cancel
Showing results for 
Search instead for 
Did you mean: 

Migration from Kerberos V5 to CommonsCrytolib

former_member182832
Participant
0 Kudos

Hello,


we want to migrate from a non-SAP kerberos solution to SAP SSO 2. The existing systems (ABAP stack) have SNC and kerberos authentication activated using the standard MIT solution Kerberos (krb5) also in the client side.

We want to migrate to CommonsCryptolib but we are facing the following issues:

  • With Krb5 in SU01 snc user mapping is: p:xxxxxxx@domain.com but with SAP SSO it should be: p:CN=xxxxxxxxxx@domain.com
  • If we switch  to CommonsCryptolib the Kerberos MIT client does not work. therefore, we would need to setup the SAP Secure Login Client however we do not have access to the systems configured with the krb5.

We are aware that SAP does not provide any support for non-SAP solution. However  could you provide me any  recommendations on how to migrate to SAP SSO without impacting the client side?

Regards,

Mehdi.

Accepted Solutions (1)

Accepted Solutions (1)

donka_dimitrova
Contributor
0 Kudos

Hello Mohamed,

As a first step you have to make sure that you have the two SNC components on the client workstation before to migrate the server configuration.

Here in this blog you will be able to find some details:

For changing the SNC names you can use for example the transaction SNC1 to re-create the names and then transaction SNC4 to enable a new canonical name.

Regards,

Donka Dimitrova

former_member182832
Participant
0 Kudos

Hi Donka,

Thank you for your help. i will try it and share the result.

Regards,

Mehdi,

Answers (0)