Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x



Similar documents
Configuring ADFS 3.0 to Communicate with WhosOnLocation SAML

ADFS Integration Guidelines

SAP NetWeaver AS Java

CA Nimsoft Service Desk

Dell One Identity Cloud Access Manager How to Configure for SSO to SAP NetWeaver using SAML 2.0

SAML 2.0 Configurations at SAP NetWeaver AS ABAP and Microsoft ADFS

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

Single Sign-On between SAP Portal and SuccessFactors

SAP NetWeaver Fiori. For more information, see "Creating and enabling a trusted provider for Centrify" on page

Microsoft Office 365 Using SAML Integration Guide

To set up Egnyte so employees can log in using SSO, follow the steps below to configure VMware Horizon and Egnyte to work with each other.

HOTPin Integration Guide: Salesforce SSO with Active Directory Federated Services

Security Assertion Markup Language (SAML) Site Manager Setup

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

How to Implement the X.509 Certificate Based Single Sign-On Solution with SAP Netweaver Single Sign-On

Implementation Guide SAP NetWeaver Identity Management Identity Provider

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

Configuring Single Sign-on from the VMware Identity Manager Service to AirWatch Applications

Egnyte Single Sign-On (SSO) Installation for Okta

How To Use Saml 2.0 Single Sign On With Qualysguard

ADFS for. LogMeIn and join.me authentication

For details about using automatic user provisioning with Salesforce, see Configuring user provisioning for Salesforce.

Connected Data. Connected Data requirements for SSO

Configuring Salesforce

CONFIGURATION GUIDE WITH MICROSOFT ACTIVE DIRECTORY FEDERATION SERVER

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

Fairsail. Implementer. Single Sign-On with Fairsail and Microsoft Active Directory Federation Services 2.0. Version 1.92 FS-SSO-XXX-IG R001.

Configuring EPM System for SAML2-based Federation Services SSO

Single Sign On (SSO) Implementation Manual. For Connect 5 & MyConnect Sites

Enabling SSL and Client Certificates on the SAP J2EE Engine

Egnyte Single Sign-On (SSO) Installation for OneLogin

How to Integrate CRM 2007 WebClient UI with SAP NetWeaver Portal

TIB 2.0 Administration Functions Overview

IBM Business Monitor V8.0 Global monitoring context lab

ACTIVID APPLIANCE AND MICROSOFT AD FS

Exostar LDAP Proxy / Secure Setup Guide. This document provides information on the following topics:

SAM Context-Based Authentication Using Juniper SA Integration Guide

Deploying RSA ClearTrust with the FirePass controller

EVault Endpoint Protection 7.0 Single Sign-On Configuration

VMware Identity Manager Integration with Active Directory Federation Services 2.0

360 Online authentication

PingFederate. Salesforce Connector. Quick Connection Guide. Version 4.1

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

SP-initiated SSO for Smartsheet is automatically enabled when the SAML feature is activated.

Configuring Parature Self-Service Portal

Angel Dichev RIG, SAP Labs

Configuring Single Sign-on from the VMware Identity Manager Service to Dropbox

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

SAML single sign-on configuration overview

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow

Authentication Methods

Virtual Office Remote Installation Guide

OneLogin Integration User Guide

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Thirtyseven4 Endpoint Security (EPS) Upgrading Instructions

Getting Started with AD/LDAP SSO

AvePoint Meetings for SharePoint On-Premises. Installation and Configuration Guide

HarePoint Workflow Extensions for Office 365. Quick Start Guide

Technical Support Set-up Procedure

SAML Authentication Quick Start Guide

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

Configuring. SuccessFactors. Chapter 67

This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections:

Upgrade of Business Systems Data Warehouse Reporting

Configuring SuccessFactors

Setting up Your Acusis Address. Microsoft Outlook

Working with Portecle to update / create a Java Keystore.

Active Directory Federation Services

SAML Single-Sign-On (SSO)

Moodle and Office 365 Step-by-Step Guide: Federation using Active Directory Federation Services

Cloud Services ADM. Agent Deployment Guide

SafeWord Domain Login Agent Step-by-Step Guide

SecureAware on IIS8 on Windows Server 2008/- 12 R2-64bit

SSO Plugin. Case study: Integrating with Ping Federate. J System Solutions. Version 4.0

How to set up Outlook Anywhere on your home system

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

Agenda. How to configure

Working with Office Applications and ProjectWise

Configuring. SugarCRM. Chapter 121

QUANTIFY INSTALLATION GUIDE

Single Sign On for ShareFile with NetScaler. Deployment Guide

AD FS 2.0 Step-by-Step Guide: Federation with Ping Identity PingFederate

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

Sharepoint server SSO

Please evaluate this documentation on the following site:

Virto Password Reset Web Part for SharePoint. Release Installation and User Guide

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Salesforce

OpenSSO: Cross Domain Single Sign On

Migrating helpdesk to a new server

An overview of configuring Intacct for single sign-on. To configure the Intacct application for single-sign on (an overview)

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

T his feature is add-on service available to Enterprise accounts.

Cloud Portal for imagerunner ADVANCE

SAP Certified Technology Professional - Security with SAP NetWeaver 7.0. Title : Version : Demo. The safer, easier way to help you pass any IT exams.

This guide identifies two possible enterprise integration scenarios for NetScaler and Azure AD.

EM L12 Symantec Mobile Management and Managed PKI Hands-On Lab

owncloud Configuration and Usage Guide

Configuring. Moodle. Chapter 82

INFORMATION SYSTEMS SERVICE NETWORKS AND TELECOMMUNICATIONS SECTOR. User Guide for the RightFax Fax Service. Web Utility

Transcription:

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x Sverview Trust between SharePoint 2010 and ADFS 2.0 Use article Federated Collaboration with Shibboleth 2.0 and SharePoint 2010 Technologies in order to setup trust between SharePoint 2010 and ADFS 2.0. Other ADFS 2.0 step-by-step and how to guides could be found at ADFS step-by-step guides Trust between AS Java (CE) 7.2 and SAP Portal 7.0x 1. Export signing certificate from CE 7.2 Open http(s)://<ce72host>:<port>/nwa -> Configuration Management -> Certificates and Keys

Select TicketKeystore view and SAPLogonTicketKeypair-cert entry.

Click button Export To File : 2. Add trusted system at SAP Portal 7.0x using the SSO2 wizard Open http(s)://<portalhost>:<port>/nwa -> Configuration Management -> Trusted Systems and select Add Trusted System -> By Uploading Certificate Manually

Import certificate and provide SID and client of CE 7.2 system (in our case it is SP3/000)

and confirm

3. Test the trust Login in CE 7.2 system (e.g. in NetWeaver Administrator, http(s)://<ce72host>:<port>/nwa) In the same browser window, navigate to 7.0x Portal (http(s)://<portalhost>:<port>/irj/portal) and you should be automatically authenticated with the MYSAPSSO2 cookie

Trust between AS Java (CE) 7.2 and ADFS 2.0 Initial configuration in AS Java (CE) 7.2 Open http(s)://<ce72host>:<port>/nwa -> Configuration Management -> Authentication and Single Sign-On

Select SAML 2.0 tab and click Enable SAML 2.0 Support button. Enter name of the local provider

Change setting Legacy Systems Support (Issue Logon Ticket) to On and click Browse button for the signing key-pair.

A signing key-pair should be generated for the local provider. It will be used as encryption key-pair as well. Here are the next steps: Step 1: Step 2:

Step 3:

Step 4:

Continue with the wizard.

Change selection mode to Automatic and click Finish.

Download metadata file:

Save the metadata file: Add Relying Party Trust in ADFS 2.0 Start AD FS 2.0 Management, select Relying Party Trusts and action Add Relying Party Trust

Select metadata file Use all default settings and save the relying party. After that select action Properties for the CE 7.2 system.

Go to Advanced tab and change the signature algorithm from SHA-256 to SHA-1.

Afterwards, select action Edit Claim Rules and add claim of type Send LDAP Attributes as Claims. Select to send the SAM-Account-Name as Name ID.

With this final step the trust setup at ADFS 2.0 is completed. In order to do the trust setup at CE 7.2 you will need the metadata of ADFS. An example of ADFS 2.0 federation metadata URL is the following - https://<adfs20host>/federationmetadata/2007-06/federationmetadata.xml. Because the metadata document is digitally signed you will need also the signing certificate in order to be able to import the metadata in AS Java (CE) 7.2. The SAP application server does not allow import of a signed metadata document unless the signature is successfully verified. To download the ADFS signing certificate: In AD FS 2.0 Management select Service -> Certificates and download the Token-signing by double clicking on it and then choose

Copy To File. Add Trusted Identity Provider at CE 7.2 Open http(s)://<ce72host>:<port>/nwa -> Configuration Management -> Authentication and Single Sign-On -> SAML 2.0 and click on Trusted Providers.

Select the metadata file you have downloaded from ADFS and click Next.

As metadata is digitally signed, choose the file with the signing certificate you have downloaded from ADFS and click Next.

Enter alias (optional) and click Next.

Leave default settings and click Next and Finish at the subsequent screens of the wizard. At the end the trusted provider will be added but will be disabled.

This is because the identity federation settings are missing. In order to add them click on the Edit button, then Add and select format name Unspecified and source name Logon ID and finally OK.

The last step is to save the provider and enable it use buttons Save and Enable. The icon in the first row should change from grey to green.

With this the trust setup on the AS Java 7.2(CE) is completed. Setup Redirect Application In this scenario, the AS Java 7.2 acts like intermediate system between ADFS 2.0 and SAP EP 7.0x. That is why, we will need a simple redirect application which: will be deployed on AS Java 7.2 will be configured with SAML 2.0 authentication will redirect to the SAP EP 7.0x only after successful authentication Testing the Scenario

Login to ADFS e.g. https://<adfs20host>/adfs/ls/idpinitiatedsignon.aspx After authenticating with ADFS, access the redirect application hosted on AS Java CE 7.2 in the same browser window. Here is what happens when testing the scenario in case first access is to AS Java 7.2: 1. Access redirect application on AS Java 7.2 2. You will be redirected to ADFS for authentication 3. After successful authentication at ADFS, you will be returned back to AS Java 7.2 with SAML 2.0 assertion. The assertion will be evaluated and after being authenticated with SAML 2.0 at AS Java 7.2, an SAP Logon Ticket will be issued (MYSAPSSO2 cookie). 4. You will be redirected to SAP EP 7.0x and authenticated with the MYSAPSSO2 cookie issued by AS Java CE 7.2. Using HTTP Watch (or similar tool) you should be able to see all these redirects: