cancel
Showing results for 
Search instead for 
Did you mean: 

SSO to the Visual Administrator itself

Former Member
0 Kudos

We are trying to set up our Visual Adminstrator to allow us to log into the Visual Administrator tool itself using another method of authentication (certificates?) instead of username / password.

I have been looking at the login modules associated with the SAP-J2EE-Engine listed in the path Security Provider -> Runtime tab, Policy Configuration tab, Component SAP-J2EE-Engine.

We run the Visual Adminsitrator from a Solaris UNIX system and display it back to a Windows XP PC. We are trying to get the Visual Adinsitrator to recognize the certificates or some other identification from the PC and map that to a user within the Visual Administrator.

So far, we have not accomplished this but I am told by my manager, this was done in the past by a member of the team who is no longer available to us and who did not document what he had done. The original system was wiped out several years ago so we have nothing for comparison.

I know the component SAP-J2EE-Engine controls the logon to the Visual Adminstrator itself. I know I can use LoginModules to control that logon sequence. I have also tried to look up each of the LoginModules available to see what information can be passed with each to determine if they could be used to identify a user. So far, I have not had much success with any of this.

Has anyone ever tried to do this when logging into the Visual Administrator itself? Is this possible with the Visual Administrator or is my manager mistaken? Our solution can use any authentication - we would prefer certificates - but we are trying to eliminate the username / password authentication and use something a little more secure.

Thank-you in advance,

Deb Nugent.

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

While the response was not what I had hoped for, I am considering the question answered. The issue is not resolved from our perspective but it appears it is not now nor will be part of the design of this mechanism.

Former Member
0 Kudos

Hello Deb,

Unfortunately your manager is mistaken and there is no easy way to do what he is asking for.

Visual Admin supports only password authentication and therefore youu2019ll need to write a new client to use SSO.

Furthermore the p4 protocol that Visual Admin uses to connect to the j2ee engine support only password authentication and therefore youu2019ll need to change that too.

Thus you will have to re-write both the client and the server side to implement such authentication, which could be done only internally at SAP.

Since Visual Admin is not even part of the latest versions of NetWeaver (7.1 and later), plans for adding such functionality do not exist.

Maybe your colleague used SSO to connect to NetWeaver Administrator (NWA) in a browser.

Regards,

Ventsi Tsachev

Technology Development Support (J2EE Engine)

SAP Labs, Palo Alto, Ca (USA)