Implementing SSO between the Enterprise Portal and the EPM Add-In



Similar documents
Process Archiving using NetWeaver Business Process Management

R/3 and J2EE Setup for Digital Signature on Form 16 in HR Systems

Table of Contents. How to Find Database Index usage per ABAP Report and Creating an Index

How To Use the BPC Mass User Management Tool in BPC 10.0 NW

SAP Master Data Governance- Hiding fields in the change request User Interface

Integration of SAP Netweaver User Management with LDAP

Enterprise Software - Applications, Technologies and Programming

Understanding HR Schema and PCR with an Example

Maintaining Different Addresses and Ids for a Business Partner via CRM Web UI

Business One in Action - How can we post bank fees and charges while posting Incoming or Outgoing Payment transactions?

How to Create a Support Message in SAP Service Marketplace

Secure MobiLink Synchronization using Microsoft IIS and the MobiLink Redirector

Integrating Easy Document Management System in SAP DMS

Third Party Digital Asset Management Integration

SAPFIN. Overview of SAP ERP Financials COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

Budget Control by Cost Center

Single Sign-On between SAP Portal and SuccessFactors

How To Use the ESR Eclipse Tool with the Enterprise Service Repository

Integration of Universal Worklist into Microsoft Office SharePoint

HR400 SAP ERP HCM Payroll Configuration

UI Framework Simple Search in CRM WebClient based on NetWeaver Enterprise Search (ABAP) SAP Enhancement Package 1 for SAP CRM 7.0

K in Identify the differences between the universe design tool and the information design tool

Data Archiving in CRM: a Brief Overview

NetWeaver Business Client (NWBC) for Incentives and Commissions Management (ICM)

Configuring Single Sign-on for SAP HANA

How to Schedule Report Execution and Mailing

Alert Notification in SAP Supply Network Collaboration. SNC Extension Guide

Portfolio and Project Management 5.0: Excel Integration for Financial and Capacity Planning

SAP NetWeaver BRM 7.3

Learning Series: SAP NetWeaver Process Orchestration, secure connectivity add-on 1c SFTP Adapter

BW Workspaces Use Cases

UI Framework Task Based User Interface. SAP Enhancement Package 1 for SAP CRM 7.0

AC200. Basics of Customizing for Financial Accounting: General Ledger, Accounts Receivable, Accounts Payable COURSE OUTLINE

User Experience in Custom Apps

Application Lifecycle Management

Sending Additional Files from SAP Netweaver PI to third Party System

TM111. ERP Integration for Order Management (Shipper Specific) COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

Sample Universe on Microsoft OLAP Cube

Installation Guide Customized Installation of SQL Server 2008 for an SAP System with SQL4SAP.VBS

Log Analysis Tool for SAP NetWeaver AS Java

How-to-Guide: Middleware Settings for Download of IPC Configuration (KB) Data from R/3 to CRM System

ERP Quotation and Sales Order in CRM WebClient UI Detailed View. SAP Enhancement Package 1 for SAP CRM 7.0 CRM Sales - SFA

USDL XG WP3 SAP use case. Kay Kadner

Business Requirements... 3 Analytics... 3 Typical Use Cases... 8 Related Content... 9 Copyright... 10

Compliant, Business-Driven Identity Management using. SAP NetWeaver Identity Management and SBOP Access Control. February 2010

Data Source Enhancement Using User Exit

How to Add an Attribute to a Case, Record and a Document in NW Folder Management (ex-records Management)

UI Framework Logo exchange without skin copy. SAP Enhancement Package 1 for SAP CRM 7.0

Consume an External Web Service in a Nutshell with good old ABAP

SAP How-To Guide: Develop a Custom Master Data Object in SAP MDG (Master Data Governance)

SAP Sustainability Solutions: Achieving Customer Strategies

Variable Exit in Sap BI How to Start

SAP DSM/BRFPlus System Architecture Considerations

Project Governance The Role Of The Business Process Owner

Fixed Asset in SAP Business One 9.0

BICS Connectivity for Web Intelligence in SAP BI 4.0. John Mrozek / AGS December 01, 2011

If you have additional questions regarding these name changes, please contact your SAP Account Executive.

OData in a Nutshell. August 2011 INTERNAL

SAP Portfolio and Project Management

SAP Business ByDesign Reference Systems. Scenario Outline. SAP ERP Integration Scenarios

How to Implement Load Balancing on SAP BusinessObjects Planning and Consolidation, version for SAP NetWeaver

Query, Read, Create and Update CLOUD FOR CUSTOMER ODATA SERVICE QUERY, READ, CREATE AND UPDATE

How To... Migrate Custom Portal Applications to SAP NetWeaver 7.3

Sales Planning Detailed View. SAP Enhancement Package 1 for SAP CRM 7.0 CRM Sales - SFA

Run SAP like a Factory

How to Configure Access Control for Exchange using PowerShell Cmdlets A Step-by-Step guide

Duet Enterprise Add SAP ERP Reports and SAP BI Queries/Workbooks to Duet Enterprise Configuration

SAP Cloud Strategy - Timeless Software. Frank Stienhans on behalf of Kaj van de Loo SAP

Accounts Receivable. SAP Best Practices

SAP Service Tools for Performance Analysis

Quick Guide EDI/IDoc Interfacing to SAP ECC from External System

Intelligent Business Operations Chapter 1: Overview & Strategy

Download and Install Crystal Reports for Eclipse via the Eclipse Software Update Manager

SOP through Long Term Planning Transfer to LIS/PIS/Capacity. SAP Best Practices

Mass Maintenance of Procurement Data in SAP

Learning Series: SAP NetWeaver Process Orchestration, business to business add-on EDI Separator Adapter

Finding the Leak Access Logging for Sensitive Data. SAP Product Management Security

Xcelsius Dashboards on SAP NetWaver BW Implementation Best Practices

Configuring Distribution List in Compliant User Provisioning

Using User Exit for Variables in BEx Reporting

RUN BETTER Become a Best-Run Business with Remote Support Platform for SAP Business One

Business Process Change Analyzer in SAP Solution Manager 7.1

Using SAP Logon Tickets for Single Sign on to Microsoft based web applications

LO Extraction Part 1: SD Application Short Overview

How To Configure MDM to Work with Oracle ASM-Based Products

AP Integration with BRFplus VERSION V APRIL SAP AG

Certificate SAP INTEGRATION CERTIFICATION

Creating New Dashboard Packages for SAP Business One 8.8

Introducing the SAP Business One starter package. A Great Start to help you to Streamline Your Small Business

Developing Applications for Integration between PI and SAP ERP in Different Network Domains or Landscapes

SAP Central Process Scheduling (CPS) 8.0 by Redwood

SAP Best Practices for Subsidiary Integration in One Client Production with Intercompany Replenishment

Ariba Network Integration to SAP ECC

Supporting SAP POS Best Practices Setting Log File Sizes and Retention

Delta Queue Demystification

SAP HANA Cloud Integration Document Version: Template Guide for SAP Sales and Operations Planning

SAP NetWeaver BPM Tutorial for Beginners: My Name and Age BPM Tutorial

Next Generation Digital Banking with SAP

SAP Sybase SQL Anywhere New Features Improve Performance, Increase Security, and Ensure 24/7 Availability

How to Use the EPM Connector to Visualize BPC Data via SAP Crystal Dashboard Design (Xcelsius Dashboards)

Transcription:

Implementing SSO between the Enterprise Portal and the EPM Add-In Applies to: SAP BusinessObjects Planning and Consolidation 10, version for SAP NetWeaver SP1 and higher EPM Add-In, SP3 and higher. For more information, visit the Enterprise Performance Management homepage. Summary One of the major changes to SAP BusinessObjects Planning and Consolidation 10, version for SAP NetWeaver was moving to a more standard BW security model, which was made possible by replacing the.net tier with the ABAP Web Application Server (WAS). This change allows us to connect to a BPC NetWeaver connection in the EPM Add-In directly from the portal without having to enter any user credentials giving Enterprise Portal customers a new deployment option. The SSO scenario covered in this guide can be incorporated into an existing Enterprise Portal implementation with minimal effort. Author: Daniel Settanni Company: SAP Labs Created on: 2 December 2011 Author Bio Daniel Settanni has worked SAP Labs in the EPM CSA for the last 5 years. He specializes in SAP BusinessObjects Planning and Consolidation, both the Microsoft and NetWeaver releases. 2011 SAP AG 1

Table of Contents Prerequisites... 3 Overview... 4 Integration between the Enterprise Portal and BPC 10 for NetWeaver s web client... 4 Integration between the Enterprise Portal and BPC 10 for NetWeaver s Office client (EPM Add-In)... 5 Why would I want to integrate the Enterprise Portal with BPC 10?... 5 What s included in the Web Application... 6 Quick note on security... 6 Importing the Web Project to NWDS... 7 Importing the WAR file into NWDS... 7 Adding References to the Apache HttpClient Libraries... 8 Updating the Deployment Descriptor... 9 Deploying the Web Application... 11 Creating the Enterprise Application... 11 Deploying the Enterprise Application... 12 Testing the Web Application... 14 Testing the Servlet... 14 Using the Test JSP Page... 16 Related Content... 17 Copyright... 18 2011 SAP AG 2

Prerequisites This solution depends on: An AS Java instance with the Enterprise Portal components installed An AS ABAP instance with SAP BusinessObjects Planning and Consolidation 10, version for SAP NetWeaver SP1 or higher installed The EPM Add-In, SP3 or higher NetWeaver Developer Studio (NWDS) 7.3 Apache HTTPComponents > HttpClient 4.1.2 o o Can be downloaded from: http://hc.apache.org/downloads.cgi Required for proper cookie support (needed to generate reentrance tickets) 2011 SAP AG 3

Overview The underlying architecture of SAP BusinessObjects Planning and Consolidation 10, version for SAP NetWeaver (herein referred to as BPC or BPC 10) has changed from its previous releases. Specifically, the.net server which previously supported Web operations has been replaced with the SAP ABAP Web Application Server (WAS). Due to this new architectural component, BPC now supports SAP Logon tickets which allow users to authenticate to one SAP system and seamlessly logon to another trusted SAP system without having to reenter their credentials. This how-to guide provides a web application that can be deployed alongside the Enterprise Portal on an AS Java stack allowing you to launch the EPM Add-In directly from the portal without having to enter credentials a second time. Integration between the Enterprise Portal and BPC 10 for NetWeaver s web client Integrating the Enterprise Portal with the BPC 10 for NetWeaver web interface is a straight forward process and is supported by default. You can simply create a new page in Portal Content; making the BPC 10 for NetWeaver web client URL the target and you are ready to go. As long as the AS ABAP server trusts the AS Java server, users can seamlessly log into the BPC web client from the Portal. A user can then launch the EPM Add-In from the BPC web client using the link provided in the web client home page. The basic flow is as follows: The only potential issue here is that a user has to go to the BPC web client, even if they only want to use the EPM Add-In. It s only a few extra steps, but still not optimal. In the next section we will explain how we can remove these extra steps to allow the user to log into the EPM Add-In directly. 2011 SAP AG 4

Integration between the Enterprise Portal and BPC 10 for NetWeaver s Office client (EPM Add-In) Now that we have seen what is possible out of the box, let s look at the solution provided by this How-To guide. It is very similar to the one above, with one key difference: the user doesn t have to navigate to the BPC 10 web client to launch the EPM Add-In. Instead, they can click on a link directly in the portal which bypasses the BPC 10 web client completely. The target in the link is the custom web application included in this HTG. This web application communicates with the BPC 10 web services for the client, obtains the reentrance ticket and passes it to the EPM Add-In. The basic flow for this scenario is as follows: Why would I want to integrate the Enterprise Portal with BPC 10? So why would someone want to enable SSO between the Enterprise Portal and their BPC 10 NetWeaver installation? We ve already covered one reason; seamless authentication but there is another equally valid reason to enable additional authentication scenarios. Currently, the web client and EPM Add-In support three basic types of authentication and in each case the credentials are all stored in BW: Basic / Forms based o Credentials are stored in BW X.509 Client Certificates o X.509 certificates are stored in BW and mapped to BW users SAP Logon Tickets o Allows users to login to the EPM Add-In without entering credentials when launched from the web client. If you are familiar with authentication in the previous releases you will notice that authentication using Active Directory credentials is not supported (this was the only supported mechanism previously). Integration with the Enterprise Portal puts this option back on the table because AS Java supports using LDAP as a data source with the UME. This means that you can still use Active Directory credentials to authenticate to BPC 10 for NetWeaver assuming the Enterprise Portal is your starting point. 2011 SAP AG 5

What s included in the Web Application The web application includes three classes and one JSP in addition to all the standard web application components. The Java source is also included in the WAR file in case you want to tweak anything or just get more insight on how this was implemented. com.sap.csa.bpc.epm_addin_launcher.java o Description: Servlet implementation providing the core functionality for the HTG. o Default URI: /PCNW10_SSO_EA/EPM_AddIn_Launcher com.sap.csa.bpc.hostdescriptor.java o Description: Standard bean style class used to store connectivity information for the BPC 10 NetWeaver AS ABAP Web Application Server (WAS). com.sap.csa.bpc.reentrancedetails.java o Description: Stores the Reentrance token and logs associated with retrieving the token. index.jsp o Description: A basic JSP, really just an HTML form that allows you to test calling the EPM_AddIn_Launcher servlet with different host/port/protocol/environment parameters using the GET and POST HTTP methods. o Default URI: /PCNW10_SSO_EA/index.jsp Note: You can change the default context root (/PCNW10_SSO_EA) in the enterprise applications application.xml file. This change would not require any changes in the web app. You can also change the default servlet URI (EPM_AddIn_Launcher) in the web applications web.xml file. You will have to update the form actions in index.jsp if you change the servlet URI. Quick note on security Two sensitive pieces of information get passed between the client and the Portal during this process, the SAP Logon Ticket and the Reentrance Ticket. These tickets could be compromised if the end user accesses the Portal without using SSL. Due to this, SSL (HTTPS) must be used when deploying this solution in production. 2011 SAP AG 6

Importing the Web Project to NWDS This section covers importing the PCNW10_SSO_WP.war file into NWDS as well as adding references to the libraries included with the Apache HttpClient 4.1.2. The PCNW10_SS_WP.war file can be downloaded here: PCNW10_SS_WP.war file Importing the WAR file into NWDS 1. Launch NWDS. 2. Select File > Import 3. Expand Web and select War File. Click Next. 4. Enter the path to PCNW10_SSO_WP.war in the War file text box, then click Finish 5. You should now see the PCNW10_SSO_WP project in Project Explorer. 2011 SAP AG 7

Adding References to the Apache HttpClient Libraries 1. Download httpcomponents-client-4.1.2-bin.zip from http://hc.apache.org/downloads.cgi and extract it. 2. Right click the PCNW10_SSO_WP project in your NWDS Project Explorer and select Properties. 3. Select Java Build Path and click Add External JARs on the Libraries tab. 4. Browse to httpcomponents-client-4.1.2\lib and select all 6 JAR files. Click Open. 5. Click OK in the Properties window. 2011 SAP AG 8

Updating the Deployment Descriptor The deployment descriptor contains the following initialization parameters used by the servlet: host The fully qualified domain name or IP address of the AS ABAP instance hosting BPC 10 NetWeaver. port The TCP port used by the Web Application Server hosting the BPC 10 NetWeaver instance. protocol Either HTTP or HTTPS. o Note If you select HTTPS, you must ensure that your AS Java system trusts the WAS servers certificate and certificate path. environment The default Environment or Appset for the EPM Add-In to connect to unless another is specified in the request. To update the deployment descriptor: 1. Launch NWDS. 2. Expand PCNW10_SSO_WP and double click on the Deployment Descriptor 3. Ensure you are looking at the Design View 2011 SAP AG 9

4. Expand web-app > servlet. There are four init-param blocks, one for each initialization parameter. Expand the first init-param (param-name = host) and update the param-value to reflect the FQDN or IP address of your BPC 10 for NetWeaver WAS server. 5. Expand the second init-param (param-name = port) and update the param-value to reflect the TCP port of your BPC 10 for NetWeaver WAS server. 6. Expand the third init-param (param-name = protocol) and update the param-value to reflect the transport protocol to use when connecting to your BPC 10 for NetWeaver WAS server. Note: You should use HTTPS in a production landscape to ensure that the SAP Logon Ticket and Reentrance Tickets don t cross the network in clear text, unless you are certain that communication between the AS Java and AS ABAP systems is on a trusted network. 7. Expand the fourth init-param (param-name = environment) and update the param-value to reflect the default environment (appset) to use if one is not provided in the HTTP request. 8. Save the deployment descriptor (web.xml) using File > Save or CTRL + S. 2011 SAP AG 10

Deploying the Web Application Web applications are deployed to the Enterprise Portal via NetWeaver Developer Studio (NWDS). This section provides step-by-step instructions for creating and deploying our new Enterprise Application. Creating the Enterprise Application 1. Launch NWDS 2. Click File > New > Enterprise Application Project 3. Enter PCNW10_SSO_EA as the project name. Click Next. 4. Select PCNW10_SSO_WP as a Java EE Module Dependency and select Generate application.xml deployment descriptor. Click Finish. 2011 SAP AG 11

5. Right click on the project PCNW10_SSO_EA in the Project Explorer and select Properties. 6. Select the Server page, select the server you want to deploy this project to and click OK. Tip: You can add servers by navigating to Window > Preferences > SAP AS Java and clicking Add. Deploying the Enterprise Application 1. Open the J2EE Perspective by clicking on the Open Perspective button in the upper right hand of the NWDS display and selecting Other. 2. Select Java EE and click OK. 2011 SAP AG 12

3. Switch to the Server s tab in the bottom pane. 4. Right click your server and select Add/Remove. 5. Select PCNW10_SSO_EA and click the Add > button. Click Finish. 2011 SAP AG 13

6. Right click PCNW10_SSO_EA in the Servers tab and select Publish. 7. Verify the project deployed successfully in the Deployment View Console tab. Testing the Web Application We will perform two tests in this section. In the first test, we will navigate to the servlet directly. This will launch the EPM Add-In using the server, port, protocol and environment that you specified in the deployment descriptor. This test provides a viable solution for simple integration scenarios where users only access a single environment hosted on a single server. The servlet responsible for launching the EPM Add-In can also use URL parameters to override the default server, port, protocol and/or environment specified in the deployment descriptor. In the second test, we will use a JSP page included in the web application to override the host we specified in the deployment descriptor. The JSP page creates the appropriate URL based on your specifications and can be used to generate links for more complex integration scenarios (i.e. where there are multiple BPC 10 NetWeaver servers and environments). Testing the Servlet 1. Launch internet explorer and navigate to the servlet Default URL is http://as_java_server:port/pcnw10_sso_wp/epm_addin_launcher 2. You will receive a message stating that the MYSAPSSO2 logon cookie was not detected. Click the link provided to log into the Enterprise Portal. 2011 SAP AG 14

3. Enter your Enterprise Portal credentials. 4. Navigate back to the URL provided in step 1. You will see the Reentrance Token used as output in Internet Explorer 5. The EPM Add-In will be launched providing you with one of two logon prompts: a. If you already have a connection in the EPM Add-In for the specified host, you will be logged in automatically b. If you don t have a connection in the EPM Add-In for the specified host, you will be prompted to select which application to log into. Note: When deploying this on the portal, you can launch the servlet in a hidden IFrame to keep the details from being displayed to end users. 2011 SAP AG 15

Using the Test JSP Page In this section we will use the provided JSP page to override the hostname we specified for the BPC 10 NetWeaver server (in the deployment descriptor) with the IP address. In real life you would change parameters to match the various BPC 10 NetWeaver environments that you want to integrate with the Enterprise Portal. You could add the resulting URL s as portal content to complete your integration scenario. 1. Launch internet explorer and navigate to the test page. Default URL is http://as_java_server:port/pcnw10_sso_wp/index.jsp 2. Select GET as your HTTP method and change one of the host/port/protocol/environment parameters to another valid value. Note: The most likely candidates for things you can change are the host (use IP Address if you specified the FQDN in the deployment descriptor or vice-versa) and environment. Note: HTTP GET requests pass parameters via the URL while POST requests pass parameters in the request body. The servlet supports both, but GET is much easier to demonstrate since the URL is easily viewed. 3. Click Test it Out. Note: If the servlet fails to find the MYSAPSSO2 cookie, log into the portal then navigate back to the test JSP page. 4. Note the URL for the servlet it now includes an HTTP parameter for host/port/protocol and environment. You can use these parameters to tell the servlet to launch the EPM Add-In against different BPC 10 instances and/or environments. 2011 SAP AG 16

Related Content BPC 10 for NetWeaver Authentication Scenarios Blog Implementing Client Certificate Authentication in SAP BusinessObjects Planning and Consolidation 10.0, version for NetWeaver SBOP PC 10 for NetWeaver Security Guide SAP NetWeaver 7.3 Security Guide > User Authentication and SSO For more information, visit the Enterprise Performance Management homepage. 2011 SAP AG 17

Copyright Copyright 2011 SAP AG. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. Microsoft, Windows, Excel, Outlook, and PowerPoint are registered trademarks of Microsoft Corporation. IBM, DB2, DB2 Universal Database, System i, System i5, System p, System p5, System x, System z, System z10, System z9, z10, z9, iseries, pseries, xseries, zseries, eserver, z/vm, z/os, i5/os, S/390, OS/390, OS/400, AS/400, S/390 Parallel Enterprise Server, PowerVM, Power Architecture, POWER6+, POWER6, POWER5+, POWER5, POWER, OpenPower, PowerPC, BatchPipes, BladeCenter, System Storage, GPFS, HACMP, RETAIN, DB2 Connect, RACF, Redbooks, OS/2, Parallel Sysplex, MVS/ESA, AIX, Intelligent Miner, WebSphere, Netfinity, Tivoli and Informix are trademarks or registered trademarks of IBM Corporation. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries. Adobe, the Adobe logo, Acrobat, PostScript, and Reader are either trademarks or registered trademarks of Adobe Systems Incorporated in the United States and/or other countries. Oracle is a registered trademark of Oracle Corporation. UNIX, X/Open, OSF/1, and Motif are registered trademarks of the Open Group. Citrix, ICA, Program Neighborhood, MetaFrame, WinFrame, VideoFrame, and MultiWin are trademarks or registered trademarks of Citrix Systems, Inc. HTML, XML, XHTML and W3C are trademarks or registered trademarks of W3C, World Wide Web Consortium, Massachusetts Institute of Technology. Java is a registered trademark of Oracle Corporation. JavaScript is a registered trademark of Oracle Corporation, used under license for technology invented and implemented by Netscape. SAP, R/3, SAP NetWeaver, Duet, PartnerEdge, ByDesign, SAP Business ByDesign, and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries. Business Objects and the Business Objects logo, BusinessObjects, Crystal Reports, Crystal Decisions, Web Intelligence, Xcelsius, and other Business Objects products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of Business Objects S.A. in the United States and in other countries. Business Objects is an SAP company. All other product and service names mentioned are the trademarks of their respective companies. Data contained in this document serves informational purposes only. National product specifications may vary. These materials are subject to change without notice. These materials are provided by SAP AG and its affiliated companies ("SAP Group") for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. 2011 SAP AG 18