SAP Fiori
Web Dispatcher & Communication Security
26 flashcards · answers and spaced-repetition review in the KnowCard app
The client-to-Web-Dispatcher channel is HTTPS for both transactional and fact sheet apps. What payload distinguishes them on that same channel?
OData flows from the browser inward. So is the front-end-to-back-end hop also HTTP/OData, and what secures it?
Which profile parameters turn on HTTPS handling in the Web Dispatcher instance profile?
Three scenarios are configured after installing Web Dispatcher: HTTP, SSL termination, SSL reencryption. What actually differs between the two SSL scenarios, and when does it matter?
You've enabled TLS/SSL across the Fiori landscape. Which connection is still unencrypted, and what fixes it?
Internet users reach Gateway servers behind the corporate firewall. What is the single published endpoint making this possible, and what breaks if it's bypassed?
A junior admin says SAPGENPSE will "create the trusted certificate" for the Web Dispatcher. What's wrong with that?
RFC traffic is already inside the corporate network. What does adding SNC give you that TLS does not?
You enable SNC on an ABAP system via RZ10. With the standard parameter set, are internal RFCs now protected — and what else is mandatory before it takes effect?
Why is it a mistake to rely on SAP Web Dispatcher alone as your web application firewall for an Internet-facing Fiori app?
Two cookie flags harden Fiori sessions. Which one blunts XSS cookie theft, which one keeps the cookie off plaintext channels — and don't mix them up?
How do you enable HTTPS for SAP HANA XS, and what's the step people skip?
On a fresh system a delivered Fiori app returns service-not-found. Before assuming a bug, what's the most likely cause?
A user launches a Fiori app. The request passes the Web Dispatcher first — so where does the initial user authentication actually happen?
How do you secure an existing RFC destination with SNC in SM59, and when is the SM59 entry alone not enough?
Trace one analytical and one fact sheet request through a classic Fiori landscape: where does the protocol stop being HTTP/OData, and why does that boundary matter for security?
Do transactional Fiori apps always need a reverse proxy, and what specifically flips that requirement?
Why do URL rewrite rules belong at the reverse proxy rather than the app server, and what's the safe HTTP-method policy there?
How does the Web Dispatcher decide whether a URL goes to the front end, the back end, or SAP HANA XS — and what breaks if a prefix is missing from the lists?
Of Web Dispatcher's three roles — load balancing, web acceleration, security/anonymity — which one offloads SSL work, and what does that offload expose if you stop there?
Beyond plain forwarding, what does it mean that the Web Dispatcher can "intercept, inspect, and interact" with traffic — and what new routing inputs does that unlock?
During the TLS handshake, what actually makes a client trust the server's certificate — and why does a self-signed Web Dispatcher cert fail even with a correct hostname?
HTTPS is enabled on the Web Dispatcher. After it terminates SSL, what is the security state of traffic behind it, and what's the fix?
Under which single condition does the Web Dispatcher ever forward to SAP HANA XS, and which app types never reach it?
Outline the steps to set up SSL between the Web Dispatcher and the front-end server, and name the two steps people forget.
Reading icm/server_port_0 = PROT=HTTPS, PORT=443, TIMEOUT=120, what is the timeout — and what's the easy misread?
Start learning today
Free to start — download the app or use it in your browser.
