Skip to Content

Nakisa Single Sign On (SSO) using Logon Ticket Option – Netweaver 7.3 and Nakisa 3.0 SPS03 Onward

With Nakisa 3.0 SPS03 onwards SSO integration using SAP Logon ticket Configuration has been simplified (with less steps compared to previous releases) and with Netweaver 7.3 it has become little easy further.

With NW 7.3 you can execute all SSO Steps from Netweaver. (This means no need to execute STRUSTSSO2 on ABAP stack or log into ABAP systems).

SSO Configuration Steps on Nakisa side:

Refer to instructions in Nakisa Admin guide on How to set Authentication Settings to SAP Logon Ticket option on Nakisa.  

Please log on to Nakisa admin console of respective Nakisa application.

Configure it in the application AdminConsole. Go to Security Settings > Authentication Settings. Select Single Sign-on with Logon Tickets and click Next twice.

Enter the details of the SAP system and client where a copy of the Portal ticket is stored (note: this will not be client 000).

Click Next and then click Finish and Submit. Then click Save and Publish

Single Sign On (SSO) Configuration On Netweaver 7.3:

  1. Navigate to Certification Administration Page on NW 7.3 (àhttp://<hostname>:<httpport>/sso2))

With Certification Administration You can manage certificates exchange between following systems

  • Java <–> Java
  • ABAP <–> Java (you can avoid STRUSTSSO2)
  • ABAP <–> ABAP

This means even if Nakisa runs on NW 7.1 or 7.2 you can configure SSO with a Central Portal (7.3) in your landscape using Netweaver 7.3 Portal.

Configuration Steps:

Import ABAP certificate into NW7.3 Java System

Go to URL on NW 7.3 System http://<hostname>:<httpport>/sso2

/wp-content/uploads/2012/07/1_123553.jpg

  1. Click on Add Trusted Systemà

Enter (Nakisa Backend ABAP system, ECC) details

/wp-content/uploads/2012/07/2_123617.jpg

Click on Next

/wp-content/uploads/2012/07/3_123618.jpg

Click on Finish:

Import JAVA Certificate into ABAP System:

/wp-content/uploads/2012/07/4_123619.jpg

/wp-content/uploads/2012/07/5_123623.jpg

/wp-content/uploads/2012/07/6_123624.jpg

/wp-content/uploads/2012/07/7_123625.jpg

/wp-content/uploads/2012/07/8_123626.jpg

Save and publish the Nakisa Application Build.

Restart the Nakisa Application

Follow these steps to stop and start (restart) Nakisa applications

  1. 1.       In the SAP NetWeaver Administrator, choose   Operation Management  Systems  Start & Stop.
  2. 2.       Choose the Java Applications tab.

All available applications are displayed in a table format with the corresponding name, vendor, status and functionality.

  1. 3.       Select an application.

———————————————————————————————————————————————————————————-

On a Side Note (though it’s not needed for 3.0 SPS03 onwards),

Missing Config files Issue: if for some reason SSO Configuration still doesn’t work, then follow these additional steps

Solution:

  • Navigate to the path as described here (substitute with your build related location details).

/wp-content/uploads/2012/07/9_123627.jpg

  • Create folder with name root
  • And under root folder create XML subfolder.
  • Copy LoginConfiguration_SAP_SSO folder (and all its content) onto newly created XML folder.
  • /wp-content/uploads/2012/07/10_123628.jpg
  • Save and publish the building.
  • Restart the Nakisa Application. (go to NWAàselect the application and restart).

SSO Log Off Issue:

Issue: Sometimes when you log on with different user ids, you will see the first user data on Nakisa applications.

Solution: The browser stores the OrgChart session (Cookie), so if you don’t close your browser then when you log back in with SSO it continues to use the session stored in your browser.

One of the suggestions (Implementation Option) is to change the URL you use in your iView from http://server:port/OrgChart/default.jsp to http://server:port/OrgChart/logout.jsp.

Upon launching the iView this will log out of the application and then log back into the application, thus authenticating the user.

To report this post you need to login first.

4 Comments

You must be Logged on to comment or reply to a post.

  1. Andy Silvey

    Hi Satish,

    this is an excellent blog.

    We are in the process of implementing Nakisa 3 on NW7.31 at the moment too.

    All the best,

    Andy.

    (0) 
    1. Basis-SAA Team

      Hi Satish

      Thanks

      I am have my Portal 7.3 system and have setup Nakisa on another java Net weaver 7.4 system . I am trying to do the above . I have issues with the step “import Java certificate into the abap system.. The screens are very small.. How do we download the certificate from the Portal into the abap system from this screens

      (0) 

Leave a Reply