SAP Router Installation
Hi,
We are trying to implement <b>SAP Router</b> in our current landscape . Can you please guide me how to configure and install sap router.I knew that we can download saprouter_12-10003208.SAR file from market place. What are other files need to download .
After download how to install , please suggest.
- Cheers
HI
GOOD
GO THROUGH THE FOLLOWING LINKS,WHICH WILL GIVE YOU IDEA TO SOLVE YOUR PROBLEM.
http://help.sap.com/saphelp_nw04/helpdata/en/4f/992dab446d11d189700000e8322d00/content.htm
http://help.sap.com/saphelp_nw04/helpdata/en/4f/992d91446d11d189700000e8322d00/content.htm
http://www.easymarketplace.de/saprouter.php
THANKS
MRUTYUN
Similar Messages
-
SAP router installation for VPN method
Hi All,
Can any one share me the steps to perform SAP Router Configuration with VPN method.
Also what are changes i need to make in saproutab file.
Appreciate your inputs.
Thanks
Pradeep.There is paperwork that you need to fill out with IPSec information, once its filled out you fax it over to SAP.
Not entirely sure what changes need to be made in saprouttab? Are you changing SAPRouter to no longer perform SNC to SAP?
Here is the doco I used for my company - https://support.sap.com/content/dam/library/SAP%20Support%20Portal/remote-support/RemoteSupport.pdf -
Error while importing SAP Router renew Certificate
Hi Gurus,
My sap router certificate got expired and got mail from SAP to renew, so I decided to renew it and followed link http://wiki.sdn.sap.com/wiki/display/Basis/HowtorenewtheSAPRouterlicense to renew saprouter certificate. All the steps were executed fine But I got below error while importing certificate from srcert file.
C:\saprouter>sapgenpse import_own_cert -c srcert -p local.pse
Please enter PIN:
import_own_cert: Installation of certificate failed
ERROR in ssf_install_CA_response: (1280/0x0500) No certficate with your
public key found
Please advise me to solve this issue.
Thanks,
VenkatHi Deepak,
thanks for your reply.
yes i have entered correct Pin and in the first step i have moved local.pse and cred_v2, certreq, srcert files to C:/saprouter/backup folder
After executing import command it has given error first time so i copied local.pse file to C:\saprouter folder and executed but same error result.
please help me to solve it.
Thanks,
Venkat -
Error in importing SAP Router Certificate
Hello,
I am trying to import my SAP Router certificate with the following command
sapgenpse import_own_cert -c srcert -p local.pse
But I get the following reply
import_own_cert: Installation of certificate failed
ERROR in ssf_install_CA_response: (1280/0x0500) No certficate with your public key found
I have placed the srcert file in c:\usr\sap\saprouter\ntintel
any suggestions?Dear Vishnu,
Thanks for your time and inputs
I tried the procedure few times. Its just not working..... somethings really strange here
I went through the link you provided but that does not help either
Now I am getting a new error as pasted below
C:\usr\sap\saprouter\ntintel>sapgenpse import_own_cert -p local.pse -c srcert
Please enter PIN:
import_own_cert: Installation of certificate failed
ERROR in ssf_install_CA_response: (1281/0x0501) aux_file2OctetString failed : "No such file or directory"
ERROR in ssf_read_certs_from_file: (1281/0x0501) aux_file2OctetString failed : "No such file or directory"
ERROR in aux_file2OctetString: (1281/0x0501) stat("srcert") returned : "No such file or directory"
Any suggestions? -
Hi All,
I have installed SAP Router before but this time when I installed and tried to start SAP Router its not getting started, and also not giving any error log file in SAP Router directory.
Please check the below command and correct me if I am wrong.
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\sap_admin>cd \
C:\>cd SAPRTR
C:\SAPRTR>saprouter -r -S 3299 -K "p:CN=<MyRouterHOSTNAME>, OU=<Cust_NUM>, OU=SAProuter,
O=SAP, C=DE"
SAP Network Interface Router, Version 38.10
Compiled Oct 7 2009 03:08:09
start router : saprouter -r
stop router : saprouter -s
soft shutdown: saprouter -p
router info : saprouter -l (-L)
new routtab : saprouter -n
toggle trace : saprouter -t
cancel route : saprouter -c id
dump buffers : saprouter -d
flush " : saprouter -f
hide errInfo : saprouter -z
start router with third-party library: saprouter -a library
additional options
-R routtab : name of route-permission-file (default ./saprouttab)
-G logfile : name of log file (default no logging)
-T tracefile : name of trace file (default dev_rout)
-V tracelev : trace level to run with (default 1)
-H hostname : of running SAProuter (default localhost)
-S service : service-name / number (default 3299)
-P infopass : password for info requests
-C clients : maximum no of clients (default 800)
-Y servers : maximum no of servers to start (default 1)
-K [myname] : activate SNC; if given, use 'myname' as own sec-id
-A initstring: initialization options for third-party library
-D : switch DNS reverse lookup off
-E : append log- and trace-files to existing
-J filesize : maximum log file size in byte (default off)
-6 : IPv6 enabled
-Z : hide connect error information for clients
expert options
-B quelength : max. no. of queued packets per client (default 1)
-Q queuesize : max. total size for all queues (default 20000000 bytes)
-W waittime : timeout for blocking net-calls (default 5000 millisec)
-M min.max : portrange for outgoing connects, like -M 1.1023
-I address : address for outgoing connects, like -I 155.56.76.6
this is a sample routtab : -----------------------------------------
D host1 host2 serviceX
D host3
P * * serviceX
P 155.56.. 155.56
P 155.57.1011xxxx.*
P host4 host5 * xxx
P host6 localhost 3299
P host7 host8 telnet
S host9
P0,* host10
KP sncname1 * *
KS * host11 *
KD "sncname "abc" * *
KT sncname3 host11 *
deny routes from host1 to host2 serviceX
deny all routes from host3
permit routes from anywhere to any host using serviceX
permit all routes from/to addresses matching 155.56
permit ... with 3rd byte matching 1011xxxx
permit routes from host4 to host5 if password xxx supplied
permit information requests from host6
permit native-protocol-routes to non-SAP-server telnet
permit ... excluding native-protocol-routes (SAP-servers only)
permit ... if number of preceding/succeeding hops (SAProuters) <= 0/*
permit SNC-connection with partnerid = 'sncname1' to any host
permit all SAP-SAP SNC-connections to host11
deny all SNC-connections with partnerid = 'sncname "abc'
open connects to host11 with SNC enabled and partnerid = 'sncname3'
first match [host/sncname host service] is used
permission is denied if no entry matches
service wildcard (*) does not apply to native-protocol-routes
C:\SAPRTR>
Rg
RameshHello my friend
It could be certificate didn't import properly or routtab content is not correct. Here's your checklist:
Creating the certificate request
1) As user <snc_adm> set the environment variables SNC_LIB and SECUDIR
2) Change to the alias SAPROUTER-SNCADD. From the list of SAProuters registered to your installation, choose the relevant u201CDistinguished Nameu201D.
3) Generate the certificate Request with the command:
sapgenpse get_pse -v -r certreq -p local.pse u201C<Distinguished Name>u201D
You will be asked twice for a PIN here. Please choose a PIN and document it, you have to enter it identically both times. Then you will have to enter the same PIN every time you want to use this PSE.
4) Display the output file "certreq" and with copy&paste (including the BEGIN and END statement) insert the certificate request into the text area of the same form on the SAP Service Marketplace from which you copied the Distinguished Name.
5) In response you will receive the certificate signed by the CA in the Service Marketplace. Copy&paste the text to a new local file named "srcert", which must be created in the same directory as the sapgenpse executable.
6) With this in turn you can install the certificate in your saprouter by calling:
sapgenpse import_own_cert -c srcert -p local.pse
7) Now you will have to create the credentials for the SAProuter with the same program (if you omit -O <user_for_saprouter>, the credentials are created for the logged in user account).
sapgenpse seclogin -p local.pse -O <user_for _saprouter>
Note: The account of the service user should always be entered in full <domainname>\<username>
8) This will create a file called "cred_v2" in the same directory as "local.pse"
9) Check if the certificate has been imported successfully with the following command:
sapgenpse get_my_name -v -n Issuer
The name of the Issuer should be:
CN=SAProuter CA, OU=SAProuter, O=SAP, C=DE
10) If this is not the case, delete the files "cred_v2"and "local.pse" and start over at Item 3.
Additional actions necessary before you can start SAProuter
1. Check if the environment of the user running SAProuter contains the environment variable SNC_LIB and SECUDIR
2. Start the SAProuter with the following command line (to start the SAProuter as a Windows service, please follow the steps described in SAP note 525751):
saprouter -r -S <port> -K "p:<Distingushed Name>"
-K tells the saprouter to start with loading the SNC library
3. The corresponding file "saprouttab" should look like:
SNC-connection from and to SAP
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 194.39.131.34 *
SNC-connection from SAP to local R/3-System for Support
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" * *
SNC-connection from SAP to telnet in your network
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" * 23
Access from the local Network to SAPNet - R/3 Frontend (OSS)
P * 194.39.131.34 3299
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <your IP> <port>
Regards,
Effan
DON'T KNOW WHY THE FORMAT MESSED UP, PLEASE USE QUOTE ORIGINAL IN REPLY MODE TO READ THE CORRECT FORMAT CONTENT. SORRY! -
How to install and configure SAP Router
Dear SAP Expert !
I want to install SAP Router but i dont know the SAP router package is allocated on DVD ? what is the DVD number ?
If you already configure SAP router please let me know how to configure ?Hello Thao
what is th exact issue that are u facing.
The account must be the administartor of the machine where u are installing SAPROUTER.Make sure you are following the correct steps as follows:
Downloading necessary software components from SAP Service Marketplace
1. Login to the SAP Service Marketplace with the Service Marketplace at using
the USERID/PASSWORD which was assigned for your installation.
2. Change the alias to www.service.sap.com/tcs to downloaded the SAP
cryptographic software. Select the correct SAPcrptographic software
depending on your saprouter operating system as shown below.
3. You must have the sapcar.exe in order to extract the SAP cryptographic
software file.
4. With the command of u201Csapcar -xvf xxxxxxx.saru201D, /ntintel directory would be
created and the following files would be extracted.
(Example C:/saprouter/ntintel)
( when the Microsoft Windows NT Intel version is downloaded)
C:/saprouter/ntintel/sapcrypto.dll
C:/saprouter/ntintel/sapgenpse.exe
C:/saprouter/ticket
Issue of Electronic Certificate
5. It is necessary to define the environment variable for u201CSECUDIRu201D and
u201CSNC_LIBu201D under system account.
Window NT environment variable setup :
Right-clicked the icon of you computer
Property -> details -> environment variable
SECUDIR = < Directory name >
Example. Variable name : SECUDIR
Variable value
: C:/saprouter/SNC_LIB = < Directory name >
Example. Variable name : SNC_LIB
Variable value : C:/saprouter/ntintel/sapcrypto.dll
UNIX
<path_to_libsecude>/<name_of_sapcrypto_library>
Windows
NT,
<drive>:/<path_to_libsecude>/<name_of_sapcrypto_library>
Windows
2000
6. Check if the environment of the user running saprouter contains the
environment variable SNC_LIB.
UNIX
Printenv
Windows NT
System environment Variable
7. You may now apply for a SAProuter certificate from the SAP Trust Center
Service of SAP service marketplace
http://service.sap.com/tcs
> SAP Trust Center Service in Detail
> SAProuter Certificates
SAProuter Certificate "Apply Now"
Click the button.
8. Please take note of your "Distinguished Name"
Please refer to the example above
-SAPRouter Name
: JPL50020586
-Distinguished Name
CN=JPL50020586, OU=0000036946, OU=SAProuter, O=SAP, C=DE
Then, clicked the "Continue" button.
9. Execute the following command in the /saprouter/ntintel
directory in order to generate your certificate to be exchanged with SAP.
sapgenpse get_pse -v -r certreq -p local.pse "Distinguished Name"
Example
sapgenpse get_pse u2013v -r certreq -p local.pse "CN=JPL50020586, OU=0000036946,
OU=SAProuter, O=SAP, C=DE"
Enter the PIN number. (you may enter any PIN Number you wish.)
Please enter PIN :
Please re-enter PIN :
<- you must use the same PIN Number as the above.
10. The "certreq" file is created in the /saprouter/ntintel directory.
11. Use a notepad to open the "certreq" file and copy the displayed information
(From the -BEGIN .to the END -)
12.You now have to paste the above copy content into the space provided
shown below. After you have pasted the text, click the u201CRequest certificateu201D
button to submit your request.
13. Once you click on the u201CRequest Certificateu201D a new screen will be displaying
your certificate issued by SAP CA (Certification Authority).
14. Using a notepad to copy the content (From u2013Beingu2026 to -END) and save it
as u201Csrcertu201D into /saprouter/ntintel/srcert.
Note :
- Please rename srcert.txt into srcert without any extension.
15. You then need to import this certificate into SAProuter using the following
command.
Please run on /saprouter/ntintel directory.
sapgenpse import_own_cert -c srcert -p local.pse
Please enter PIN : (same as point 9)
16. Execute the following command in the /saprouter/ntintel directory.
sapgenpse seclogin -p local.pse
Please enter PIN : (same as point 9)
This will create a file "cred_v2" in the same directory.
17. Please check whether the certificate has been imported correctly.
Execute this command in /saprouter/ntintel directory.
sapgenpse get_my_name -v -n Issuer
The result should be "CN=SAProuter CA, OU=SAProuter, O=SAP, C=DE".
18. When the above results are not obtained , please delete local.pse and
cred_v2 and work again from steps 9. Please seek the assistance from your
local SAP helpdesk or create an OSS message via component XX-SER-NET-
OSS, if you are not able to obtain the above-mentioned result after you have
repeated the above steps.
Route permission table (saprouttab)
19. The corresponding file ./saprouttab should contain at least the following
entries.
Example : by SNC connection, when connecting to sapserv2
(194.39.131.34) the following entries need to be indicated by saprouttab.,
SNC-connection to SAP
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 194.39.131.34
SNC-connection from SAP to local R/3-System for Support
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> <R/3-Instance>
SNC-connection from SAP to local R/3-System for pcANYWHERE, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 5631
SNC-connection from SAP to local R/3-System for NetMeeting, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 1503
SNC-connection from SAP to local R/3-System for saptelnet, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 23
Access from the local Network to SAPNet - R/3 Frontend (OSS)
P <IP-addess of a local PC> 194.39.131.34 3299
deny all other connections
D * * *
Start the SAProuter with the following command.
Saprouter -r -S <port> -K
"p: <Your Distingiushed Name>"
-K tells the saprouter to start with loading the SNC library.
Example: saprouter -r -S 3299 u2013K "p:CN=JPL50020586, OU=0000036946,
OU=SAProuter, O=SAP, C=DE"
Additional Note
-You may refer to SAP note: 30289 in the SAP service marketplace for detail
information with regards to SAProuter
http://www.service.sap.com/note -
Pre requisites for installing SAP Router
Hi Friends,
As i am going through the implementation phase, I have to install sap router which i am new at. Also i am doing it because i have to connect Maintenance Optimizer to Sap service Market place for which Router would be essentially required.
I have some questions to put forth.
1. what are the pre requisites for SAP Router
2. Do we require Public IP and what would be the use of this ip
3. how to configure the SAP Router
4. Can i install the SAP router on the same host on which we have Solution manager, is it advisable. or we should go for a seperate host.
Regards
AayushInstalling the sapcrypto library and starting the SAProuter
Contents
u2022 Downloading necessary software components from SAP Service Marketplace
u2022 Creating the certificate request
u2022 Additional actions necessary before you can start saprouter
This section describes the necessary steps to download and install the sapcrypto library for use with saprouter. The saprouter must be started with the options described later in this section.
The license for the sapcrypto library covers saprouter connections between saprouters at SAP and the first saprouter on customer sites and backend connections within the customer`s network. For all other purposes the library CANNOT be used!
Downloading necessary software components from SAP Service Marketplace
1. Login to the SAP Service Marketplace with the Service Marketplace USERID which is assigned to your installation.
2. Change to the alias SAPROUTER-SNCADD. Before you can download the software components two preconditions must be met.
a. You must have been allowed to download the software. This authorization is added as soon as SAP has received a positive statement from the "Bundesausfuhramt". This procedure is necessary since the software falls under EU regulations.
b. For more information on how to obtain authorization if download is not possible see note 397175.
c. You must accept that you must follow the regulations imposed by the EU on the use and distribution of the cryptographic software components downloaded from the SAP Service Marketplace.
3. The acceptance of the terms and conditions is logged with your USERID and stored for reporting purposes to the "Bundesausfuhramt".
4. Accepting with the button on the web-based form takes you to the folder where you can download the Software components.
These are packed into a single CAR file sapcrypto.car
5. Copy the file to the direcory where the saprouter executable is located
6. You can get the file car.exe/sapcar.exe, which is necessary to unpack the archive from any Installation Kernel CD.
Executing the command car -xvf SAPCRYPTO.CAR will unpack the following files:
[lib]sapcrypto.[dll|so|sl]
sapgenpse[.exe]
ticket
Creating the certificate request
1. As user <snc>adm set the environment variables
SECUDIR = <directory_of_saprouter>
2. Change to the Shortlink SAPROUTER-SNCADD. From the list of SAProuters registered to your installation, choose the relevant "Distinguished Name"
3. Generate the certificate Request with the command
sapgenpse get_pse -v -r certreq -p local.pse "<Your Distinguished Name>"
4. Alternatively use the two commands:
sapgenpse get_pse -v -noreq -p local.pse "<Your Distinguished Name>"
sapgenpse get_pse -v -onlyreq -r certreq -p local.pse
5. Display the output file "certreq" and with copy&paste insert the certificate request into the text area of the same form on the SAP Service Marketplace from which you copied the Distinguished Name
6. In response you will receive the certificate signed by the CA in the Service Marketplace, cut&paste the text to a local file named srcert
7. With this in turn you can install the certificate in your saprouter by calling
sapgenpse import_own_cert -c srcert -p local.pse
8. now you will have to create the credentials for the SAProuter with the same program (if you omit -O <user>, the credentials are created for the logged in user account)
sapgenpse seclogin -p local.pse -O <user_for _saprouter>
9. This will create a file called cred_v2 in the same directory.
For increased security please check that the file can only be accessed by the user running the SAProuter.
Do not allow any other access (not even from the same group)!
On UNIX this will mean permissions being set to 600 or even 400!
On NT check that the permissions are granted only to the user the service is running as!
1. Check if the certificate has been imported correctly
sapgenpse get_my_name -v -n Issuer
The name of the Issuer should be: CN=SAProuter CA, OU=SAProuter, O=SAP, C=DE
2. If this is not the case, delete the files cred_v2, local.pse and start over at Item 4. If the output still does not match please open a customer message in component XX-SER-NET-OSS stating the actions you have taken so far and the output of the commands
4.,7.,8. and 10.
Additional actions necessary before you can start saprouter
1. The environment variable SNC_LIB needs to be set for the user account SAProuter is running under.
SNC_LIB has the form
UNIX <path_to_libsecude>/<name_of_sapcrypto_library>
Windows NT, Windows 2000 <drive>:\<path_to_libsecude>\<name_of_sapcrypto_library>
2. Check if the environment of the user running saprouter contains the environment variable SNC_LIB
UNIX printenv
Windows NT System environment variable
3. start the saprouter with the following command line:
saprouter -r -S <port> -K "p:<Your Distingushed Name>"
-K tells the saprouter to start with loading the SNC library
the corresponding file ./saprouttab should contain at least the following entries
inbound connections MUST use SNC
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <your_server1> <port_number>
repeat this for the servers and port_numbers you will need to allow,
please make sure that all explicit ports are inserted in front of a
generic entry '*' for port_number
outbound connections to <sapservX> will use SNC
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <sapservX> <sapservX_inbound_port>
permission entries to check if connection is allowed at all
P <IP address of a local host> <IP address of sapserv2>
all other connections will be denied
D * * *
Example
For a SNC encrypted connection to the SAPRouter on sapserv2 (194.39.131.34), the saprouttab should contain the following entries:
SNC-connection from and to SAP
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 194.39.131.34 *
SNC-connection from SAP to local R/3-System for Support
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> <R/3-Instance>
SNC-connection from SAP to local R/3-System for NetMeeting, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 1503
SNC-connection from SAP to local R/3-System for saptelnet, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 23
Access from the local Network to SAPNet - R/3 Frontend (OSS)
P <IP-addess of a local PC> 194.39.131.34 3299
deny all other connections
D * * *
Lalit Kumar -
Hi,
We are configured new installation of SAP Router. Router side it's working fine.
We are not able to connect OSS1. It's given error was "Service ? unknown".
Out saprouttab like
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 194.39.131.34 *
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 172.17.3.9 3200
P 172.17.3.25 194.39.131.34 3299
dev_rout showing this error.
***LOG Q0I=> NiPGetServByName: service 'sapdp99' not found: getservbyname [ninti.c 463]
Please check it and suggest me.
Regards
S.PrasadHello,
I already solve my problem. I had an error when I tried to log on at transaction OSS1 after I setup the saprouter configuration. It showed a window with the error "Unable to connect to SAPNet message server" and after service 'sapdb99' unknown".
The solution for this was put this entry sapdp99 3299/tcp in services file located in C:WINDOWSsystem32driversetc (on Window) on sap router server!!
After doing a restart the to service (services.msc) of SAP Router the problem has been overcome.
King regards,
João Dimas - Portugal -
Reg : SAP Router Configuration
Dear Friends,
How to configure the SAP router? If anybody have configuration details pls help me.
Our System is ECC 6.0
OS - 2003 Server
DB : MS SQL Server
Then How to Communicate to SAP.
Regards
kesavHi,
> How to configure the SAP router? If anybody have configuration details pls help me.
1) Download the latest SAP Router files (saprouter.car, nipping, cryptographic library) from SAP Service Market Place --- Patches.
2)Create a user called sncadm as a member of Administrator. Log off administrator and login as sncadm. Create the following environment variables for this user.
SECUDIR = c:\usr\sap\saprouter
SNC_LIB = c:\usr\sap\saprouter\sapcrypto.dll
3) Create folder c:\usr\sap\saprouter and copy the downloaded files into that folder. Extract all the compressed files. Now typically this folder will have the following files.
Sapcrypto.dll
Sapgenpse.exe
Ticket
Ntscmgr.exe
Nipping.exe
Saprouter.exe
(other required files can be copied from kernel directory of other SAP Systems)
4) Go to http://service.sap.com/saprouter-sncadd. Click on u201CApply Nowu201D
You will get information like this (on first screen):
Click on Continue. Now we have to create the request for SAProuter which is to be given as input in the next screen u201CRequest Certificate for SAProuteru201D.
5)Open a command prompt and execute the following commands.
Cd \usr\sap\saprouter
sapgenpse get_pse u2013r sap-router.p10 u2013p sap-router.pse u201CCN=SAP-ROUTER, OU=0000733879, OU=SAProuter, O=SAP, C=DEu201D
You will be asked for a PIN: input any (but do not forget!!!!!) No Password is given in this installation.
This command will create the file sap-router.p10 and sap-router.pse.
Open the file sap-router.p10 with notepad, copy & paste this certificate request to the text area of the u201CRequest Certificate for SAProuteru201D page.
Click on Request Certificate
In response you will get certificate signed by CA.
Copy & paste the text into a text file including the header & footer (saprt.txt is the file created here)
6)Now install the certificate as follows
Sapgenpse import_own_cert u2013c saprt.txt u2013p sap-router.pse
7)Now create credentials for saprouter
Sapgenpse seclogin u2013p sap-router.pse u2013O sncadm
This will create a file called cred_v2 in c:\usr\sap\saprouter
8)Now Check whether certificate has been imported correctly or not
Sapgenpse get_my_name u2013v u2013n Issuer
The name of issuer should be: CN=SAProuter CA, OU=SAProuter, O=SAP, C=DE. If the name is not correct, then delete the file cred_v2 and start all over again from Step u2013 4.
9)Now create a file u201Csaprouttabu201D in the folder c:\usr\sap\saprouter and make the following entries in that.
SNC connection to SAP
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 194.39.131.34 *
Access from your local Network to SAPNet - R/3 Frontend
P 172.16.. 194.39.131.34 3299
P 172.17.. 194.39.131.34 3299
P 172.18.. 194.39.131.34 3299
P 172.19.. 194.39.131.34 3299
D * * *
Save the file and close
10) Make the following changes in the hosts file and services file (under windows\system32\drivers\etc folder ) SAP-ROUTER system
hosts file:
172.18.9.8 SAP-ROUTER
194.39.131.34 sapserv2
services file:
sapdp99 3299/tcp
sapgw99 3399/tcp
sapmsO01 3601/tcp
11) Now check the entry in the services files for all servers and all front-end PCs under %winnt%/system32/drivers/etc/ there should have:
sapdp99 3299/tcp
sapmsO01 3601/tcp
12) Now start the sap router using the command (from the saprouter directory)
Saprouter u2013r u2013V 3 u2013K u201Cp:CN=SAP-ROUTER,OU=0000733879,OU=SAProuter,O=SAP,C=DEu201D
13)Connection to SAP can tested using the command
lgtst u2013H /H/172.18.9.8//H/194.39.131.34/S/sapdp99/H/oss001/S/sapmsO01 u2013S x u2013W 30000
Note : The file lgtst.exe can be copied from other SAP systemu2019s kernel directory.
The output should look like these:
Using trcfile: dev_lg
List of reachable application servers
u2026.
u2026..
u2026u2026.
u2026u2026u2026.
If the lgtst command does not display the list of reachable application servers, then the connection to SAP could not be established. Troubleshoot the error and rectify.
For more info see the following sapnote
note 30289 : SAProuter documentation
note 525751: Installation of the SNC-SAPRouter as NT Service
note 46902 : Security aspects in remote access
note 48243 : Integrating SAProuter into a firewall
note 33135 : Guidelines for OSS1 (Version for SAPSERV3).
note 35010 : Service connections: Composite note (overview) -
Changing SAP Router to different System
HI Experts,
SAP Router is installed in our Develpoment system can it be possible for us to install this on the solution manager System. Is this advisable to change the SAP router to a different machine. If so How is that possible?
Regards,
Vamshi.Hi,
Please use the following step.
Installation Steps
1.1 Downloading necessary software components from SAP Service Marketplace:
1. SAProuter
Use the latest SAProuter version (37.x), which can be downloaded from
SAP Service Marketplace under the following link.
http://service.sap.com/swdc
 Download
 Support Packages and Patches
 Entry by Application Group
 Additional Components
 SAPROUTER
 SAPROUTER 6.40
SAPROUTER 6.40
From the available list of SAProuters, select the SAProuter for your OS platform.
2. SNC Libraries (SAPcryptolib) download:
http://service.sap.com/swdc
 Download
 SAP Cryptographic Software
Select the SAPcrytoLib libraries compatible with your Operating System.
Note: Please also download the SAPCAR.exe file from the above location to extract the SAProuter archive files.
3. Create a folder in /usr/sap with the name as: saprouter.
4. Extract both the files i.e. SAProuter.SAR and Cryptolib.CAR files into saprouter folder using the command:
SAPCAR -xvf SAProuterxxx.SAR
SAPCAR -xvf CRYPTOLIBxxx.CAR
1.2 Creating the certificate request
1. As user <snc>adm set the environment variables:
SECUDIR = /usr/sap/saprouter
SNC_LIB = /usr/sap/saprouter/libsapcrypto.so
2. Go to the Trust Center Service - Download Area and get the "Distinguished Name" for your SAProuter from the list of SAProuters registered for your installation.
3. Generate the certificate Request with the command:
./sapgenpse get_pse -v -r certreq -p local.pse "<Your Distinguished Name>"
P.S: We can also get the distinguished name from SAP itself when we register for the remote service connection.
4. Display the output file "certreq" using the command:
cat certreq
and with copy & paste insert the certificate request into the text area of the same form on the SAP Service Marketplace from which you copied the Distinguished Name.
1.3 Importing the certificate request
1. With this in turn you can install the certificate in your saprouter by calling
./sapgenpse import_own_cert -c srcert -p local.pse
1.4 Setting secured login to SAProuter
1. Now you will have to create the credentials for the SAProuter with the same program (if you omit -O <user>, the credentials are created for the logged in user account)
sapgenpse seclogin -p local.pse -O <user_for _saprouter>
2. This will create a file called cred_v2 in the same directory.
3. Check if the certificate has been imported correctly
./sapgenpse get_my_name -v -n Issuer
4. If this is not the case, delete the files cred_v2, local.pse and start over at Item 3 of 4.2 . If the output still does not match please open a customer message in component XX-SER-NET-OSS stating the actions you have taken so far and the output of the commands 3 of 4.2, 4.3, and 4.4.
1.5 Additional actions necessary before you can start saprouter
1. Logon to the system as <sid>adm, here sa1adm.
2. The environment variables SECUDIR, SNC_LIB and USER needs to be set for the user account SAProuter is running under using the commands:
setenv SECUDIR <path_to_libsecude>
i.e. setenv SECUDIR /usr/sap/saprouter
setenv SNC_LIB <path_to_libsecude>/<name_of_sapcrypto_library>
i.e. setenv SNC_LIB /usr/sap/saprouter/libsapcrypto.so
setenv USER sa1adm
3. Check if the environment of the user running saprouter contains the environment variable SECUDIR, SNC_LIB and USER using : printenv
4. Start the saprouter with the following command line:
#./saprouter -r -S <port> -K "p:<Your Distingushed Name>"
-K tells the saprouter to start with loading the SNC library
Eg. ./saprouter -r -S 3299 -K "p:CN=nradev, OU=0000759188, OU=SAProuter, O=SAP, C=DE"
./saprouter -r -V 2 -K "p:CN=nradev, OU=0000759188, OU=SAProuter, O=SAP, C=DE"
./saprouter -r -R /usr/sap/saprouter/saprouttab -G log.txt -V 2 -K "p:CN=nradev, OU=0000759188, OU=SAProuter, O=SAP, C=DE"
5. The corresponding file ./saprouttab should contain at least the following entries
inbound connections MUST use SNC
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <your_server1> <port_number>
repeat this for the servers and port_numbers you will need to allow,
please make sure that all explicit ports are inserted in front of a
generic entry '*' for port_number
outbound connections to <sapservX> will use SNC
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <sapservX> <sapservX_inbound_port>
permission entries to check if connection is allowed at all
P <IP address of a local host> <IP address of sapserv2>
all other connections will be denied
D * * *
6. Example: For a SNC encrypted connection to the SAPRouter on sapserv2 (194.39.131.34), the saprouttab should contain the following entries:
SNC-connection from and to SAP
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 194.39.131.34 *
SNC-connection from SAP to local R/3-System for Support
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> <R/3-Instance>
SNC-connection from SAP to local R/3-System for NetMeeting, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 1503
SNC-connection from SAP to local R/3-System for saptelnet, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 23
Access from the local Network to SAPNet - R/3 Frontend (OSS)
P <IP-addess of a local PC> 194.39.131.34 3299
deny all other connections
D * * *
Thanks,
Harshal -
Hi Team,
We have installed a new sap router in our landscape, Now across all the systems SAP is getting timeout issue from our router.
If i am changing it to old router everything works fine.
My query is what all commands need to check for network timeout issue, then is there any timeout parameter need to set after installation of new router in windows server 2008 for SAP Router.
Kindly suggest on this .
Thanks,
Pradeep.Hi Nirav,
Verify if saprouter.exe and niping.exe is placed under directory E:USRSAPSAPROUTER and same path is mentioned in windows services.
If path is correct one then you need to modify registry
Under HKEY_LOCAL_MACHINE ® SYSTEM ® CurrentControlSet ® Services ® Event Log ® Application enter the key saprouter and define the following values for it:
EventMessageFile (REG_SZ): ....saproutersaprouter.exe
TypesSupported (REG_DWORD): 0x7
I hope this will help you.
Regards,
Rupali Bajpai -
Dear All,
PC on which sap router software is installed to access sap remotely is corrupted. we want to format that Pc.
is it necessary to communicate SAP before formatting.
Also tell me steps to configure router software after formatting.
rgdsMake sure you give the same hostname to the router system as SAP has already registered your router at :
http://service.sap.com/saprouter-sncadd
Once you have repeated the router installation, make sure you repeat the certificate requesting and import through service mearketplace for the SNC.
http://service.sap.com/~form/sapnet?_SHORTKEY=01100035870000044248&_SCENARIO=01100035870000000202&_OBJECT=011000358700003588172003E
And once its completed, make sure you test the connection with SAP.
Regards,
Jazz -
Hi,
I have (stupid perhaps) question.
Is this scenario possible:
SNC connection from SAP GUI to SAP Router, and non-SNC connection from SAP Router to SAP System.
I know how to set up scenario like this:
SAP System --- (non-SNC conn) --- saprouter1 --- (SNC conn) --- saprouter2 --- (non-SNC conn) --- SAP GUI.
Best regards,
Marek MajchrowskiWolfgang,
To be sure myself and Marek understand, can you confirm the different scenarios supported:
Scenario 1:
SAP GUI --- (non SNC conn) --- saprouter1 --- (SNC conn) --- saprouter2 --- (non-SNC conn) --- SAP System
With this scenario, it would be possible for a user to logon using SAP GUI onto the SAP System, but without SAP GUI SNC.
Scenario 2:
SAP GUI --- (SNC conn) --- saprouter1 --- (non SNC conn) --- saprouter2 --- (SNC conn) --- SAP System
With this scenario it would be possible to logon to the SAP System using SAP GUI, and using SNC authentication.
Also, with this scenario the SAP GUI software and SAP System software would consider this to be similar to:
SAP GUI -- (SNC conn) -- SAP System
Scenario 3:
This is the scenario mentioned by Marek in his initial question:
SAP GUI -- (SNC conn) -- saprouter1 -- (non SNC conn) -- SAP System
With this scenario it will not be possible to logon to SAP System using SNC, and only possible if the SAP GUI is configured to not use SNC. In other words the SNC connection between SAP GUI and saprouter1 is available, but cannot be used.
Thanks,
Tim
Edited by: Tim Alsop on Feb 25, 2008 5:24 PM -
Problem with services of SAP after installation of ABAP on MS SQL server
Hi,
I am trying top install 2004 Netweaver ABAP+ JAVA on my machine
Following is my machine configuration -
Machine type - Windows 2003 Standard Edition SP1
Machine name - pun-idmqa-vm1
SAP Instance name - QSA
DB type - MS SQL 2000 SP4 + hotfixes and instcoll.exe is executed. After nstalling SQL shows server proper as SQL_Latin1_General_CP850_BIN2 collation
Message port - 3600
I could sucessfully install Database from CD and thereby could sucessfully install ABAP. During postinstall I tried to start the server. all the following services got up -
msg_server.exe
disp+work.exe
igswd.exe
But after some time 2nd service goes down. Following is the error message flashed in
trc file: "dev_disp", trc level: 1, release: "640"
Mon Jul 02 16:33:16 2007
kernel runs with dp version 128000(ext=102000) (@(#) DPLIB-INT-VERSION-128000-UC)
length of sys_adm_ext is 524 bytes
systemid 560 (PC with Windows NT)
relno 6400
patchlevel 0
patchno 31
intno 20020600
make: multithreaded, Unicode
pid 2492
***LOG Q00=> DpSapEnvInit, DPStart (00 2492) [dpxxdisp.c 1100]
Mon Jul 02 16:33:17 2007
shared lib "dw_xml.dll" version 31 successfully loaded
shared lib "dw_xtc.dll" version 31 successfully loaded
shared lib "dw_stl.dll" version 31 successfully loaded
shared lib "dw_gui.dll" version 31 successfully loaded
Mon Jul 02 16:33:21 2007
WARNING => DpNetCheck: NiAddrToHost(1.0.0.0) took 4 seconds
***LOG GZZ=> 1 possible network problems detected - check tracefile and adjust the DNS settings [dpxxtool2.c 3886]
MtxInit: -2 0 0
DpSysAdmExtInit: ABAP is active
DpSysAdmExtInit: JAVA is not active
DpShMCreate: sizeof(wp_adm) 10528 (1316)
DpShMCreate: sizeof(tm_adm) 2780232 (13832)
DpShMCreate: sizeof(wp_ca_adm) 24000 (80)
DpShMCreate: sizeof(appc_ca_adm) 8000 (80)
DpShMCreate: sizeof(comm_adm) 290000 (580)
DpShMCreate: sizeof(vmc_adm) 0 (372)
DpShMCreate: sizeof(wall_adm) (38456/34360/64/184)
DpShMCreate: SHM_DP_ADM_KEY (addr: 054B0040, size: 3192688)
DpShMCreate: allocated sys_adm at 054B0040
DpShMCreate: allocated wp_adm at 054B1B58
DpShMCreate: allocated tm_adm_list at 054B4478
DpShMCreate: allocated tm_adm at 054B44A0
DpShMCreate: allocated wp_ca_adm at 0575B0E8
DpShMCreate: allocated appc_ca_adm at 05760EA8
DpShMCreate: allocated comm_adm_list at 05762DE8
DpShMCreate: allocated comm_adm at 05762E00
DpShMCreate: allocated vmc_adm_list at 057A9AD0
DpShMCreate: system runs without vmc_adm
DpShMCreate: allocated ca_info at 057A9AF8
DpShMCreate: allocated wall_adm at 057A9B00
MBUF state OFF
EmInit: MmSetImplementation( 2 ).
Mon Jul 02 16:33:22 2007
<ES> client 0 initializing ....
<ES> InitFreeList
<ES> block size is 1024 kByte.
Using implementation std
<EsNT> Memory Reset enabled as NT default
<EsNT> EsIUnamFileMapInit: Initialize the memory 1132 MB
<ES> 1131 blocks reserved for free list.
ES initialized.
Mon Jul 02 16:33:36 2007
rdisp/http_min_wait_dia_wp : 1 -> 1
***LOG CPS=> DpLoopInit, ICU ( 2.6.1 2.6 4.0) [dpxxdisp.c 1462]
Mon Jul 02 16:33:38 2007
***LOG Q0K=> DpMsAttach, mscon ( pun-idmqa-vm1) [dpxxdisp.c 9719]
Mon Jul 02 16:33:46 2007
CCMS: start to initalize 3.X shared alert area (first segment).
DpMsgAdmin: Set release to 6400, patchlevel 0
Mon Jul 02 16:33:47 2007
MBUF state PREPARED
MBUF component UP
DpMBufHwIdSet: set Hardware-ID
***LOG Q1C=> DpMBufHwIdSet [dpxxmbuf.c 1025]
DpMsgAdmin: Set patchno for this platform to 31
Release check o.K.
Mon Jul 02 16:34:20 2007
ERROR => W0 (pid 2740) died [dpxxdisp.c 12170]
ERROR => W1 (pid 3736) died [dpxxdisp.c 12170]
my types changed after wp death/restart 0xbf --> 0xbe
ERROR => W2 (pid 3876) died [dpxxdisp.c 12170]
my types changed after wp death/restart 0xbe --> 0xbc
ERROR => W3 (pid 3896) died [dpxxdisp.c 12170]
my types changed after wp death/restart 0xbc --> 0xb8
ERROR => W4 (pid 3852) died [dpxxdisp.c 12170]
ERROR => W5 (pid 2008) died [dpxxdisp.c 12170]
my types changed after wp death/restart 0xb8 --> 0xb0
ERROR => W6 (pid 3776) died [dpxxdisp.c 12170]
my types changed after wp death/restart 0xb0 --> 0xa0
ERROR => W7 (pid 4052) died [dpxxdisp.c 12170]
my types changed after wp death/restart 0xa0 --> 0x80
DP_FATAL_ERROR => DpWPCheck: no more work processes
DISPATCHER EMERGENCY SHUTDOWN ***
increase tracelevel of WPs
killing W0-2740 (SIGUSR2)
ERROR => DpWpKill(2740, SIGUSR2) failed [dpxxtool.c 2468]
killing W1-3736 (SIGUSR2)
ERROR => DpWpKill(3736, SIGUSR2) failed [dpxxtool.c 2468]
killing W2-3876 (SIGUSR2)
ERROR => DpWpKill(3876, SIGUSR2) failed [dpxxtool.c 2468]
killing W3-3896 (SIGUSR2)
ERROR => DpWpKill(3896, SIGUSR2) failed [dpxxtool.c 2468]
killing W4-3852 (SIGUSR2)
ERROR => DpWpKill(3852, SIGUSR2) failed [dpxxtool.c 2468]
killing W5-2008 (SIGUSR2)
ERROR => DpWpKill(2008, SIGUSR2) failed [dpxxtool.c 2468]
killing W6-3776 (SIGUSR2)
ERROR => DpWpKill(3776, SIGUSR2) failed [dpxxtool.c 2468]
killing W7-4052 (SIGUSR2)
ERROR => DpWpKill(4052, SIGUSR2) failed [dpxxtool.c 2468]
NiWait: sleep (10000 msecs) ...
NiISelect: timeout 10000 ms
NiISelect: maximum fd=1629
NiISelect: read-mask is NULL
NiISelect: write-mask is NULL
Mon Jul 02 16:34:30 2007
NiISelect: TIMEOUT occured (10000 ms)
dump system status
Workprocess Table (long) Mon Jul 02 11:04:30 2007
========================
No Ty. Pid Status Cause Start Err Sem CPU Time Program Cl User Action Table
0 DIA 2740 Ended no 1 0 0
1 DIA 3736 Ended no 1 0 0
2 UPD 3876 Ended no 1 0 0
3 ENQ 3896 Ended no 1 0 0
4 BTC 3852 Ended no 1 0 0
5 BTC 2008 Ended no 1 0 0
6 SPO 3776 Ended no 1 0 0
7 UP2 4052 Ended no 1 0 0
Dispatcher Queue Statistics Mon Jul 02 11:04:30 2007
===========================
--------++++--
+
Typ
now
high
max
writes
reads
--------++++--
+
NOWP
0
3
2000
10
10
--------++++--
+
DIA
5
5
2000
5
0
--------++++--
+
UPD
0
0
2000
0
0
--------++++--
+
ENQ
0
0
2000
0
0
--------++++--
+
BTC
0
0
2000
0
0
--------++++--
+
SPO
0
0
2000
0
0
--------++++--
+
UP2
0
0
2000
0
0
--------++++--
+
max_rq_id 13
wake_evt_udp_now 0
wake events total 9, udp 7 ( 77%), shm 2 ( 22%)
since last update total 9, udp 7 ( 77%), shm 2 ( 22%)
Dump of tm_adm structure: Mon Jul 02 11:04:30 2007
=========================
Term uid man user term lastop mod wp ta a/i (modes)
Workprocess Comm. Area Blocks Mon Jul 02 11:04:30 2007
=============================
Slots: 300, Used: 1, Max: 0
--------++--
+
id
owner
pid
eyecatcher
--------++--
+
0
DISPATCHER
-1
WPCAAD000
NiWait: sleep (5000 msecs) ...
NiISelect: timeout 5000 ms
NiISelect: maximum fd=1629
NiISelect: read-mask is NULL
NiISelect: write-mask is NULL
Mon Jul 02 16:34:35 2007
NiISelect: TIMEOUT occured (5000 ms)
Shutdown server ...
DpModState: buffer in state MBUF_PREPARED
NiBufSend starting
NiIWrite: write 110, 1 packs, MESG_IO, hdl 3, data complete
MsINiWrite: sent 110 bytes
MsIModState: change state to SHUTDOWN
DpModState: change server state from STARTING to SHUTDOWN
Switch off Shared memory profiling
ShmProtect( 57, 3 )
ShmProtect(SHM_PROFILE, SHM_PROT_RW
ShmProtect( 57, 1 )
ShmProtect(SHM_PROFILE, SHM_PROT_RD
DpWakeUpWps: wake up all wp's
Stop work processes...
Stop gateway
killing process (3832) (SOFT_KILL)
Stop icman
killing process (3960) (SOFT_KILL)
Terminate gui connections
[DpProcDied] Process lives (PID:3832 HANDLE:1600)
waiting for termination of gateway
NiWait: sleep (1000 msecs) ...
NiISelect: timeout 1000 ms
NiISelect: maximum fd=1629
NiISelect: read-mask is NULL
NiISelect: write-mask is NULL
Mon Jul 02 16:34:36 2007
NiISelect: TIMEOUT occured (1000 ms)
Mon Jul 02 16:34:37 2007
[DpProcDied] Process died (PID:3832 HANDLE:1600)
[DpProcDied] Process died (PID:3960 HANDLE:1588)
DpHalt: cancel all lcom connections
MPI CancelAll 2 -> 0
MPI DeleteAll 2 -> 0
NiIMyHostName: hostname = 'pun-idmqa-vm1'
AdGetSelfIdentRecord: > <
AdCvtRecToExt: opcode 60 (AD_SELFIDENT), ser 0, ex 0, errno 0
AdCvtRecToExt: opcode 4 (AD_STARTSTOP), ser 0, ex 0, errno 0
DpConvertRequest: net size = 163 bytes
NiBufSend starting
NiIWrite: write 562, 1 packs, MESG_IO, hdl 3, data complete
MsINiWrite: sent 562 bytes
send msg (len 110+452) to name -, type 4, key -
detach from message server
***LOG Q0M=> DpMsDetach, ms_detach () [dpxxdisp.c 9945]
NiBufSend starting
NiIWrite: write 110, 1 packs, MESG_IO, hdl 3, data complete
MsINiWrite: sent 110 bytes
MsIDetach: send logout to msg_server
MsIDetach: call exit function
DpMsShutdownHook called
NiSelClear: removed hdl 3 from selectset
MBUF state OFF
AdGetSelfIdentRecord: > <
AdCvtRecToExt: opcode 60 (AD_SELFIDENT), ser 0, ex 0, errno 0
AdCvtRecToExt: opcode 40 (AD_MSBUF), ser 0, ex 0, errno 0
AdCvtRecToExt: opcode 40 (AD_MSBUF), ser 0, ex 0, errno 0
blks_in_queue/wp_ca_blk_no/wp_max_no = 1/300/8
LOCK WP ca_blk 1
make DISP owner of wp_ca_blk 1
DpRqPutIntoQueue: put request into queue (reqtype 1, prio LOW, rq_id 19)
MBUF component DOWN
NiBufClose: clear extensions for hdl 3
NiBufSetStat: bufstat of hdl 3 changed from OK to OFF
NiICloseHandle: shutdown and close hdl 3 / socket 1608
MsIDetach: detach MS-system
Mon Jul 02 16:34:38 2007
EsCleanup ....
***LOG Q05=> DpHalt, DPStop ( 2492) [dpxxdisp.c 8478]
Good Bye .....
I am new to SAP EP installation. Please help me regarding this issue.
Thanks and Regards,
Smithaforgot to tell you, after that probably you will need to make the installation again.
good luck. -
SAP router error on windows server 2008 64bit
Hi All,
I am installing sap router on windows 2008 server 64 bit.
While trying to generate certificate request it showing below error.
E:\usr\sap\saprouter\nt-x86_64>sapgenpse get_pse -v -r certreq -p local.pse "CN=
solman, OU=000XXXXXXX, OU=SAProuter, O=SAP, C=DE"
Got absolute PSE path "C:\Users\soladm\sec\local.pse".
Please enter PIN:
Please reenter PIN:
Supplied distinguished name: "CN=solman, OU=000XXXXXXX, OU=SAProuter, O=SAP, C=
DE"
Creating PSE with format v2 (default)
get_pse: Can't create PSE.
ERROR in af_create: (4352/0x1100) could not flush : "SW-PSE"
ERROR in create_PSE: (4352/0x1100) could not flush : "SW-PSE"
ERROR in modified_PSEFile: (4352/0x1100) could not flush : "SW-PSE"
ERROR in flush_PSEFile: (1283/0x0503) Can't write file : "C:\Users\soladm\sec\lo
cal.pse"
ERROR in aux_OctetString2file: (1283/0x0503) Can't write file : "C:\Users\soladm
\sec\local.pse"
I couldn't find the cryptography software specifically for windows 2008 server 64 bit ? So I downloaded the software for windows server 64 bit platform.
Do any one have idea on this...
Please reply..
Regards
VinayHi,
Yes, there is no specific cryptography software for windows server 2008 and whatever u have chosen is correct.
Fom the following error message I could see where the issue arises.
Can't write file : "C:\Users\soladm\sec\local.pse"
I think you have not set the following ENV variable for the SAPRouter admin user (in your case soladm) and hence the sapgenpse tries to import the certificate in the SOLADM user's document folder.
Set the following variables for the user SOLADM and then try to import the certificate as mentioned in the [link|http://service.sap.com/saprouter-sncdoc].
SECUDIR = E:\usr\sap\saprouter
SNC_LIB = E:\usr\sap\saprouter\nt-x86_64\sapcrypto.dll
Hope this resolves ur issue.
Regards,
Varadharajan M
Maybe you are looking for
-
hi! Deploying an application on WL7 I get this error: <i>java.lang.NullPointerException: Start server side stack trace: java.lang.NullPointerException at weblogic.utils.enumerations.FileEnumeration.getNextFile (FileEnumeration.java(Compiled Code
-
Po Ref to PR for a particular material type
Hi... I already did the configuration for the creation of PO with reference to PR, means without PR, PO will not be generated and throw the error message like, "You have no authorization to create without reference to another document". Now, I want t
-
Calling JSP bean function on button OnClick
Hi- A NewBie question.... I have a .jsp page and supporting .java bean. I registed the bean in .jsp page using <jsp:useBean ...> I want to fire a function defined in that bean on the click of a button which is defined in the .jsp page So I am doing s
-
getting very frustrated with the wait. does Verizon have any idea when the 8.1 update will be distributed? will it be in September? 2014? before WP9.0? Give us some idea PLEASE!
-
Returns to the state of departure
Hi When I reload the browser page it returns to the state of departure set in Flash Bilder even if it is for the authentication state of the beginning and we lose the session. I used Flash Bilder