SAP Note, Version: 4, Released On: 01.10.2014
Component:BC-CST-WDP
Priority:Recommendations / Additional Info
Category:Installation information
Release Status:Released to Customer
Correction:0
Manual Activities:0
Prerequisites:0
Description
Symptom
You use the PSE Management in SAP Web administration interface of the SAP Web Dispatcher.
Other Terms
SAPWEBDISP, SAPWEBDISP_HDP, Web Admin, icm/HTTP/admin_0, SSL configuration, SSL, SAPSSLS, SAPSSLS.pse, SAPSSLC, SAPSSLC.pse, SAPSSLA, SAPSSLA.pse, saplogon.pse, sapsrv.pse, sapgenpse, Web administration interface
Reason and Prerequisites
You use PSE Management in SAP Web Dispatcher and you configure PSE files according SAP Note 2009483.
Solution
The drop down list for PSE selection shows predefined PSE files as well as PSE files in the security directory (parameter SECUDIR) . The PSE files in the Web administration interface have a certain purpose.
If you run your SAP Web Dispatcher in standalone scenarios, you will see the following predefined PSE files:
- SAPSSLS.pse
- SSL server PSE. This file is used by default for a SSL server initialization. The SSL server should have a Distinguished Name with its host or at least domain name in the DN attributes. Example: Server with name server.mysap.com should either have subject DN “CN=server.mysap.com” or “CN=*.mysap.com”.
- SAPSSLC.pse
- SSL client PSE. This file is used by default for a SSL client initialization.
- SAPSSLA.pse
- SSL anonymous PSE. This name is the default value for a SSL client communication you use for anonymous connections, without partner verification.
If you use a Web Dispatcher in the HANA XS installation, you see the following predefined PSE files:
- SAPSSLS.pse
- SSL server PSE. This file is used by default for a SSL server initialization. The SSL server should have a Distinguished Name with its host or at least domain name in the DN attributes. Example: Server with name server.mysap.com should either have subject DN “CN=server.mysap.com” or “CN=*.mysap.com”.
- SAPSSLC.pse
- SSL client PSE. This file is used by default for a SSL client initialization.
- SAPSSLA.pse
- SSL anonymous PSE. This name is the default value for a SSL client communication you use for anonymous connections, without partner verification.
- saplogon.pse
- Single Sign-On PSE for SAP logon ticket validation and SAP assertion ticket creation and validation.
- sapsrv.pse
- SSL server PSE for SQL communications with the HANA DB. The same rules apply for the subject name as for SAPSSLS.pse. If HANA is SAML enabled, this PSE is also used for SAML trust configuration.
Remark: The predefined PSE files you see here are generated at startup of the Web Dispatcher if the PSE is not available. This means that the existing entries you see after first usage are generated. You can decide whether you want to recreate the key pair of these PSE files. The generation is done with the best known default values for the respective PSE.
Software Components
| Software Component | From | To | |||
|---|---|---|---|---|---|
| HDB | 1.00 | 1.00 | |||
| KRNL32NUC | 7.20 | 7.20 | |||
| KRNL32NUC | 7.20EXT | 7.20EXT | |||
| KRNL32NUC | 7.21 | 7.21 | |||
| KRNL32NUC | 7.21EXT | 7.21EXT | |||
| KRNL32UC | 7.20 | 7.20 | |||
| KRNL32UC | 7.20EXT | 7.20EXT | |||
| KRNL32UC | 7.21 | 7.21 | |||
| KRNL32UC | 7.21EXT | 7.21EXT | |||
| KRNL64NUC | 7.20 | 7.20 | |||
| KRNL64NUC | 7.20EXT | 7.20EXT | |||
| KRNL64NUC | 7.21 | 7.21 | |||
| KRNL64NUC | 7.21EXT | 7.21EXT | |||
| KRNL64NUC | 7.38 | 7.38 | |||
| KRNL64UC | 7.20 | 7.20 | |||
| KRNL64UC | 7.20EXT | 7.20EXT | |||
| KRNL64UC | 8.00 | 8.00 | |||
| KRNL64UC | 8.04 | 8.04 | |||
| KRNL64UC | 7.21 | 7.21 | |||
| KRNL64UC | 7.21EXT | 7.21EXT | |||
| KRNL64UC | 7.38 | 7.38 | |||
| WEBDISP | 7.20 | 7.20 | |||
| WEBDISP | 7.20_EXT | 7.20_EXT | |||
| WEBDISP | 7.21 | 7.21 | |||
| WEBDISP | 7.21_EXT | 7.21_EXT | |||
| WEBDISP | 7.40 | 7.40 | |||
| CRYPTOLIB | 5.5.5 PL21 | 5.5.5 PL21 | |||
| CRYPTOLIB | 5.5.5 PL24 | 5.5.5 PL24 | |||
| CRYPTOLIB | 5.5.5 PL26 | 5.5.5 PL26 | |||
| CRYPTOLIB | 5.5.5 PL30 | 5.5.5 PL30 | |||
| CRYPTOLIB | 5.5.5 | 5.5.5 | |||
| CRYPTOLIB | 5.5.5 FOR 7.20 | 5.5.5 FOR 7.20 | |||
| CRYPTOLIB | 8 | 8 | |||
| KERNEL | 7.20 | 7.21 | |||
| KERNEL | 8.00 | 8.00 | |||
| KERNEL | 8.04 | 8.04 | |||
| KERNEL | 7.38 | 7.38 |
References
This document refers to
| SAP Note/KBA | Component | Title | ||
|---|---|---|---|---|
| 2009483 | BC-CST-WDP | PSE Management in Web Administration Interface of SAP Web Dispatcher |
This document is referenced by
| SAP Note/KBA | Component | Title | ||
|---|---|---|---|---|
| 2935957 | HAN-DB-SEC | HANA SSO with Assertion Tickets fails with error ‘Creation of SAP Assertion Ticket failed because of: $ErrorText$.’ | ||
| 2880635 | HAN-DB-SEC | SAML fails due to conflicting PSE’s | ||
| 2592757 | HAN-DB-SEC | HANA Basic How-To Series – Securing HANA XS classic via SSL / TLS / HTTPS – using sapgenpse and pse container (OpenSSL Edition) – SYSTEMDB | ||
| 2502174 | HAN-DB-SEC | HANA Basic How-To Series – Securing HANA XS classic via SSL / TLS / HTTPS – using Web Dispatcher Administration and pse container (Microsoft CA edition) – SYSTEMDB | ||
| 2487120 | HAN-AS-XS | HANA Basic How-To Series – Securing HANA XS classic via SSL / TLS / HTTPS – using sapgenpse and pse container (Microsoft CA edition) – SYSTEMDB | ||
| 2014996 | BC-CST-WDP | SSL Setup SAP Web Dispatcher | ||
| 2009483 | BC-CST-WDP | PSE Management in Web Administration Interface of SAP Web Dispatcher |
Attributes
| Key | Value | ||
|---|---|---|---|
| Other Components | SAP HANA > SAP HANA Database > SAP HANA Security & User Management (HAN-DB-SEC) | ||
| Other Components | Basis Components > Security – Read KBA 2985997 for subcomponents > Secure Sockets Layer Protocol (BC-SEC-SSL) | ||
| Other Components | Basis Components > Client/Server Technology > Internet Communication Manager (BC-CST-IC) | ||
| Other Components | Basis Components > Security – Read KBA 2985997 for subcomponents (BC-SEC) | ||
| Other Components | Basis Components > Identity and Access Management > Please use BC-IAM-SSO* (BC-IAM-SL) |



发表回复