SAP Fiori

Authentication & Single Sign-On

15 flashcards · answers and spaced-repetition review in the KnowCard app

You want an SSO mechanism that needs no issuing system reachable at logon time (e.g. for Internet-facing or occasionally-disconnected devices). Why is X.509 a fit, and what is the catch that disqualifies it for greenfield landscapes?
A landscape has users in several domains and you must map them to SAP users without a one-to-one account match. Which SSO mechanism is built for this, and what specifically lets it bridge the domains?
On the intranet, Kerberos/SPNEGO gives the smoothest Fiori SSO experience. What is the trade-off that decides whether it's actually feasible for your project?
Two near-twins for Fiori SSO: SAML 2.0 and Kerberos. For Internet-facing access, which do you choose and what single network requirement decides it?
After a user authenticates once on the ABAP front-end server, why don't subsequent Fiori requests re-authenticate from scratch — and what's still NOT skipped?
You've set up the ABAP front-end server to issue SAP logon tickets but HANA-served apps still reject SSO. What configuration step on the acceptor side was missed?
Why must you NOT choose Kerberos/SPNEGO as the SSO mechanism for users who connect from outside the corporate network, and what is the only workaround?
Kerberos is sold as keeping passwords off the network. Concretely, what mechanism achieves that, and what is exchanged instead?
A common misconception: SAML 'passes the login' across organizations. What does SAML actually communicate between an identity provider and a service provider?
Logon-ticket SSO works within one system but silently fails between two systems in different DNS domains. Which constraint did the landscape violate, and why is the failure silent?
With logon-ticket SSO, why can't you simply map an ABAP username to a differently-named HANA database user, and what extra naming constraint kicks in with all classic app types?
Which SSO mechanisms support which classic Fiori app types — specifically, which ones cover analytical/search apps (SAP HANA XS) and which do not?
In the service-provider-initiated SAML flow, the SAP Gateway never checks the user's password yet grants a session. On what basis does it decide to trust that user?
Compared with token-based SSO, X.509 client certificates add two ongoing operational duties. What are they, and why does long certificate validity create the second one?
A team picks SAML 2.0 as the single SSO mechanism for ALL Fiori app types, including analytical. What breaks, and what does it force them to add?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play