Preview

SAP HANA SPS 07: Security

Powerful Essays
Open Document
Open Document
4051 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
SAP HANA SPS 07: Security
What´s New? SAP HANA SPS 07
Security
(Delta from SPS 06 to SPS 07)
SAP HANA Product Management

November, 2013

Agenda
Authentication
User/role management
Authorization
Encryption
Audit logging
Documentation

© 2013 SAP AG. All rights reserved.

Public

2

Authentication

What’s New in SAP HANA SPS 07: Security
SPNEGO support for SAP HANA XS
SPNEGO (Kerberos with Simple and Protected GSSAPI Negotiation Mechanism) is now available as an authentication option for SAP HANA XS
Configuration
1. In Microsoft Active Directory, for each host and alias register new service principal names and map them to the
(potentially already existing) SAP HANA service user
2. On the SAP HANA server, add the keys for the new service principal names to the keytab
3. In SAP HANA, configure the Kerberos user mapping for the user
Note: If the user mapping has already been set up for Kerberos authentication for SQL access, you do not have to change anything here
4. Using the SAP HANA XS Administration Tool (http://<host>:80<sysno>/sap/hana/xs/admin/), select SPNEGO as authentication method for the user

© 2013 SAP AG. All rights reserved.

Public

4

What’s New in SAP HANA SPS 07: Security
SAP Logon Ticket and SAP Assertion Ticket support
SAP Logon Tickets and SAP Assertion Tickets are now supported for both SQL and XS access
Prerequisites
 A separate trust store for SAP Logon and Assertion tickets has been configured
 System privilege USER ADMIN

Configuration
1. In the Systems view in SAP HANA studio, choose Security
2. Create a new user by right-clicking on Users and choosing
New User
3. Select the authentication method(s) and choose the
(Deploy) button

Notes
 Prior to SPS 07, SAP HANA implicitly selected both user name/password and SAP Logon Tickets as authentication methods for new users. Now you have to explicitly set authentication options for new users
 To re-enable the old behavior for SAP Logon Tickets, a new configuration parameter has been introduced
(Indexserver.ini ->

You May Also Find These Documents Helpful

  • Satisfactory Essays

    The company is reengineering the company’s Intranet/Information systems and enterprise resource planning (ERP) system. The upper management has chosen to implement SAP to connect all aspects of the company; accounting, manufacturing, aircraft services, supply inventory, and customer resource management (CRM). Implementing this new information system (IS) will allow the different parts of the company to operate as one, by allowing the various modules in SAP to communicate and exchange data. SAP will replace all of the outdated and splintered software the company currently uses by allowing easier communication between the departments and the programs that are used. The change was started about three years ago and will be completed in about two years for a total of five years to complete and be fully implemented. Connecting all of the different departments will save a tremendous amount of money for the company. Reengineering the IS systems will allow the sales department and customer representatives more easy access to the customer’s information, such as current and future orders, current aircraft service status or new aircraft delivery time; thereby increasing the customers value and customer…

    • 464 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Assume that instead of entering the value of 1, you accidentally tried to enter the letter Q (which is just below 1 on the keyboard). SAP would not have allowed it. If the speakers to your computer were turned on, you would hear an error sound when trying to type the letter Q into the field.…

    • 711 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    IT302 Assignment 5.1

    • 308 Words
    • 2 Pages

    g. What is the ability to respond to multiple IPs or names as if the server were multiple servers called?…

    • 308 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Because SAP software implements ¡§best practices¡¨ of companies it has studied, including its customers. Any organization that implements SAP must change its business processes to reflect those found in the way SAP¡¦s applications operate. Failure to do so is asking for implementation failure.…

    • 509 Words
    • 3 Pages
    Satisfactory Essays
  • Better Essays

    SAP ERP stands for Systems, Applications, and Products in Data Processing. It began in Germany in 1972. SAP ERP has its advantages and disadvantages. It allows easier global integration, updates only need to be done once, provides real-time information, and creates and efficient work environment. On the downside, there is locked relationship by contract; inflexibility and the implementation have a risk of project failure.…

    • 908 Words
    • 4 Pages
    Better Essays
  • Powerful Essays

    Sap America Case Study

    • 1429 Words
    • 6 Pages

    The case is about a company named SAP America, which is the abbreviation for Systems, Applications and Programs in Data Processing, which in three short years had gone from a smaller company to the heavy hitter within the corporate computing world. Within this case there were many details brought to light on the ambition of the founding members, and the eventual additions to the SAP team. The case details how this firm took their R/3 product, which was a real-time, integrated applications software, and changed the game of product market infiltration.…

    • 1429 Words
    • 6 Pages
    Powerful Essays
  • Better Essays

    Kahuna Cleaning Supply

    • 2354 Words
    • 11 Pages

    Kahuna Cleaning Supply is a family-run business based in New Haven that specialized in commercial cleaning supplies.…

    • 2354 Words
    • 11 Pages
    Better Essays
  • Good Essays

    SQLserverSecurity

    • 393 Words
    • 3 Pages

    MS SQL server allows two types of logins Windows/operating system authenticated and SQL server authentication. This can be accomplished in either the configuration manager or through TSQL. In this case, the configuration manager will be used to create a user login. This will create a password of the database on a per user instance. Using Windows login will allow permissions based upon Windows groups with assigned privileges. The following steps are used:…

    • 393 Words
    • 3 Pages
    Good Essays
  • Good Essays

    Steps

    • 1343 Words
    • 6 Pages

    Note: Firefighter IDs cannot be used for SAP logins. Do not use existing userIDs as Firefighter IDs.…

    • 1343 Words
    • 6 Pages
    Good Essays
  • Satisfactory Essays

    6. Each time you use Bloomberg to take a session, you will need to login using your personal username/password…

    • 437 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    If Döngüsü

    • 1355 Words
    • 6 Pages

    This document states how to create Web Service from an existing Function Module or BAPI and how to use that for any business scenario using SAP Interactive Forms by Adobe. Form created by this method can be used standalone without portal, to submit data to SAP database within Organization‟s Intranet. Author: Vaibhav Tiwari…

    • 1355 Words
    • 6 Pages
    Satisfactory Essays
  • Good Essays

    So whenever a new entry happens in disti_end_customer table , it interacts with SAP-BP application and now the SAP-BP uses DataFlux (DFX) tool which operates on the tables present in SAP-BP and E2 and propose whether it can be linked to an old customer ; or if it’s a new customer then it must be first created in SAP-BP. This is the way, dataflux’s role is defined. The results proposed by DataFlux would be manually corrected by ST user or US user, the information is then flown in to SAP-BP or GBMS (Geographical Business Management System), used for commission purposes.…

    • 907 Words
    • 4 Pages
    Good Essays
  • Powerful Essays

    Biq Optimization

    • 2205 Words
    • 9 Pages

    November 10, 2011: updated recommendation for parameter log_buffer (SAP note 1627481) updated recommendation for deprecated parameter remote_os_authent (SAP note 1622837)…

    • 2205 Words
    • 9 Pages
    Powerful Essays
  • Satisfactory Essays

    Hana

    • 39990 Words
    • 160 Pages

    SAP HANA Database Architecture. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 SAP HANA Extended Application Services. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 Refactoring SAP HANA-Based Applications. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 SAP HANA Development Platform. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 Developer Scenarios. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 4.1.1 4.1.2 Scenario: Developing Native SAP HANA Applications. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 Scenario: Using Database Client Interfaces. . . . . . . . . . . . . . . . . . . . . .…

    • 39990 Words
    • 160 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Please make sure you have installed all HP-UX operating system patches as outlined in SAP note…

    • 782 Words
    • 5 Pages
    Satisfactory Essays