Using the Portal Single Sign-On for java applet clients

Hi
We have a task to build a java applet working within a portlet and comunicating to some session EJB(wrapped BC4J) running on the OC4J. The applet is presumably connecting to server via RMI. This connection should be restricted to some groups of portal users.
When a user is entering the applet he is supposed to be already logged into the Portal.
There is a lot of information on building custom secure portlets using only a pure HTML(same as JSP) client whith the help of the Portal Single Sign-On.
But, is it possible to use the Single Sign-On for establishing a secure RMI connection from applet to OC4J without entering a password in the applet once more?
Yuriy

Perhaps you can write a small JSP page or PLSQL
web procedure that will grab user name from
the SSO Server (via SSOSDK/mod_osso)
and invoke the applet with encrypted user name.
The applet will receive the encrypted username
and decrypt it to get the clear user name.
This help to get Single Sign-On.
To make sure that environment is secure, encrypted
user name parameter should have random salt,
user name, and time stamp to prevent replay attack.
Applet must make sure that the encrypted users name
time stamp set by the JSP/PLSQL page has value
within a reasonable time limit like 5 minutes

Similar Messages

  • SSO means everyone must use the portal -- no GUI?

    We are just transitioning from Blueprint to Realization and must make a decision.  We'd like to use Single Sign-On.  I was told that if we use SSO, then all users must use the portal, no-one can use the SAPGUI.  Is this true?

    Hi Leo,
    Single Sign-on merely means that a user has to authenticate against a trusted party and and can access afterwards all other applications (if configured for SSO) without authentication.
    There are quite a few SSO techniques. See the article in <a href="http://en.wikipedia.org/wiki/Single_sign_on">Wikipedia</a> to get a first impression.
    If it comes to SAP NetWeaver Portal we talk about SSO between the portal and the integrated backend applications. That means once the user logged into the portal the user can access the integrated applications without giving his credentials. Basically, there are two SSO methods available:
    - SAP Logon Ticket
    - User Mapping
    Find more information on these techniques in the SAP Library.
    <a href="http://help.sap.com/saphelp_nw04/helpdata/en/d6/031c3ac9fb1d75e10000000a114084/frameset.htm">Authentication and Single Sign-on</a>
    <a href="http://help.sap.com/saphelp_nw04/helpdata/en/89/6eb8deaf2f11d5993700508b6b8b11/frameset.htm">Authentication on the Portal (Single Sign-on)</a>
    Hope I could help a bit.
    Best regards,
    Martin

  • I recently signed up for a one month trial of adobe pro.  I logged in.  I cannot convert a single page of PDF file to word or Excel with this trial.  I just get the request to sign up for a year.  What good is the trial if I can't try it?

    I recently signed up for a one month trial of adobe pro.  I logged in.  I cannot convert a single page of PDF file to word or Excel with this trial.  I just get the request to sign up for a year.  What good is the trial if I can't try it?

    Hey vcomfort6,
    Please ensure that you are using Adobe Acrobat and not Reader to convert PDF file to word or excel.
    Could you tell me whether it is a scanned document? Does this happen with all PDFs or any specific one?
    Do you get any error message? What exactly happens when you try doing the same?
    Hope to hear from you.
    Regards,
    Anubha

  • How to use single sign-on  for BCC and Experience Manager

    Does anyone have experience in implementing single-sign-on for BCC and Endeca Experience manager for business users.

    With the older versions of Endeca commerce stack there is no OOTB support for this. However with Oracle Commerce 11, SSO with BCC and Experience Manager are out of the box. Oracle Commerce 11 is released today.

  • I do not use or have not signed up for a MobileMe Account but I am getting duplicates in my iCal for some reason.  All discussions I read are pointing to the MobileMe being the problem but it is not.  Please help me.  There must be another reason.

    I do not use or have not signed up for a MobileMe Account but I am getting duplicates in my iCal for some reason.  All discussions I read are pointing to the MobileMe being the problem but it is not.  Please help me.  There must be another reason all my entries appear twice. 

    If you wish to submit comments to Apple, the best way is to use their feedback pages.
    http://www.apple.com/feedback/itunesapp.html
    It's not likely that anyone from Apple will see your comments here among the thousands of other posts.
    Regards.

  • Single Sign On For CRM IC?

    I'm working on a project to implement Single Sign On for our company.  I currently have it working for all of our SAPGUI users via SNC (LDAP auth) and also our portal users (also via LDAP auth), and want to use it also for the CRM Interaction Center (Web client). 
    Has anyone successfully implemented a single sign on solution for the IC?  If so, reward points are waiting for someone who can guide me to documentation on how to set it up/configure.
    Thanks in advance for any help the forum can provide.

    Hi Wayne, a very good question based on the docs. <a href="http://help.sap.com/saphelp_crm40sr1/helpdata/en/99/39926a159f4a75bd7abeec9b49a040/frameset.htm">In the docs</a> it is stated that:
    <b>Integration Into Single Sign-On Environments</b>
        The application does not accept SAP logon tickets.
        The application does not accept X.509 digital certificates.
        When the IC agent user is integrated into the SAP Enterprise Portal, it is SSO enabled.
    I would guess, this means, there is an iview or something like this in the portal to start the WebClient wihtout requiering the user to authenticate again.
    regards,
    Patrick

  • Single Sign On for SAP - Integration wih AD

    Users often need both an SAP and Active Directory identity and password to work in their IT environment. However, these multiple identities and passwords create several problems: user confusion leading to decreased productivity, increased help desk costs and security breaches.
    For this purpose how can we extend Active Directory authentication for single sign-on to SAP?
    Regards,
    Majid Khan

    Hi,
    It seems that SAP SSO/IWA  based on Spnego Kerberos is what you want.
    Spnego Kerberos only works on a J2EE stack based system.
    The classical technique is so to implement it on a SAP portal and to use redirect applications to use the portal saplogon ticket to authenticate on abap systems.
    Check help.sap.com on the subject, you will get a lot of information.
    Regards,
    Olivier

  • Single sign on and java-apps

    Hello!
    I'm a Austrian student and i need help for my degree dissertation. We have created a Portalhomepage. And now,
    we would like to use the same username and password for several javaapplications.
    What possibilities exists to implement this facts? I need all sorts of documentations.
    Sorry! My English is very bad.
    Thanx in advance!

    The best approach is to implement the Java applications as SSO partner applications so that they delegate their authentication to the Login Server, thereby leveraging the same credentials as used to login to the Portal.
    The SSO-SDK which is required to implement a partner application is available from technet:
    Portal Development Kit
    SSO Software Development Kit
    Example Java Application Written as an SSO Partner App
    null

  • Accessing portal roles in webdynpro for java

    Hi,
    Please let me know how to access portal roles in webdynpro for java.
    Rgds,
    Patana

    Hi ,
    Please use this API to access the portal roles:
    IRoleFactory fact=UMFactory.getRoleFactory();
    Also see this code to get more information of role using code:
    IRoleFactory rolef=UMFactory.getRoleFactory();
    IRoleSearchFilter searchfilterrole= rolef.getRoleSearchFilter();
    ISearchResult searchResult = rolef.searchRoles(searchfilterrole);
    while(searchResult.hasNext())
    String unq=(String) searchResult.next();
    IRole role1=rolef.getRole(unq);
    String roleName = role1.getDisplayName();
    String roleID = role1.getUniqueID();
    // Once you get the informationof role you can use it in your application as per your requirement.
    Also please note that:
    You should add "com.sap.security.api.jar" to your project`s java build path for getting the Portal Security API's.
    I hope this solves the problem. Please revert back incase you need any further informationon this.
    Thanks and Regards,
    Pravesh

  • Oracle Single Sign-On for perticular module ?

    hello people,
    I have implemented Single Sign-On for some of my jsp pages in different folders like finance, inventory, etc,. Am creating some test users and groups in OID. but the users in inventory group are able to login to finance module. can u please give me some suggestions on how to restrict this ? where to do the configurations ?
    thanks

    Hi,
    if it is a J2EE application, use J2EE roles - defined in web.xml - and map it to groups in OID through the orion-application.xml file. See the OC4J security guide which is a part of Oracle Application Server documentation on OTN
    Frank

  • I have ad Apple ID on my iPad , when I use the apple on my iPhone for the first time, I put in my Apple ID for the iPad, didn't work. Need to create a new one. Why? How can I just use my iPad ID on my iPhone?

    I have ad Apple ID on my iPad , when I use the apple on my iPhone for the first time, I put in my Apple ID for the iPad, didn't work. Need to create a new one. Why? How can I just use my iPad ID on my iPhone?

    Hi kamfong,
    Went to Settings where?
    If you want to use your exisiting Apple ID on your iPad, you need to:
    1.     Go to Settings>iTunes & App Store and sign out the new ID, and then sign on the old one
    2.     Go to Settings>iCloud, scroll to the bottom and delete the iCloud account, and the sign back onto iCloud using the old ID
    You still have not indindated why you are saying that using your old ID originally "didn't work". What do you mean by that? Did you get some sort of error when you tried to sign on with your exisiting Apple ID?
    Cheers,
    GB

  • Using the same Asset Master Record for similar assets

    Dear all,
    I would like to ask if it is possible to use the same asset master record for multiple assets which are similar. The assets will be posted in different periods / fiscal years and therefore the depreciation would change and be charged according to the useful life of the individual assets posted to the same master record and which in turn will vary according to periods / fiscal year posted.
    For example, an asset master record is created for Vehicles. The 1st vehicle with a useful life of 4 years is depreciated at the start of the year for 4 years. The second vehicle is purchased on 6 months after on the 1st June using the same asset master record. However the depreciation is not worked out over the same useful life of the previous vehicle but is extended for a further 6 periods. Is this possible and how is it done.
    Many thanks for any feedback and help.
    Thanks
    PRG

    Dear Peter
    What is the issue in case you created separate Asset Master for each Vehcile ? Is there any specific need for you to accommodate all the assets in one single asset master ?
    I don't think it is correct method as per Company's Act. Over and above, how would you plan for the Fixed Assets Register in the given situation ?
    Regards
    Gemini

  • Working with documents via BEx Analyzer not using the portal

    Hello,
    i read that we are able to create (work) with documents (comments) via
    BEx Analyzer. When i want to add a comment how it is described in the
    help we get connected to the portal. We dont want to use the portal for
    that. Therefore we searched a way to skip the portal. We read that in
    BW Versions before 7.0 the portal was not connected but since 7.0 we
    have the portal connectivity, but it should also possible to not use
    the portal and to access directly the BI Server. I searched for the
    Customizing to do so but i could not find it where to switch to the old
    logic.
    And another question is when we use the Portal with the knowledge base . The documents are stored in the document framework (SKWF). Is it the same as the Datawarehousing Workbench --> documents. This storage we want to use.
    Can anyone give me a hint?
    Kind regards,
    Murat

    Hi Murat,
       We are also facing the same issue of when trying to create/access the documents from BEx analyzer it is connecting portal , we need to bypass portal and directly access the document browser in BW server.
      In your thread you mentioned it is done. So can you please let me know how did you enable the old configuration?. It will be very much helpful to us.
    Awaiting for your reply.
    Thanks,
    V.Senthilkumar

  • How to use the portal Calendar

    Hi,
    I want to post a calendar of events for my portal users and I'm looking for documentations or tutorial in using the portal calendar feature.
    Thanks,
    Leonard

    hi leonard,
    there are 2 samples in the PDK for a lotus notes calendar portlet and a microsoft exchange calendar portlet. you can access them at portalcenter.oracle.com - PDK - Samples.
    another possibility would be to use the calendar portlet that is provided by the portlet builder. in you portal go to the navigator - providers - locally built providers - example applications: there you find a sample of a calendar portlet. you can create a new one by clicking on Create New...Calendar
    another possibiliy is to look at the portlets from our partners: on portalcenter click on Portal Catalog - Search the Portal catalog - type in 'calendar' as search word and you get back a list of available calendar portlets.
    thanks,
    christian

  • Error Using the SQL Server 2000 Driver for JDBC Service Pack 3

    Hi,
    I�m using the SQL Server 2000 Driver for JDBC Service Pack 3. The connection is succesfully, but when I use de statement.executequery() method, there is the follow exception:
    java.sql.SQLException: [Microsoft][SQLServer 2000 Driver for JDBC][SQLServer]Invalid object name 'PEC_COUNTRY'.
    This is my code:
    ResultSet resultSet;
    Statement statement;
    Connection connection;
    Class.forName("com.microsoft.jdbc.sqlserver.SQLServerDriver").newInstance();
    connection = DriverManager.getConnection("jdbc:microsoft:sqlserver://S0MALMUERTA:1433;user=sa;password=");
    statement = connection.createStatement();
    resultSet = statement.executeQuery("SELECT COY_INX, COY_NAME, COY_ICO FROM PEC_COUNTRY
    ");When I make the last instruction, occurs the above exception
    Thanks in advance
    Luija

    The way you are connecting, the default database used will be 'master' and i guess that the table PEC_COUNTRY was defined in another database.
    If it is the case you need to specify the database name.
    connection = DriverManager.getConnection("jdbc:microsoft:sqlserver://S0MALMUERTA:1433;DatabaseName=yourdb;user=sa;password=");

Maybe you are looking for

  • Monitoring of data

    Hi Sapiens, when i am monitoring the data rsmo, one of the ods has 0 records. the ods is receiving the data from r/3 ztable. how to check from r/3, the number of records sent to bw. Plz advise. Regards

  • How can I extract metadata using JMF

    Hello, I want to extract metadata such as artist, pulisher, name, author , etc. from media files. Can Java Media Framework do? Personally, I did not find any APIs from JMF Javadoc. thank you

  • Publish to .Mac says it has published but it hasn't!

    In the last week when I publish my site (about 70 pages) directly to .Mac, iWeb say it is finished uploading in about 2 minutes, a suspiciously short time given the slowness of my connection. Previously it took much longer (10 or 20 minutes) but work

  • UCCX Agent ready state softkey

    I was under the understanding that UCCX agents could also sign into the ready state through they're assigned phones ? So far in my reading of documents and such I have yet to see any bit of information for setting up agents without CAD. In many of ou

  • De-Authorise all computers

    I have already used this option in iTunes once this year, and I am now at the point where I need to do it again, I have tried using the form on apple's website to ask them to help me with the issue but I haven't heard anything back and I did this abo