cancel
Showing results for 
Search instead for 
Did you mean: 

Secure Login Client does not bring SL Server Certificate

yakcinar
Active Contributor
0 Kudos

Hello,

We want to implement NW Single Sign-On for our SAP systems. We have done the implementations as follows; (with the help of Implementation Guide and http://scn.sap.com/docs/DOC-40179 Implementing Single Sign-On with X.509 Certificates)

Secure Login Server

  • We installed NW 7.4 and Secure Login Server 2.0 SP4
  • Configured UME for MS AD
  • Initialized the Secure Login Server
  • Activated SSL
  • Activated SPNEGO
  • Configured Apache Reverse Proxy

Secure Login Client

  • Imported Root CA to client
  • Applied Policy Registry files (ProfileDownloadPolicy_xxx.reg)
  • Installed SL Client
  • Inserted “ShowUserPoliciesPage” with the value 1 in the registry path

System Info is as follows;

SL Server FQDN          : mycmnwsso.mycmp.com.tr

SPNEGO User              : SL-JAVA-SSO (SPNs: HTTP/mycmnwsso.mycmp.com.tr, HTTP/sso.mycmp.com

SLA Console URL        : https://sso.mycmp.com/slac           

Enroll URL                    : https://sso.mycmp.com:443/SecureLoginServer/slc/getProfiles?grouppolicy...

I login to one of the client with domain user. I donot see the SLServer Root Certificate on SL Client. I opened trace. There is “[2014.12.03 17:08:50.754000][WARN ][sbus.exe            ][LOADER      ][ 6300] ERROR(0xA0800200) in sec_get_SEC_DLL: Failed to load library sbusslogin” error.

Why I cannot get SL Certificate on SL Client?

Although I entered ShowUserPoliciesPage registry entry I cannot see Profile tab page on SL Client Tool?

Any recommendation about the issue?

Can you help, please?

Thanks and Regards,

Yuksel AKCINAR

Accepted Solutions (1)

Accepted Solutions (1)

former_member200373
Participant
0 Kudos

Hello,

seems that you missed to install the Secure Login Server support for Secure Login Client.

It is not checked in the default feature selection of SAPSetupSLC.exe.

-- Stephan

yakcinar
Active Contributor
0 Kudos

Thank you Stephan,

I reinstalled using the feature selected. Now Policy Groups tab has come.

And I see some more logs.

Try to solve other problems now.

former_member190695
Participant
0 Kudos

HI Yuksel,

You should get the user certificate in the Secure Client Login.

The SL root certificate (issuer) should be installed manually or distributed by an Active Directory policy.

Regards,

Ridouan

Answers (0)