sap dumps sap fiori tutorial sap ui5 sap ui5 & fiori sap ui5 & fiori tutorial sara ui5cn 2367245 - Troubleshooting performance issues with SAP BPA Amazon free tier for SAP AWS setup Experience CALL_FUNCTION_NOT_FOUND CCMS Configuration and Use Create New Data Class in SAP (Oracle) Critical top SAP Abap dumps DHCP Clients Not Receiving IP Addresses Download Stack.xml HAN-DB HAN-DB-ENG High CPU Usage Due to Excessive Process Switching How To How to Start and Stop SAP Hana Tenant Database How to change SAP Hana Sql Output results are limited to 5000 Records How to perform SAP Dual Stack Split - Netweaver Inactive Objects in SAP Intercompany transactions in SAP AP / AR : Cross Company Code Transaction Interface Flapping Due to Duplex Mismatch KBA LOAD_PROGRAM_LOST MSSQL shrinking transaction log file Migrating to SAP hana database NAT Overload Causing Internet Access Failure Note 500235 - Network Diagnosis with NIPING OSPF Adjacency Not Forming PRINCE2 Foundation Sample Questions Preparing for S/4HANA Conversion and the MUST know items Push to Download Basket S/4HANA Migration Cockpit S/4JANA SAP BI Support Data Load Errors and Solutions SAP BI/BW Landscape SAP BPA SAP Basis SAP Basis Automation SAP Business Objects SAP CPS SAP Certification SAP FI Certification SAP FI Certification Sample Questions SAP HANA Admin - Cockpit SAP HANA DB Engines SAP HANA Database SAP HANA terminate session connection disconnect cancel kill hang stuck SAP Hana DB restore SAP Hana Numeric Error Codes SAP Landscape SAP Language installation SAP MM and Purchase Order Tables SAP Maintenance Planner SAP Note 500235 SAP R/3 Glossary SAP Readiness Check SAP S/4HANA 1709 Installation Files SAP S/4HANA 2023 SAP S/4HANA 2023 Installation SAP S/4HANA 2023 running SAP S/4HANA Installation SAP Scheduling SAP Solman 7.2 CHARM: SAP Support Package Stack Strategy SAP Support package SAP Upgrade SAP support stack upgrade SP stacks STORAGE_PARAMETERS_WRONG_SET SUSE/SLES/Kernel versions Setup of S/4hana 2023 TSV_TNEW_PAGE_ALLOC_FAILED TSV_TNEW_PAGE_ALLOC_FAILED error Transaction ID Unable to download an SAP Note Unix/Linux Command That Are Helpful For SAP Basis Upgrading SAP Kernel Without Downtime Upgrading windows server 2008 to windows server 2019 What is OSS Notes? SAP SNOTE Tutorial accounting agile ale idoc ale/edi archive FI documents audit auditing auditor aws aws cloud basic type bluefield approach ccms ccmsidb charm copilot datavard dbacockpit download sap note download snote edi idoc electronic data interchange enable sap archiving objects erpprep ffid firefighter fraud functional hana admin how to apply sap security note https://www.erpprep.com/ idoc install install sap fiori installation interfaces intermediate document internal control license key linux version materials management messsage niping test order type port prince2 agile prince2 agile practitioner purchasing quick info s4 hana sap abap dumps sap abbreviations sap activate certification sap activate project manager sap authorization sap aws sap brownfield sap ccms sap ccms configuration sap erp sap error sap grc sap greenfield sap internet demo system sap license sap maintenance certificate sap material management sap meaning sap mm sap mm consultant sap monthly security note sap netweaver sap network diagnostic sap niping sap note sap oss sap patch day sap performance sap performance issue sap purchase order sap s/4hana sap sales and distribution sap sap otc sap sd sap sd certification training sap sd course sap sd jobs sap sd module sap sd online training sap sd training sap sd tutorial sap sd tutorial for beginners sap security sap security note sap snote sap snote tutorial sap solution manager sap sql segregation of duties separation of duties sles slicense smc snote snote in sap system sod conflict solution manager solution maneger stop start hana database suse linux techie trex two step upgrade required waterfall