SAP S/4HANA Administration
Authentication, SSO & Communication Security
44 flashcards · answers and spaced-repetition review in the KnowCard app
An older integration design reaches for SAP logon tickets for cross-system SSO. Why is that the wrong call today, and what replaces them?
You're configuring SAP GUI SSO with Kerberos and jump straight to the Kerberos setup. Why does it fail, and what had to come first?
On the SAP Web Dispatcher, which PSE holds the cert for incoming HTTPS and which is for the hop out to the backend — and what symptom do you get if you swap them?
Kerberos SSO to your SAP system worked for weeks, then every user's SSO fails at once. What AD-side requirement was almost certainly violated?
Before you put a freshly configured SAP Web Dispatcher into the request path, how do you confirm it'll actually reach the backend instead of finding out from failing user traffic?
Your X.509 cert encrypts traffic whether it's self-signed or CA-signed, so why does production HTTPS still demand the CA-signed one?
If a connection is encrypted, is the data also guaranteed to be unaltered and to come from who it claims? Why or why not?
You imported a new server certificate via STRUST on one app server, but other app servers in the system still present the old cert. What did you misunderstand about where the PSE lives?
You need SSO that lets external business partners and cloud apps authenticate, not just internal employees logging into on-prem systems. Which SAP product fits, and which one leaves you short?
A TLS vulnerability needs a newer SAP Web Dispatcher, but you can't touch the connected system's kernel right now. Can the Web Dispatcher run a higher release than that kernel?
Why is Kerberos the wrong choice for SSO to an internet-facing app, even though it works perfectly for internal SAP GUI logon?
One SAP Web Dispatcher fronts several SAP systems and a request matches more than one system entry. Which wdisp/system_conflict_resolution setting do you want, and which one masks a misconfiguration?
You're standing up a Fiori central-hub landscape and wonder whether the SAP Web Dispatcher is optional. Is it, and what makes it non-negotiable there?
Kerberos/SNC SSO maps an AD identity to an SAP user via the SNC name. What's the exact format, and how do you avoid mapping thousands of users by hand in SU01?
Under the SAP Web Dispatcher's default load balancing, one healthy app server keeps getting far less traffic than the others. What drives the weighting, and what likely explains the skew?
A partner's X.509 cert is properly CA-signed, yet your client still rejects it as untrusted. What does verification actually rely on that's missing here?
You suspect an outdated CommonCryptoLib is behind a TLS handshake failure. Where can you read its version, and which method still works when the SAP system won't even start?
In the SSL handshake the server has a public key, yet the actual data flows under a shared symmetric key. Why bring asymmetric crypto into it instead of just agreeing on the symmetric key directly?
Among the three SSL PSEs — SAPSSLS, SAPSSLC, SAPSSLA — which does an ordinary browser session use, and what distinguishes the two client PSEs from each other?
A developer asks to enable is/HTTP/show_detailed_errors to make troubleshooting a production HTTP issue easier. Why do you say no?
When you wire S/4HANA into a SAML 2.0 federation, does it act as identity provider or service provider — and why does getting that backwards break login?
You configured client certificates and assume cert-only access is now enforced — but a user with no cert still gets in via password. What is icm/HTTPS/verify_client set to, and what should it be?
You're rolling out Identity Authentication for thousands of users and need accounts created and deactivated automatically as HR data changes. Which IAS capability makes that possible, and what are you stuck doing without it?
Users logging in through Identity Authentication keep being prompted to change their SAP password at first login — pointless for an SSO'd account with no usable local password. What do you set, and why does the default cause this?
SSL supports server, client, and mutual authentication — which mode do ICM and the SAP Web Dispatcher use out of the box, and what does that imply if you need to authenticate the client by certificate?
How is the SAP Web Dispatcher's web admin interface reached, and what's the riskiest mistake when exposing it on an internet-facing dispatcher?
To send someone a confidential message with asymmetric encryption, whose key do you encrypt with — yours or theirs — and what's the consequence of getting it backwards?
Setting up SSL across a multi-app-server system, do you generate one certificate request per server or a single one, and what's the trade-off?
SAP Cloud Identity Services has two components — which one logs users in, and which one creates and deactivates their accounts? Picking only one leaves which gap?
Across SSO building blocks, certificates and tokens/assertions both vouch for identity — but one carries an operational risk the other doesn't. What's the difference, and why does it matter?
You hardened the SAP system's TLS cipher list but outbound HTTPS calls still negotiate a weak suite. Which two parameters exist, and which did you forget?
You launch the SAML2 wizard in S/4HANA but it won't complete the trust setup. Which two prerequisites are most often missing?
You map X.509 logon certificates to user IDs through table USREXTID, but maintenance is painful. What more effective mechanism does S/4HANA offer, and what happens to the old table once you switch?
You want to bring an on-premise S/4HANA system into a cloud SSO landscape with SAP Cloud Identity Services as the identity provider. What role does S/4HANA play, and where do you configure and troubleshoot it?
You notice a PSE file named sap_system_pki_instance.pse in the STRUST file system that nobody created by hand. Where did it come from, and what must you never do with it?
A colleague proposes fixing an AS ABAP certificate quickly by editing the .pse file on the OS with sapgenpse. Why is that dangerous, and what is the correct path?
In UCON the RFC basic scenario stays inactive until you activate it, but RFC calls that arrive over WebSocket instead of CPIC behave differently out of the box. What's the difference, and how should you manage its allowlist?
The AS Java-based SAP Single Sign-On product is going out of maintenance. What is the successor for SAP GUI SSO, and what must the S/4HANA system trust for it to work?
An external system can call tens of thousands of remote-enabled function modules in AS ABAP, and S_RFC authorizations are often granted with wildcards. What does SAP provide to lock this down centrally, and how is it organized?
A user authenticated in SAP BTP needs to reach an on-premise S/4HANA system without a second logon. On the S/4HANA side, what has to be in place for this certificate-based identity forwarding to work?
TLS secures HTTPS traffic, but SAP GUI and RFC connections aren't HTTP-based. How does S/4HANA protect those connections, and which component does each side use?
Your team already knows SAML 2.0 for SSO, which exchanges a signed XML assertion. SAP now positions a modern alternative that drops XML entirely — what is it and how does it differ?
After an upgrade, RFC callbacks that used to work are suddenly blocked. Which hardened default is responsible, and how do you build the allowlist it needs?
Your landscape uses the licensed 'SAP Single Sign-On' product on an AS Java for Kerberos. Why plan to move off it, and what is the alternative for SAP GUI?
Start learning today
Free to start — download the app or use it in your browser.
