Installation guide

Configuring the SAP Systems
150 Sun ONE Identity Server Policy Agents 2.1 Web Policy Agents Guide April 2005
Configuring the SAP Systems
To set up the SSO environment, you need to configure at least one SAP system to
issue SSO2 logon tickets and some other systems to accept the SSO2 logon tickets.
The following sections provide steps to configure these systems.
Configuring SAP R/3 System and the ITS
instance
As stated in the section Prerequisites, the connection between AGate and the
ticket-issuing SAP system need to be configured for SNC. The following
instructions describe how to configure the SAP R/3 system and its corresponding
ITS instance. For instructions on how to install SNC, please refer to the SAP SNC
User’s Guide.
1. On the ticket issuing SAP R/3 system, configure the following parameters in
the
DEFAULT.PFL
file.
2. Specify AGate’s SNC information in the system access control list for SNC.
This list is available in the table SNCSYSACL, view VSNCSYSACL and
TYPE=E.
Enter the SNC name for AGate in the SNC name field.
Select the following options:
Entry for RFC activated
Entry for diag activated
Table 6-1 Parameters in
DEFAULT.PFL
Parameter Value
snc/enable 1
snc/gssapi_lib path_to_SAPCRYPTOLIB
snc/identity/as SNC name of the application server
snc/data_protection_max 3
snc/data_protection_min 1
snc/data_protection_use 2