The following section describes the required steps for setting up Single Sign-On (SSO) with Secure Network Communication (SNC) and Kerberos encryption in Xtract Universal.
Warning! Single Sign-On availability
ABAP application server has to run on a Windows OS and SNC with Kerberos encryption setup on SAP.
Activation of HTTPS in Xtract Universal #
- Enable access control protocol HTTPS (1) within the tab Web Server settings.
- Reference an existing X.509 certificate (2).
HTTPS port 8165 is set up by default
- Click [OK] to confirm (3)
Configuration of Windows AD service account #
- Create a Windows AD service account for Xtract Universal (XU) Server. This is the account the XU service is running under (XU service account).
- In the Attribute editor tab define two Service Principal Names (SPN). Use the following notation <service class</<host<, e.g., HTTP/FQDN.domain.local:8165.
- In the Delegation tab define the XU service account for constrained delegation - Use Kerberos Only.
- Enter the SPN of the service account under which the SAP ABAP application server is running (SAP Service Account), e.g., SAPServiceERP/do_not_care For more detailed information about the partner name notation in SAP, see the SAP Help portal.
- In the tab Log On, change the account to XU service account, e.g., firstname.lastname@example.org.
Xtract Universal Server Settings #
Warning! Incompatible library
Xtract Universal runs on 64bit OS only. Kerberos Wrapper Library gx64krb5.dll(64-Bit version) is required.
gx64krb5.dll from SAP Note 2115486.
- Copy the Kerberos Wrapper Library to the file system, e.g., to
C:\SNC\gx64krb5.dllof the machine, where the Xtract Universal service is running.
- Place the downloaded .dll file on each machine, where the Xtract Universal Designer is running.
- Open “Computer Management” by entering the following command:
- Under Local Users and Groups select Groups > Administrators.
- Click [Add] (4) to add the XU service account to the local admin group (5).
- Open “Local Security policy” by entering the following command:
- Select [Local Policies > User Rights Assignment]
- Act as part of the operating system
- Impersonate a client after authentication
- Change the registry settings of the XU server machine:
SAP Source Settings in Xtract Universal #
Note: An existing SAP connection to a Single Application Server or Message Server is the prerequisite for using SSO with SNC.
- In the main menu of the Designer, navigate to [Server > Manage Sources]. The window “Source Details” opens.
- Select an existing SAP source and click [Edit] (pencil symbol).
- Enable the SNC option (1) in the subsection Authentication.
- Enable the checkbox Impersonate authenticated caller (SSO) (2).
- Enter the complete path of the Kerberos library in the field SNC library
- Enter the SPN of the SAP service account in the field Partner name. Use the following notation: p:[SPN]@[Domain-FQDN-Uppercase] (4).
- Click [Test Connection] to verify your connection settings.
- Click [OK] to confirm.
Note: The SAP Logon Pad SNC settings for partner name differ from the ones used in Xtract Universal. SAP Logon Pad uses the UPN of the SAP service accounts and Xtract Universal uses the Service Principal Name (SPN). Use the following notation: p:[SAP Service Account]@[domain]. SPN’s are case sensitive in the SNC partner name.
SNC Activation in SAP #
In SAP, apply the Kerberos SNC settings as described in the SAP Help.