Open our portal to outside world

Hi,
We Installed SAP HCM and also SAP EP systems .  Currently all the users are connecting using Http: and not https:(Secure)
In order to setup https  and We are planning to open our portal to outside world.
I have few questions . Your answers are greatly appreciated.
1. In order to setup https connectivity do we need SSL
2. In order to use SSL do we need a web dispatcher. If Yes, is this something which SAP is recommending or it is must to use SAP Web dispatcher inroder to enable SSL in SAP.
Thanks
Pradeep.G

Hi,
>
> 1. In order to setup https connectivity do we need SSL
>
Yes, you need SSL for that.
> 2. In order to use SSL do we need a web dispatcher. If Yes, is this something which SAP is recommending or it is must to use >SAP Web dispatcher inroder to enable SSL in SAP.
>
Its not mandatory to use web dispatcher for SSL. But i will recommend you to use web dispatcher so that you should not expose your actual system IP and host to outer world and at same time security will be enhanced.
Thanks
Sunny

Similar Messages

  • How to expose a web service to the outside world?

    Hello,
    i have created a Web service from a Session bean and successfully published it on one of my UDDI registries using the Admin tool.
    At this point, what do I need to do further in order to expose this Web service not just in our LAN but to the outside world?
    Roy

    Offcourse it should be published at UDDI.
    Four play  key roles in Web services: Universal Description, Discovery and Integration (UDDI), Web Services Description Language (WSDL), Web Services Inspection Language (WSIL), SOAP, and Web Services Interoperability (WS-I).
    The UDDI specification defines open, platform-independent standards that enable businesses to share information in a global business registry, discover services on the registry, and define how they interact over the Internet.
    See this link too:
    http://help.eclipse.org/help32/index.jsp?topic=/org.eclipse.jst.ws.consumption.ui.doc.user/concepts/cwsdlud.html
    Regards, Suresh KB

  • Words documents opened from portal display website instead of document

    A user is opening Word documents from a newly-created section of our portal to find that the Word document displays the website instead of the text that is supposed to be in the document. Saving the document first and then opening it works fine.
    It seems similar to this issue:
    WWC-41400 when accessing PowerPoint docs
    with the following key differences:
    1. It doesn't actually display an error. The screen that appears in the Word document looks somewhat like our login screen, but without the login text.
    2. This problem only started happening after we redid a section of our website. The new section contains the same documents, but it was rebuilt on the top level of our navigation rather than where it was before.
    3. The user only has this problem with the new section of the website--not the previous implementation of that section and not with the rest of the portal website. It only seems to be the new section we developed.
    It doesn't seem like she needs to upgrade Word, as Powerpoint was upgraded in the referenced URL above, because it's working elsewhere in the portal. Are there any issues related to us developing the new section of the website that would cause this? Thank you for any assistance.

    If Adobe documents are automatically saved instead of opened, check the Applications panel in Firefox ("Tools -> Options -> Applications") and change the action for PDF documents to either "Use Adobe Reader" if you want to use the application or "Use Adobe Acrobat (in Firefox" if you want the PDF file to open inside a Firefox browser window via the Adobe Acrobat plugin. If you want to be asked what to do with PDF files each time, select "Always Ask" for the action. See* [[Managing file types]] and [[Opening PDF files within Firefox]].
    See also [http://kb.mozillazine.org/File_types_and_download_actions]

  • Make VM accessible to the outside world (iptables question)

    I have a VM running on one of our internal servers on top of Oracle Enterprise Linux 4.x with VMware Server 3.x
    Inside the VM runs a Oracle Database and a WebLogic Server, and I need to access the Weblogic administrative interface and the applications running on it from another computer part of Oracle Internal Network.
    If I start the VM with its network interface in "bridged" mode, then the VM doesn't get any IP by DHCP. If I try to manually assign an IP to it, the network doesn't work, most probably because of some security rules enforced by the local SA.
    If I start the VM with its network interface in NAT mode, then the internal applications fail to start with network sockets errors.
    The only way to start the VM and the applications running inside it without errors is the "host network only" mode, but then the applications are not available from any other machine than the one on top this VM runs.
    So I guess that the easiest way to solve this problem would be to create some IPTABLES rules so that all http/https/ssl traffic passing through the physical machine network interface on certain ports to be forwarded to the VM host-only network interface.
    I do not have enough knowledge of IPTABLES rules and I know this is quite a huge subject, so starting to learn it now will take some days which I can not afford right now...
    Is someone with more knowledge on the subject able to help me here?
    Thanks and Regards
    Serban

    Can you get in touch with your local SA to see if there are any policy or network security restrictions that apply? DHCP is not a good solution for your situation anyway, and I would not bother to setup firewall with dynamic port forwarding and proxying to bypass networking restrictions. I think, the most, if not the only feasible option, to make your VM talk to the outside world, is to setup your VM in bridged network mode, so that the VM interface can broadcast at the same level as your host interface. Besides, your current external network security may prevent routing any IP address other than the one of your host computer, in which case you will be able to access your VM only from within your host computer, regardless.
    If you cannot work out a static IP address or direct access to your VM from outside, perhaps simple port forwarding may work in your case, which will automatically forward all traffic to a certain port on your host computer to the network of your VM, but then you won't be able to choose.
    Edited by: Dude on Nov 12, 2010 7:14 AM

  • Different Business Cases where SAP needs to be Inegrated with outside world

    Hello Experts,
    Can I get some info, where SAP R/3 needs to be integrated with out side world(Business Flows) that are most commonly used in all industrial sectors.
    Inrgraton either with XI/PI or any other Interation tolls in the market.
    Thanks & Regards,
    Srikanth

    Dear Srikanth,
    Please go through the link:
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/46d6c25d-0b01-0010-06a9-8e8218753c02
    Traditionally, integrating SAP applications with the outside world used to be extremely difficult, due to limited interfacing provided by SAP. EAI vendors like IBM and webMethods addressed this business need, providing SAP adapters as part of their integration offerings. Recently, SAP has also addressed this issue through its SAP Net Weaver/XI offering.
    Please let me know in case of any spcific queries.
    Regards,
    Rakesh

  • Java instance doesn't start in our portal system after db restore

    We just restored the db of our live portal system to our portal qa system.
    Our live portal system is EP 7.0, db version:Oracle 10.2.0.2 and os version: Windows 2003 server 64 bit
    Our QA portal system is EP 7.0, db version:Oracle 10.2.0.2 and os version: Windows 2003 server 32 bit
    We converted the 64 bit db to 32. DB opened without a problem.
    We also changed the Dispatcher and server ids in configuration files and config tool one by one.
    When we try to open SAP, the java process fails after a few seconds.
    We searched the log files and found the error:
    D:\usr\sap\<SID>\JC00\exe\jlaunch.exe=>sapparam(18): D:\usr\sap<SID>SYS\profile\<SID>_JC00_<hostname>: line 21 starts with illegal byte sequence
    D:\usr\sap\<SID>\JC00\exe\jlaunch.exe=>sapparam(18): D:\usr\sap\<SID>\SYS\profile\<SID>JC00_<hostname>: reading canceld after 101 illegal bytes
    Any suggestions
    Tolga

    Hi Tolga,
       Check whether the SAP SUPER USER (SAP *) is active or not,If it is active just deactivate it bocos if it is active java instance might not start in certain cases
    Regards,
    Tilak..

  • Mailx unable to send mails to outside world?

    hi
    on a solaris sparc 9 environment mailx command is unable to send mails to the outside world. What could be the reason & needs to be checked?
    thanks

    sounds basic, but what's your entry of malhost in /etc/hosts pointing to? If it's not there, add the entry with the IP address of your SMTP host.
    when sending test mail from mailx, have another window open thats tail-ing the contents of /var/log/syslog - that usually contains good info about sendmail.
    another thing worth checking is the rules on your SMTP gateway. If this is a new host, it may need adding to the list of authorised relay list. Also check to see if the SMTP host is alowed to relay mail outside of its own domain too.

  • Security: Portlets visible to the outside world?

    When I deploy portlets to a oc4j instance managed by the applicationserver it seems that the url of the webapplication is automatically visible through the ora http server. Since my webapplications only contain portlets that should be accessed by the portal, how do I prevent the outside world from sending request directly to the webapplication?

    You have used some very general terms in your question but I will attempt to reply with some caveats.
    Generally speaking most remote access VPNs use private addresses which are translated using NAT when traffic leaves the protected (internal) network en route to a public server, such as a web server on the Internet. You address appears to the remote server as one of the addresses from the NAT pool (or sometimes outside interface) of the VPN concentrator or firewall that is performing that function.
    You can always check your address as it appears to the outside by browsing to something like http://whatismyip.com

  • Opening a Portal page from UWL item's click

    Hi,
    I have written a custom UWL connector that connects to 3rd party system to fetch tasks.
    This custom connector has  been registered with UWL and tasks from this 3rd party system are now appearing in my UWL.
    The requirement is to open a Portal page on click of these UWL items.
    That is, when user clicks on this custom UWL item, a Portal page should be opened in new window.
    I tried setting item's executionURL to following (inside getItems() method of connector) : -
    1. https://myportal.com/irj/portal?navigationtarget=roles://portal_content/com.mycompanyPurchaising/com.mycompany.Purchase_Request/com.mycompany.Roles/com.mycompany.purch_pr/com.mycompany.purch_pr/com.mycompany.purchaseRequest
    2. https://myportal.com/irj/portal?navigationtarget=roles://portal_content/com.mycompany.Purchaising/com.mycompany.Purchase_Request/com.mycompany.Roles/com.mycompany.purch_pr/com.mycompany.purch_pr/com.mycompany.purchaseRequest&target="_blank"
    3. Set Quick link property of corresponding page and then set executionURL as: -
    https://myportal.com/irj/portal/purchaserequest
    Issue being faced: -
    When user clicks on this UWL item, it opens following URL which just displays blank portal page: -
    https://myportal.com/irj/servlet/prt/portal/prteventname/navigate/prtroot/pcd!3aportal_content!2fcom.mycompany.layout.PortalLayoutFolder!2fcom.mycompany.layout.DesktopFolder!2fmycompanyDesktop!2fframeworkPages!2fframeworkpage!2fcom.sap.portal.innerpage!2fcom.sap.portal.contentarea?NavigationTarget=ROLES%3A%2F%2Fportal_content%2Fcom.mycompany.Purchaising%2Fcom.mycompany.Purchase_Request%2Fcom.mycompany.iViews%2Fcom.mycompany.purchaseRequest&CurrentWindowId=WID1326775699455&NavMode=1
    Any idea what is going wrong here?
    I am not able to figure out what & from where its preparing above URL instead of opening the URL that I specified in Connector's executionURL attribute.
    Regards,
    Amey

    Issue was with iView that I was trying to open in DEV portal.
    It worked fine in TEST & PROD portals.
    Hence, NavigationTarget=<> approach works fine.

  • Opening an attachment from outside the tomcat context

    I am creating a simple mail software. In my incoming message screen i'm showing all the Attachments as hyperlinks. I want that when the user clicks the hyperlink the Attachment should open in a new browser window.
    My problem is that the attachments are there in a folder outside the tomcat context i.e. in a folder outside the tomcat's folder on the server's c:/Attachments folder.
    If I put the attachments in the root folder of my application under webapps folder it is working properly. But I want to open it from the outside folder c:/Attachments, and also I can't hardcode this path in my code. It can be any path outside tomcat.
    Please help me, if u have any solution.

    Make that path a parameter in web.xml
         <context-param>     
              <param-name>beginyear</param-name>
              <param-value>2004</param-value>          
              <description>starting year of the application</description>
         </context-param>

  • Best Practice on Not Exposing your internal FQDN to the outside world

    Exchange server 2010, sits in DMZ, internet facing. The server is currently using the Default Receive Connector. This exposes the internal fqdn to the outside world (ehlo). Since you should not (can't) change the FQDN on your Default Receive connector, what
    is the best practice here?
    The only solution I can see is the following:
    1. Change the Network on the Default Receive Connector to only internal IP addresses.
    2. Create a new Internet Receive Connector port 25 for external IP addresses (not sure what to put in Network tab?) and use my external FQDN for ehlo responses (e.g. mail.domain.com)
    3. What do I pick for Auth and Permissions, TLS and Annoymous only?
    Michael Maxwell

    Yes, it fails PCI testing/compliance. I shouldn't be able to see my internal server and domain. I understand that is the recommendation, but my client doesn't want to host in the cloud or go with a Trend IHMS (trust me I like that better, but its
    not my choice). I have to work with the deck of cards dealt to me. Thanks, just want a solution with what I have now.
    Michael Maxwell
    Understand. I wont go into the value of those tests  :)
    If the customer is really concerned about exposing the internal name, then create a new receive connector with a different FQDN  ( and corresponding cert)  for anonymous connections as you mention above. Know that  it also means internal clients
    can connect to the server on port 25 as well if you dont have the ability to scope to set of ip addresses ( i.e. a SMTP gateway).
    The internal names of the servers will also be in the internet headers of messages sent out:
    http://exchangepedia.com/2008/05/removing-internal-host-names-and-ip-addresses-from-message-headers.html
    http://www.msexchange.org/kbase/ExchangeServerTips/ExchangeServer2007/SecurityMessageHygiene/HowtoremoveinternalservernamesandIPaddressesfromSMTPheaders.html
    Twitter!:
    Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • Opening our program after payment when account is active but the dialog box says free trial has expired

    opening our program after payment when account is active but the dialog box says free trial has expired

    Has it ever been shown as fully licensed on this computer? Or has it just been showing a free trial countdown, which you ignored and it has now run out?

  • E-mail to all of our portal-users

    Hello,
    I'd like to send an e-mail to all of our portal-users to keep them informed
    about our new products.
    I currently do so by using the news-iview "send-to" feature, but every time
    I try to send an email, I get the following error message: resource can't be
    used.
    Should I make any changes in my settings?
    Are there any other possibilities to send an e-mail through the portal to
    all users at once?
    I'd really appreciate your help.
    Regards,
    Mike.

    Hello Mike, Hello Francesco,
    have you set a SMTP Server at: System Administration -> System Configuration -> UM Configuration -> Notification E-Mails ?
    Regards
    Gregor

  • Zip file not open in portal

    Dear all,
    I have encountered a problem while opening a zip file in portal it can't open. Once we click on R/3 side its working fine but the same thing happen in portal its not open if we are pressing CTLR button  than it will open in portal what's the prob .Can anyone give me some highlights on this issue.
    Regards

    Hi,
    Pls check this linK:
    Re: Opening a .zip file from Enterprise portal
    Thanks and Regards,
    Shyam.

  • Computer Not Visible to Outside World

    How do I retain my computer's unique IP address following the addition of an AirPort Extreme base station?
    WIRED SETUP: Telephone line --> DSL modem --> AirPort Extreme --> Ethernet port on back of G5
    My computer has always had a unique IP address. This allows me to connect to my computer when I'm on-the-road traveling, etc. (via Timbuktu or FTP).
    Now that I've set up the AirPort Extreme base station, my base station has been given a unique, static IP but my computer is now dependent on DHCP for it's IP address allocation. As far as I can tell, this renders my computer inaccessible from the outside world.
    How do I configure this so that I'm able to retain the benefits of the AirPort Extreme (using it to broadcast a wireless Internet connection) while ALSO keeping my G5 (see "WIRED SETUP" above) completely accessible to the outside world? Thanks!
    Dual 1.8GHz G5 (rev B)   Mac OS X (10.4.4)  

    Disabling distribute DHCP address won't work for your situation. Since you want to continue to use the wireless connection in addition to the G5 wired computer, you will need to still distribute IP addresses on the AEBS.
    As a solution, SurferLeo v.0, you can set up port forwarding on the base station. In affect, while you're on the road, you would attempt to connect to your public IP address (the one given by your DSL modem; the IP address given to your AEBS). Then, port forwarding would forward that traffic to the specific private IP address specified in the port forwarding settings.
    So, given that your public IP is x.x.x.x and that your G5's IP is 10.0.0.2 (or whatever), you would configure the AEBS to forward port numbers A, B, and C to 10.0.0.2 - where "A, B, and C" are the port numbers for the specific task you are performing.
    This site discusses setting up port forwarding.
    Here's a list of common port numbers.
    Various Macs and PC's   Mac OS X (10.4)  

Maybe you are looking for

  • Did you know about "Arbitration and Mediation" FAQ?

    I have just made a discovery that many of you frustrated Verizon customers will be very interested in knowing about. Did you know that you can type in legal action in the search verizon.com box and you will find a category called "Arbitration & Media

  • Can you post Notes (Display Note) at a higher level of aggregation than CVC

    I am only able to post Notes with the Display Note at the CVC level.  ALL PRODUCTS ALL CUSTOMERS and I receive the error message "No Notes can be processed in the current selection".  ONE PRODUCT ALL CUSTOMERS OR ALL PRODUCTS ONE CUSTOMER and I get d

  • IPhone User Cannot Logon

    I am trying to enable iPhone access to a certain user.  The user has already been granted with Iphone_Access global privilege.  But the user is still not able to login via mobile.  Username and password has been checked multiple times already.  Enabl

  • Query to compare two different periods

    hello, I want to compare two different periods and put together following query and wondering if this is the right way to do it: WITH  MEMBER  [TotalForThePeriod] AS  SUM( {[Date].[Calendar].[Date].&[20070101]:[Date].[Calendar].[Date].&[20070228]}  

  • CS3 crashing in Vista (comdlg32.dll)

    I have a problem with Photoshop CS3 on vista home premium (32bit). Each time I try to save an image (either using the keyboard shortcut or selecting from the edit menu) Photoshop immediately crashes (with no error message). If I close the image I get