BSP-System-Login and 2 different DMZ

Hi all,
our current customer has installed an instance of SAP Web AS 6.20 in a DMZ. He has another DMZ where the reverse proxy is installed. So, SAP Web AS and reverse proxy are located in different domains.
When we call our BSP-App via Internet we first have to authenticate against the reverse proxy, then a rewrite rule leads us through two firewalls to the SAP Web AS in the other DMZ.
Actually we reach the system/login-page of our BSP. When we enter the logon credentials and press the logon button we are redirected every time not to our own start-page but again to our system/login-page. We are caught in a loop.
It seems that the SSO2 authentication is not valid for the domain of the SAP Web AS but for the reverse proxy.
Has anyone experience with this kind of system landscape or can give any comment?
Thanks, Bernd

Hi Bernd,
it seems to me that the sso2 cookie is getting eaten by the reverse proxy (they really do this sometimes But seriously, I assume:
1. initial request sent from browser to was
2. not authenticated - meaning redirect to system login
3. request with system login url sent to was
4. response with rendered login page sent back to browser
5. request with login credentials sent to was
6. authentication successful, redirect to your application
7. request with your application url sent to was
8. not authenticated - meaning redirect to system login
and so on ....
With system login and after succesfull authentication every request contains the sso2 cookie that keeps the authentication data and is verified at the was. This one seems to be missing in step 7. How can you prove this? Use one of the http tracing tools mentioned in Brian's weblog https://weblogs.sdn.sap.com/pub/wlg/180. [original link is broken] [original link is broken] [original link is broken] [original link is broken] [original link is broken] [original link is broken] [original link is broken] [original link is broken] [original link is broken]
Verify step 6. Make a hardcopy of the trace and present it to the reverse proxy admins. Otherwise they're not going to believe you.
Ulli

Similar Messages

  • Call an other service with a different login and paswword

    Hello
    From my BSP application I need to add a link to a BEX service. To do, I need to set the login and password with a hidde method (User does have to fill login and password) ...
    Is a method is available to do ... ?
    Message was edited by: Jerome FORTIAS

    Hallo Jerome,
    There are easy methods to transfer the username and password via the URL. <b>However, this add major security risks.</b> (One example, this information is suddenly stored in the browser history.) If you really insist on using this technique, please check documentation.
    The better technique to do this, is just to configure SSO2. Then a SSO2 cookie is issued, and with the correct configuration it is accepted by all other systems. Currently the SDN home page has a good article on how to configure SSO2.
    Alternative, have users use X.509 certificates. However, this is a lot of work, as software must be installed on each PC.
    ++bcm

  • Junked old macbook for a new one. changed apple id password from a different mac. i want to login and it asks for name and password. no matter what i type i cant seem to login. any way help?

    junked old macbook for a new one. changed apple id password from a different mac. i want to login and it asks for name and password. no matter what i type i cant seem to login. why cant i just enter my apple id and password. or is there a way to change whatever name and password are on the new one from another mac so i can login. anything helps...thanks

    Just open System Preferences>Users & Groups and unlock the preference pane with your root password.
    Set the New Account to be an Administrator and fill in the rest of the data and then click "Create User".
    I would suggest using this user to be YOU with admin capabilities. I wouldn't use the root user - too much damage could occur if you're not sure what you're doing. If you have files, etc., that you want to move to this account, simply but them in the Shared folder - or if you 'rescued' some old files and the like from your 'trashed' MBP, you can put them in your NEW admin account folders.
    Hope I've explained myself well - call back with any questions!
    Clinton

  • Business Package, Alias and different systems....

    Hello everybody,
    I have got some questions concerning the mentioned topics.
    I have a business package (Internal Sales Repr.) and it is already installed.
    <b>1.</b> On each iView in the business package there is set an ID for a SAP System, for example a BW. Is this the SID or is it the ALIAS I defined for a system to access the BW?
    <b>2.</b> There is a machine with enterprise portal, R/3 and BW running under the same SID. They all have different clients. (thank god it is a test system and not productive)
    Do I need to create different systems in the portal to access to BW and R/3 because of the different clients?
    Is it generally possible to implement SSO form the portal to the Backend, if they have the same SID?
    <b>3.</b> The ID from 1. is not set as a deltalink. Is it defined by default or it is set when I install the business package?
    Wow, a lot of stuff. But I hope you can help me
    thanks
    christian

    Hi Christian,
    Two different system has to be created in portal. In the system object you have to set the connector properties, user admin, user mapping and the WAS for BW and ITS for R/3 properties.
    You have to create the system alias and the test the connection.
    For import and export of the certificates. you have to use Strustsso2 transaction.
    Regards
    Arun

  • Multiple "login" and "System" keychains

    My menu bar lock icon shows two entries for keychain "login". There are also 2 entries for "login" in Keychain access. This is also true for my "System" keychain. They can be both locked, both unlocked or one of each. If I delete the extra one, they both get deleted. There are still two "login" keychains in the list, but the lock icon is gone and an empty square is shown instead (for both of them). There is only one login.keychain in my ~/Library/Keychains and only one System.keychain in /Library/Keychains. This all applies to my Power Book. On my iMAC, keychain access shows 2 "System" keychains but only one "login". What are these extra keychains and how do I get rid of them. It's not really a problem (everything works like I think it's supposed to), it's more of a nuisance and a puzzle that I really want to solve.

    Hi Zaheer,
    Thanq for reply,
    SM04 we can find no.sessions and terminals , but i am looking for mutiple logons login and logout timings.
    Thanks,
    sksk.

  • I NEED TO GET LOGIN AND LOGOUT TIMING DETAILS FROM CLIENT SYSTEMS

    HI,
    CAN ANYONE PLEASE HELP ME ON HOW TO GET LOGIN AND LOGOUT , CLIENT EVENT DETAILS FROM CLIENT SYSTEMS ON SERVER 2008 R2.
    THANKS,
    KUMAR.

    You may need to enable active directory Logon/Logoff Audit event.
    The Audit logon events policy records all attempts to log on to the local computer, whether by using a domain account or a local account.
    On Domain Controller, this policy records attempts to access the DC only.
    By using these events we can track user's logon duration by mapping logon and logoff events with user's Logon ID which is unique between user's logon and logoff.
    Please refer to this blog to understand the complete process to audit the successful or failed logon and logoff attempts in the network using the audit policies :
    http://www.lepide.com/blog/audit-successful-logon-logoff-and-failed-logons-in-activedirectory/
    Lepide - Simplifying IT Management

  • Partition Restore Cold Backup Different System and Different Version DB

    Is it possible, can we restore the cold backup at different database version and different operating system(but same ENDIAN_FORMAT) ????????
    My original system HP-UX (64-bit) and database version 10.2.0.3.0 i have cold backup and i want to partion restore on Linux Redhot 5.5 (64-bit), database version 10.1.0.4.0 .
    If it is possible. How can i do this.

    My original system HP-UX (64-bit) and database version 10.2.0.3.0 i have cold backup and i want to partion restore on Linux Redhot 5.5 (64-bit), database version 10.1.0.4.0 .1. AFAIK you can not do it i mean wiht cold backup move from HP to linux
    2. You can try to use exp-imp if you want to change db version.
    See below notes:
    Master Note For Oracle Database Upgrades and Migrations [ID 1152016.1]
    Different Upgrade Methods For Upgrading Your Database [ID 419550.1]
    Regard
    Helios

  • Dynamic System Resolution and Custom Login Modules

    I'm trying to achieve the following, and wondered whether anyone could validate that is possible, and possible solutions.
    We want to use Dynamic System Resolution to programatically determine which system alias (and therefore which R3 client) should be returned based on the user. So far so good.
    When the user logs in, we want them to be able to specify which R3 client they wish to use whilst logged in to EP. We are considering writing a custom login module to do this, which will strip the client the user wishes to use out of the j_user username, and stores the client value *somewhere* so that the Dynamic System Resolution code can access it and base the system alias it returns on the user's prefered client.
    Considering the DSR code only has access to the IUser object it would be handy if our login module could store the prefered client as an attribute in the IUser object. Is it possible to set custom attributes in custom login modules for a given user?
    We want to do this to avoid having to have an EP instance per client in a given R3 system, and to avoid duplicating worksets by creating delta linked copies and overriding the client number.
    Any suggestions?
    Cheers,
    Steve

    Hello,
    Before even doing such an elaborated construction, I do not succeed in writing a working Dynamic System Resolution.
    The service doing the resolution is never called when the method getSystemID() is invoked.
    I know that the registry is read (I first test with a system alias which was in the PCD and get an error when debugging, I forget that you cannot use the same system alias in the PCD and in the Dynamic System Resolution service) but afterward the resolving service is not called.
    Has anyone an idea ?
    Thanks a lot
    Best regards
    Richard

  • Airport password created in login and system keychain both..

    Hey,
    I've been having a few vexing problems with my new MacBook 2.16 running 10.4.6 that I was hoping that I might get solved on here. I've been unable to get my machine to use the airport password in the system.keychain. If it's not in the login.keychain, it doesn't work. I've tried deleting and re-creating the keychain using systemkeychain -vfCt and it still doesn't work. Anybody have any ideas? I'm downloading the Combo 10.4.6 updater to see if that corrects the problem. I've already tried to repair permissions.
    If I elect to save the password to an airport network, it is saved in both the login and system keychain and I'm not sure if this is the correct behavior.

    I've applied the 10.4.6 Combo updater, no affect upon the problems that I've been having with airport. It just won't seem to use a password stored in the system.keychain for some reason.

  • Fixed assets depreciation wherein local and system currency is differeent

    Hi,
    We just have a question regarding the Fixed Asset Depreciation if Local and System Currency is different.
    Setup of Currency:
    Local Currency = USD
    System Currency = Peso
    During monthly amortization the depreciation is in Local Currency (USD) converted amount at the time of acquisiton if other currency is used. The corresponding system amount which is in Peso will use the FOREX rate based on the posting date of the depreciation run.
    What we want is to maintain a correct lapsing schedule of Fixed Assets in both PHP & USD, and both following the accounting standard.   Therefore, to be in line w/ the standard, we have to use the historical rates.
    Is it possible that when the depreciation was posted in system currency the historical or the acquisition rates will be used not the conversion rate when the depreciation was done?
    Thanks,
    Janice

    Hi Janice,
    I don't think that is possible to maintain system consistency.  if you could assign FOREX arbitrarily, what is your accounting principle?
    Thanks,
    Gordon

  • Different system drive and  applications drive

    I recently added a Raptor Drive and wanted to use it as a system drive and then use my 160GB drive that came with the computer as an application drive.
    Well after moving my stuff over to the Raptor Drive and tried to open Final Cut is said something to the effect that this was not the correct device or hardware. I think that is a feature of copy protection so you can't just copy Final Cut...you have to install it.
    So here is my question...will I have to reinstall Final Cut and all my other programs from scratch if I continue with this process? It is already on the 160GB drive in the same machine. Seems like a huge inconvenience. Is there another way??
    Thanks in advance
    FatherTime
    DP 2.0 G5 1GB RAM, iBook   Mac OS X (10.4.7)  

    I used Carbon Copy Cloner to clone my existing system drive onto the Raptor. That way, I didn't have to reinstall a single thing or have to reset any application preferences.
    I had to pare down the size of my existing drive (which was a 500 GB model) so that I could clone to the Raptor. I got it down to about 70GB by moving items to another external drive and then did the clone.
    So, my setup has the OS, Applications, and (most of) my user folder on the Raptor. I moved DVD Studio Pro's templates, GarageBand's and Soundtrack Pro's audio library, and LiveType's various items to the 500 GB drive. I also moved my iTunes library and my iPhoto library to the 500 GB drive. All of this allowed me to keep sufficient free space on the Raptor.
    If you don't want to clone your hard drive to the Raptor, you could try dragging Final Cut Pro over. However, you'd also need to drag over the items in /Library/Application Support/Final Cut Pro System Support as well as the items in ~/Library/Preferences/Final Cut Pro User Data. And, there's still no guarantee that it'll work properly.
    If you need to move other (non-Apple) applications to your other drive, you'll probably be OK in doing that. It's really only the Apple applications that need to remain in the /Applications folder.

  • Non US characters in login and email generation

    I have a design problem that I would like to check if anyone else has found a good solution to.
    Once you leave the safe shores of the United States your users start having names that includes all kinds of funny characters. In the good old days this problem was resolved by the fact that the HR system only handled 7 bit US ascii characters but today you are likely to have to face an HR system that supports unicode or at least some kind of character set that includes lots of non US ascii characters. I just ran some stats on my current enterprise population and it seems like about 5% of the users have names containing "strangeness".
    These strange characters causes big problems if you aren't allowed to include non US ascii characters in logins, email addresses and other generated fields. Exactly what a "strange character" is varies. RFC 5322 takes a quite liberal view towards special characters but explicitly disallows non US letters.
    The simplistic solution is to drop any character that isn't a US ascii letter. This works if the problem is names like "O'Malley" as the "'" really shouldn't be part of the user login and probably not part of an email address either(can be debated). This solution breaks down when you get to Germany or Scandinavia where your users that are called "Örjan Åhs" may not appreciate an email address of rjan.hs@your_company.com.
    What you would like to do is to convert "Örjan Åhs" to either "Orjan Ahs" or (possible) "Oerjan Aohs" but I haven't been able to find any java lab that does that conversion for you.
    Anyone that has run into this problem before and solved it?
    I wonder how certain characters in this post will be rendered on computers in different parts of the world :)
    /Martin, who long ago converted his last name (Swedish) to be 7 bit ascii compliant

    Thanks Daniel
    The code above drops any non US ascii characters which is fine in some situations but doesn't work for me as that would result in (amongst other issues) unacceptable email addresses.
    Example: The user "Jörgen Åhs" gets the email [email protected] (using drop strategy), what is needed is [email protected]
    The solution to this problem is to write a transform function and as we have about 80 non US ascii characters in character set we are using this mapping can quite easily be externalized to a configuration file.
    Good point about the preferred name. I have not seen this specific problem in my current system but it is very common in certain parts of the world i.e. people with Chinese heritage in south east Asia often have a Chinese legal name and a western name that they actually use in day to day interactions. If you base the email address of their name in HR much screaming ensures. The same thing should actually happen in the US as you are supposed to enter the name on your social security card into the HR system but that seems largely to be ignored.

  • Apps auto-launch on startup, despite System Prefs and quitting before shutdown.

    All apps that were open before shutdown are relaunching themselves upon startup.
    This behavior occurs even if I quit each application individually before initiating system shutdown.
    This behavior occurs whether I tick or untick the following settings within System Preferences / General:
    • Ask to keep changes when closing documents.
    • Close windows when quitting an application.
    This behavior occurs despite none of the apps being listed within System Prefs / Login Items.
    Examples of auto-launching apps (behavior occured just now with these): TextEdit, Dictionary, Calendar, Contacts, Safari, Firefox, Excel, Acrobat.
    I am the administrator and only user on this machine.
    Early 2011 MacBook Pro 13"
    Mac OS X 8.5
    Build 12F45
    2.7 GHz Intel
    8GB RAM

    Back up all data.
    This procedure will unlock all your user files (not system files) and reset their ownership and access-control lists to the default. If you've set special values for those attributes on any of your files, they will be reverted. In that case, either stop here, or be prepared to recreate the settings if necessary. Do so only after verifying that those settings didn't cause the problem. If none of this is meaningful to you, you don't need to worry about it.
    I've tested these instructions only with the Safari web browser. If you use another browser, they may not work as described.
    Step 1
    If you have more than one user account, and the one in question is not an administrator account, then temporarily promote it to administrator status in the Users & Groups preference pane. To do that, unlock the preference pane using the credentials of an administrator, check the box markedAllow user to administer this computer, then reboot. You can demote the problem account back to standard status when this step has been completed.
    Triple-click anywhere in the following line on this page to select it:
    { sudo chflags -R nouchg,nouappnd ~ $TMPDIR.. ; sudo chown -R $UID:staff ~ $_ ; sudo chmod -R u+rwX ~ $_ ; chmod -R -N ~ $_ ; } 2> /dev/null
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    Launch the Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste into the Terminal window (command-V). I've tested these instructions only with the Safari web browser. If you use  another browser, you may have to press the return key after pasting.
    You'll be prompted for your login password. Nothing will be displayed when you type it. You may get a one-time warning to be careful. If you don’t have a login password, you’ll need to set one before you can run the command. If you see a message that your username "is not in the sudoers file," then you're not logged in as an administrator.
    The command may take a few minutes to run, or perhaps longer if you have literally millions of files in your home folder. Wait for a new line ending in a dollar sign (“$”) to appear, then quit Terminal.
    Step 2 (optional)
    Take this step only if you have trouble with Step 1 or if it doesn't solve the problem.
    Boot into Recovery. When the OS X Utilities screen appears, select
    Utilities ▹ Terminal
    from the menu bar. A Terminal window will open.
    In the Terminal window, type this:
    res
    Press the tab key. The partial command you typed will automatically be completed to this:
    resetpassword
    Press return. A Reset Password window will open. You’re not going to reset a password.
    Select your boot volume ("Macintosh HD," unless you gave it a different name) if not already selected.
    Select your username from the menu labeled Select the user account if not already selected.
    Under Reset Home Directory Permissions and ACLs, click the Reset button.
    Select
     ▹ Restart
    from the menu bar.

  • Shared logins and performance

    I am upgrading MS Access applications to SQL Server 2012 back ends. We're currently approaching SS access with a single login shared by multiple users, but less than 24, for the same application. I'm having trouble finding documentation regarding
    what performance effects (if any) we will have from SQL Server using this single ID approach. Does anyone have some information regarding this?

    Hi SteveChicago,
    Based on my understanding, you want to know if it can cause a performance issue when sharing a single login with multiple users.
    As Sean mentioned, share a single login with multiple users could cause a security issue rather than a performance issue.
    A login is a security principal, or an entity that can be authenticated by a secure system. Users need a login to connect to SQL Server. As a security principal, permissions can be granted to logins. The scope of a login is the whole Database Engine. So
    I recommend you to create different logins for multiple users, and grant them property permission to access different database. To make sure every has his own login with different permission, it’s better for us to manage databases. About how to create a login
    and map the login to a database user, please refer to this article:
    http://msdn.microsoft.com/en-us/library/aa337562.aspx.
    Best regards,
    Qiuyun Yu

  • Error when login and authorizing my new computor

    error when login and authorizing my new computor

    Zachy,
    It goes something like this...
    Put your new drive in the enclosure. Use Disk Utility to format it, etc. I'd give it a slightly different name than the original. Let's say you have Old Disk and New Disk as your drive names. Use Carbon Copy Cloner to copy Old Disk to New Disk. Now you should have an exact copy, which you can test by rebooting and holding down the Option key. Choose New Disk from the list and let it boot, make sure all is well.
    Shut down and physically swap the drives. Take Old Disk and put it in the enclosure. Now your system has a new disk with a lot more space and you can reformat your old disk and just use it for large files or whatever.

Maybe you are looking for

  • How can I modify / update T002C's only one field

    Hi everyone ; I would like to write dialog programing code. After I am writing call screen screennumber, I would like to generate a design in screen painter.But screen painter doesn't open. There is an error. Error says ' EU_SCRP_WN32 : timeout durin

  • Rman Detect Block Corruption

    Hi I know rman detect block corruption but my question is block corruption having two types one is physical block corruption and other is logical block corruption by default rman enable physical block corruption but by default rman not able to detect

  • 3G access fix

    I got my iPhone today and everything worked fine except some issues with the iTunes/App Store download sync and more importantly it only worked on WiFi and no Edge or 3G! After reading a post here I did a full restore that took about 30 mins and it w

  • V Cast Apps Error Message "Unable to complete request" after updating software

    Purchased the Samsung Droid Charge last week. I really like the phone, but I'm running into an error message.  When I click on the V Cast Apps icon, I'm directed to install an update, otherwise I can't use the software. So I click to update, the down

  • Recording in iMovie with external microphone?

    Is there a way to capture video in iMovie using the iSight and an external microphone? If so, how do I set that up? If not, what program records the best quality videos but also has this external mic option?