on 06-10-2008 12:53 PM
Hello Experts,
I am working on the following offline scenario:
User fills in the Travel Form offline and sends the same by an email to one particular email ID. From this ID, we read the form, parse the same to get the data and then call the RFC to create Travel Request in SAP. This scenario is working fine.
However, I am thinking about security concerns of the same. Since anyone who has access to the form and an SMTP Server and can send a request in someone's name and this will create a travel request in SAP for that person.
So apart from digital signatures, what are my options? How can I make this scenario secure.
Regards,
Shubham
Hi Shubham,
If you do not want to use dig signatures (either on a pdf form or a signed email) the only thing you could do is to make it harder to break your scenario. "Making it harder" means that it can be broken.
You could use visible and or invisble IDs. In case of visible IDs you could ask your users to provide it (like the employee number or a transaction approval code). The latter is a specific secret only know to the user and a lot of variants of this approach exist.
So you can decided if it is sufficient to make it reasonably hard (this depends on you, the company and/or the scenario) or you want to go with digitally signing emails/pdfs.
Regards,
Juergen
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
89 | |
10 | |
9 | |
9 | |
9 | |
6 | |
6 | |
5 | |
5 | |
4 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.