SlideShare a Scribd company logo
Principal	
  Propagation	
  with	
  SAP	
  Cloud	
  Platform
Automation	
  Core
• Technology	
  improvements	
  mean	
  computing	
  tasks	
  previously	
  requiring	
  interaction	
  with	
  people,	
  can	
  be	
  fully	
  automated.
• Automation	
  brings	
  repeatability,	
  reduced	
  error	
  rates,	
  easy	
  scalability	
  of	
  service	
  provision.
Platform	
  Agnostic
• Future	
  interoperability	
  and	
  open	
  standards	
  will	
  mean	
  businesses	
   can	
  swap	
  easily	
  between	
  cloud	
  providers.
• It	
  is	
  key	
  that	
  solutions	
   are	
  designed	
  to	
  operate	
  in	
  such	
  a	
  platform	
  agnostic	
  manner	
  outside	
  the	
  bounds	
  of	
  normal	
  
technical	
  architecture	
  design	
  (i.e.	
  no	
  fixed	
  O/S	
  choices	
  or	
  fixed	
  DB	
  platforms).
Established	
  Technological	
  Principals
• Solutions	
   today,	
  should	
   be	
  built	
  using	
  already	
  established	
  technological	
  principals.
• Using	
  bleeding	
  edge	
  rarely	
  produces	
  the	
  perceived	
  benefits	
  in	
  places	
  such	
  as	
  core	
  business	
   systems,	
  without	
  significant	
  
buy-­‐in	
  from	
  business	
   leaders.
• Pre-­‐empting	
  standards	
  not	
  already	
  widely	
  adopted,	
  could	
  produce	
  a	
  “Beta-­‐Max”	
  scenario.
Future	
  Assurance
• Technology	
  solutions	
  should	
  deliver	
  for	
  a	
  minimum	
  timeframe	
  within	
  the	
  context	
  of	
  the	
  lifecycle	
  of	
  the	
  related	
  business	
  system.
• Example:	
  Re-­‐writing	
  scripts	
  during	
  any	
  platform	
  migration	
  should	
  not	
  just	
  use	
  the	
  coolest	
  scripting	
  language,	
  they	
  should	
  use	
  a	
  commonly	
  
known	
  language	
  widely	
  used	
  and	
  understood.
Drivers
• Permits	
  federated	
   authentication	
  (single-­‐sign-­‐on)	
   into	
  customer	
  SAP	
  systems	
  
via	
  an	
  IdP such	
  as	
  SAP	
  IDM.
• Authentication	
  to	
  on-­‐premise	
   SAP	
  IDM	
  is	
  possible.
• Subsequent	
   SAP	
  system	
  can	
  authenticate	
   against	
  the	
  IDM	
  generated	
  SAP	
  logon	
  
ticket	
  (MYSAPSSO2	
  cookie)	
  or	
  SAML2	
  token.
• SAP	
  Cloud	
  Platform	
  (SCP)	
  users	
  (S-­‐users)	
   can	
  use	
  SAP	
  Cloud	
  Platform	
  services	
  
such	
  as	
  Web	
  IDE,	
  authenticating	
  into	
  the	
  customer	
  SAP	
  systems	
  against	
  their	
  
respective	
   SAP	
  system	
  account	
  in	
  the	
  IdP (usually	
  their	
  corporate	
  identity).
About	
  Principal	
  Propagation
• SAP	
  Cloud	
  Platform	
  a.k.a.	
  SCP	
  (previously	
   called	
  SAP	
  HANA	
  Cloud).
• A	
  PaaS	
  set	
  of	
  tools,	
  utilities	
  and	
  cloud	
  capabilities	
  for	
  use	
  with	
  SAP	
  and	
  non-­‐
SAP	
  products,	
  all	
  provided	
  in	
  the	
  cloud.
• Accessed	
   over	
  the	
  internet.
• Is	
  the	
  future	
  of	
  SAP	
  software	
   integration	
  and	
  will	
  provide	
  the	
  basis	
  for	
  many	
  
SAP	
  SaaS	
  applications	
  also.
• Can	
  be	
  accessed	
   from	
  “on-­‐premise”	
   (or	
  your	
  cloud	
  provider)	
   using	
  the	
  SAP	
  
Cloud	
  Connector	
  (SCC),	
  which	
  acts	
  as	
  a	
  reverse	
   proxy.	
  
About	
  SAP	
  Cloud	
  Platform
SCP
SAP	
  Cloud	
  Platform	
  
Developer	
  with	
  S-­‐user	
  
account.
Destinations:
BE1:1234
SAP	
  Cloud	
  Connector
Sub-­‐ Account:	
  ABC123
BE1:1234	
  =	
  
https://be1.corp
Trust	
  Store
CA	
  Cert
System	
  Cert
BE1	
  SSL	
  Cert	
  Chain
Cloud “On-­‐Premise”	
  (Cloud	
  be	
  
cloud	
  hosted	
  IaaS)
IdP (SAP	
  IDM)
UME
Developer	
  corporate	
  
identity	
  and	
  account.
BE1	
  – SAP
(https://be1.corp)
Optional
Web	
  Dispatcher
Trust	
  Store
SCC	
  CA	
  Cert
Target	
  ICF	
  Service
ICM	
  (+Web	
  Dispatcher)	
  Parameters:
login/certificate_mapping_rulebased=”1“
icm/trusted_reverse_proxy_0=<SCC	
  System	
  CA>
icm/HTTPS/verify_client=1
ICM
Trust	
  Store
SCC	
  CA	
  Cert
SSL
HTTP	
  HEADER
SCC	
  Cert	
  
Chain
x.509
Client	
  Cert
SAML	
  
Token
Customise:
STRUST
CERTRULE
RZ10
Wdisp SSL	
  Chain
Architecture	
  Overview
SCP:
• Create	
  S-­‐user	
  account(s).
• Create	
  destination	
  to	
  back-­‐end	
  SAP	
  system	
  via	
  SCC	
  with	
  Principal	
  Propagation	
  enabled	
  and	
  pointing	
  to	
  your	
  IdP.
IdP:
• SAML:	
  Configure	
  SAML	
  token	
  creation	
  for	
  SCP	
  users	
  after	
  authentication.
SCC:
• Sub-­‐Account:	
  Register	
  SCP	
  sub-­‐accounts	
  for	
  incoming	
  connections	
  from	
  SCP.
• On-­‐Premise:	
  Configure	
  trust	
  store	
  with	
  back-­‐end	
  SAP	
  system	
  SSL	
  server	
  cert	
  and	
  optional	
  Web	
  Disp SSL	
  cert.
• On-­‐Premise:	
  Configure	
  Principal	
  Propagation	
  user	
  x.509	
  client	
  cert	
  creation	
  upon	
  SAML	
  token	
  receipt.
BE1:
• ICM:	
  Transaction	
  STRUST	
  to	
  trust	
  the	
  SCC	
  client	
  x.509	
  cert.
• AUTH:	
  Transaction	
  CERTRULE	
  to	
  map	
  SCC	
  dynamic	
  x.509	
  client	
  cert	
  CN	
  to	
  SAP	
  system	
  user	
  accounts.
• ICM:	
  Transaction	
  RZ10	
  to	
  configure	
  ICM	
  params to	
  enable	
  trusting	
  of	
  client	
  x.509	
  certs	
  forwarded	
  in	
  HTTP	
  
header.
Optional	
  Web	
  Dispatcher:
• ICM:	
  Adding	
  SCC	
  client	
  x.509	
  cert	
  to	
  the	
  SAPSSLS	
  PSE.
• ICM:	
  DEFAULT.PFL	
  to	
  configure	
  ICM	
  params to	
  enable	
  trusting	
  of	
  client	
  x.509	
  certs	
  forwarded	
  in	
  HTTP	
  header.
Areas	
  for	
  Configuration
• Principal	
  Propagation	
  should	
  enable	
  smooth	
  efficient	
   access	
  to	
  back-­‐end	
  SAP	
  
systems	
  via	
  the	
  SAP	
  Cloud	
  Connector	
   from	
  the	
  SAP	
  Cloud	
  Platform.
• A	
  secure	
  setup	
  is	
  always	
  recommended,	
   paying	
  attention	
  to	
  SAP	
  
recommendations	
   for	
  the	
  SCC	
  networking	
  and	
  HA.
• The	
  future	
  direction	
  of	
  SAP	
  integration	
  will	
  need	
  to	
  use	
  the	
  SCC	
  more	
  and	
  
more.	
  	
  Example:	
  SAP	
  Analytics	
  Coud.
• The	
  Principal	
  Propagation	
  trust	
  setup	
  is	
  complex	
  and	
  involves	
  multiple	
  
certificates,	
   leaving	
  you	
  open	
  to	
  the	
  probability	
  of	
  certificate	
  expiration	
  
causing	
  an	
  outage.
Summary
SAP	
  Notes:
• SAP	
  note	
  2462533	
  -­‐ Configuring	
  Principal	
  Propagation	
  to	
  an	
  ABAP	
  System.
• SAP	
  note	
  2052899	
  -­‐ ICM	
  -­‐ Multiple	
  Trusted	
  Reverse	
   Proxies
• SAP	
  note	
  2461375	
  -­‐ How	
  to	
  connect	
  SAP	
  Cloud	
  Platform	
  Identity	
  
Authentication	
  Service	
   to	
  on-­‐premise	
   user	
  store
SAP	
  Guides:
• SCC	
  secure	
   setup	
  recommendations:
https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-­‐
US/e7ea82a4bb571014a4ceb61cb7e3d31f.html
• Configure	
  Principal	
  Propagation	
  for	
  an	
  ABAP	
  system:
https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-­‐
US/a8bb87a72d094e0d981d2b1f67df7bc3.html
References
Thank	
  You

More Related Content

What's hot

From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...
From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...
From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...
confluent
 
BW Migration to HANA Part1 - Preparation in BW System
BW Migration to HANA Part1 - Preparation in BW SystemBW Migration to HANA Part1 - Preparation in BW System
BW Migration to HANA Part1 - Preparation in BW System
Linh Nguyen
 
SAP Cloud Platform API Management Technical Brief
SAP Cloud Platform API Management Technical BriefSAP Cloud Platform API Management Technical Brief
SAP Cloud Platform API Management Technical Brief
SAP Cloud Platform
 
Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...
Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...
Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...
HostedbyConfluent
 
Application Integration: EPM, ERP, Cloud and On-Premise – All options explained
Application Integration: EPM, ERP, Cloud and On-Premise – All options explainedApplication Integration: EPM, ERP, Cloud and On-Premise – All options explained
Application Integration: EPM, ERP, Cloud and On-Premise – All options explained
Alithya
 
S4 h 188 sap s4hana cloud implementation with sap activate
S4 h 188 sap s4hana cloud implementation with sap activateS4 h 188 sap s4hana cloud implementation with sap activate
S4 h 188 sap s4hana cloud implementation with sap activate
Lokesh Modem
 
SAP HANA SPS09 - Multitenant Database Containers
SAP HANA SPS09 - Multitenant Database ContainersSAP HANA SPS09 - Multitenant Database Containers
SAP HANA SPS09 - Multitenant Database Containers
SAP Technology
 
SAP Cloud Platform - Integration, Extensibility & Services
SAP Cloud Platform - Integration, Extensibility & ServicesSAP Cloud Platform - Integration, Extensibility & Services
SAP Cloud Platform - Integration, Extensibility & Services
Andrew Harding
 
SAP BusinessObjects Private Cloud Edition (PCE)
SAP BusinessObjects Private Cloud Edition (PCE)SAP BusinessObjects Private Cloud Edition (PCE)
SAP BusinessObjects Private Cloud Edition (PCE)
Wiiisdom
 
BW Migration to HANA Part 3 - Post-processing on the Migrated System
BW Migration to HANA Part 3 - Post-processing on the Migrated SystemBW Migration to HANA Part 3 - Post-processing on the Migrated System
BW Migration to HANA Part 3 - Post-processing on the Migrated System
Linh Nguyen
 
Lo extraction – part 5 sales and distribution (sd) datasource overview
Lo extraction – part 5  sales and distribution (sd) datasource overviewLo extraction – part 5  sales and distribution (sd) datasource overview
Lo extraction – part 5 sales and distribution (sd) datasource overview
JNTU University
 
SAP ChaRM and Retrofit
SAP ChaRM and Retrofit SAP ChaRM and Retrofit
SAP ChaRM and Retrofit
Mark Hansraj
 
S4HANA Migration Overview
S4HANA Migration OverviewS4HANA Migration Overview
S4HANA Migration Overview
Samir Lalani -CPA
 
Oracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data Streaming
Oracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data StreamingOracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data Streaming
Oracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data Streaming
Michael Rainey
 
The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...
The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...
The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...
NRB
 
S4 HANA presentation.pptx
S4 HANA presentation.pptxS4 HANA presentation.pptx
S4 HANA presentation.pptx
NiranjanPatro2
 
Hepsistream real time click-stream data analytics platform
Hepsistream real time click-stream  data analytics platformHepsistream real time click-stream  data analytics platform
Hepsistream real time click-stream data analytics platform
Hepsiburada
 
Data Warehouse Cloud - Das Ende von SAP BW?
Data Warehouse Cloud - Das Ende von SAP BW?Data Warehouse Cloud - Das Ende von SAP BW?
Data Warehouse Cloud - Das Ende von SAP BW?
ISR Information Products AG
 
Unifying Stream, SWL and CEP for Declarative Stream Processing with Apache Flink
Unifying Stream, SWL and CEP for Declarative Stream Processing with Apache FlinkUnifying Stream, SWL and CEP for Declarative Stream Processing with Apache Flink
Unifying Stream, SWL and CEP for Declarative Stream Processing with Apache Flink
DataWorks Summit/Hadoop Summit
 
Transition to SAP S/4HANA System Conversion: A step-by-step guide
Transition to SAP S/4HANA System Conversion: A step-by-step guide Transition to SAP S/4HANA System Conversion: A step-by-step guide
Transition to SAP S/4HANA System Conversion: A step-by-step guide
Kellton Tech Solutions Ltd
 

What's hot (20)

From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...
From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...
From Postgres to Event-Driven: using docker-compose to build CDC pipelines in...
 
BW Migration to HANA Part1 - Preparation in BW System
BW Migration to HANA Part1 - Preparation in BW SystemBW Migration to HANA Part1 - Preparation in BW System
BW Migration to HANA Part1 - Preparation in BW System
 
SAP Cloud Platform API Management Technical Brief
SAP Cloud Platform API Management Technical BriefSAP Cloud Platform API Management Technical Brief
SAP Cloud Platform API Management Technical Brief
 
Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...
Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...
Kafka error handling patterns and best practices | Hemant Desale and Aruna Ka...
 
Application Integration: EPM, ERP, Cloud and On-Premise – All options explained
Application Integration: EPM, ERP, Cloud and On-Premise – All options explainedApplication Integration: EPM, ERP, Cloud and On-Premise – All options explained
Application Integration: EPM, ERP, Cloud and On-Premise – All options explained
 
S4 h 188 sap s4hana cloud implementation with sap activate
S4 h 188 sap s4hana cloud implementation with sap activateS4 h 188 sap s4hana cloud implementation with sap activate
S4 h 188 sap s4hana cloud implementation with sap activate
 
SAP HANA SPS09 - Multitenant Database Containers
SAP HANA SPS09 - Multitenant Database ContainersSAP HANA SPS09 - Multitenant Database Containers
SAP HANA SPS09 - Multitenant Database Containers
 
SAP Cloud Platform - Integration, Extensibility & Services
SAP Cloud Platform - Integration, Extensibility & ServicesSAP Cloud Platform - Integration, Extensibility & Services
SAP Cloud Platform - Integration, Extensibility & Services
 
SAP BusinessObjects Private Cloud Edition (PCE)
SAP BusinessObjects Private Cloud Edition (PCE)SAP BusinessObjects Private Cloud Edition (PCE)
SAP BusinessObjects Private Cloud Edition (PCE)
 
BW Migration to HANA Part 3 - Post-processing on the Migrated System
BW Migration to HANA Part 3 - Post-processing on the Migrated SystemBW Migration to HANA Part 3 - Post-processing on the Migrated System
BW Migration to HANA Part 3 - Post-processing on the Migrated System
 
Lo extraction – part 5 sales and distribution (sd) datasource overview
Lo extraction – part 5  sales and distribution (sd) datasource overviewLo extraction – part 5  sales and distribution (sd) datasource overview
Lo extraction – part 5 sales and distribution (sd) datasource overview
 
SAP ChaRM and Retrofit
SAP ChaRM and Retrofit SAP ChaRM and Retrofit
SAP ChaRM and Retrofit
 
S4HANA Migration Overview
S4HANA Migration OverviewS4HANA Migration Overview
S4HANA Migration Overview
 
Oracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data Streaming
Oracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data StreamingOracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data Streaming
Oracle GoldenGate and Apache Kafka: A Deep Dive Into Real-Time Data Streaming
 
The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...
The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...
The NRB Group mainframe day 2021 - IBM Z-Strategy & Roadmap - Adam John Sturg...
 
S4 HANA presentation.pptx
S4 HANA presentation.pptxS4 HANA presentation.pptx
S4 HANA presentation.pptx
 
Hepsistream real time click-stream data analytics platform
Hepsistream real time click-stream  data analytics platformHepsistream real time click-stream  data analytics platform
Hepsistream real time click-stream data analytics platform
 
Data Warehouse Cloud - Das Ende von SAP BW?
Data Warehouse Cloud - Das Ende von SAP BW?Data Warehouse Cloud - Das Ende von SAP BW?
Data Warehouse Cloud - Das Ende von SAP BW?
 
Unifying Stream, SWL and CEP for Declarative Stream Processing with Apache Flink
Unifying Stream, SWL and CEP for Declarative Stream Processing with Apache FlinkUnifying Stream, SWL and CEP for Declarative Stream Processing with Apache Flink
Unifying Stream, SWL and CEP for Declarative Stream Processing with Apache Flink
 
Transition to SAP S/4HANA System Conversion: A step-by-step guide
Transition to SAP S/4HANA System Conversion: A step-by-step guide Transition to SAP S/4HANA System Conversion: A step-by-step guide
Transition to SAP S/4HANA System Conversion: A step-by-step guide
 

Similar to Principal Propagation with SAP Cloud Platform

The impact of SaaS on cloud integration
The impact of SaaS on cloud integrationThe impact of SaaS on cloud integration
The impact of SaaS on cloud integration
Codit
 
SAP Hana Cloud Platform - Development Landscape Planning
SAP Hana Cloud Platform - Development Landscape PlanningSAP Hana Cloud Platform - Development Landscape Planning
SAP Hana Cloud Platform - Development Landscape Planning
Nagesh Caparthy
 
Confluent Partner Tech Talk with Reply
Confluent Partner Tech Talk with ReplyConfluent Partner Tech Talk with Reply
Confluent Partner Tech Talk with Reply
confluent
 
SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...
SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...
SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...
Amazon Web Services
 
HP: Implementácia cloudu s HP
HP: Implementácia cloudu s HPHP: Implementácia cloudu s HP
HP: Implementácia cloudu s HP
ASBIS SK
 
Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...
Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...
Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...
Precisely
 
Lessons from Building Large-Scale, Multi-Cloud, SaaS Software at Databricks
Lessons from Building Large-Scale, Multi-Cloud, SaaS Software at DatabricksLessons from Building Large-Scale, Multi-Cloud, SaaS Software at Databricks
Lessons from Building Large-Scale, Multi-Cloud, SaaS Software at Databricks
Databricks
 
Confluent Partner Tech Talk with Synthesis
Confluent Partner Tech Talk with SynthesisConfluent Partner Tech Talk with Synthesis
Confluent Partner Tech Talk with Synthesis
confluent
 
UTF-8'en'IBM_Cloud_SCO_Content_20130702c
UTF-8'en'IBM_Cloud_SCO_Content_20130702cUTF-8'en'IBM_Cloud_SCO_Content_20130702c
UTF-8'en'IBM_Cloud_SCO_Content_20130702c
R.gowtham kumar
 
SAP ASCS on Kubernetes - A Proposal
SAP ASCS on Kubernetes - A ProposalSAP ASCS on Kubernetes - A Proposal
SAP ASCS on Kubernetes - A Proposal
Gary Jackson MBCS
 
Application Migrations at Scale AWS Summit SG 2017
Application Migrations at Scale AWS Summit SG 2017Application Migrations at Scale AWS Summit SG 2017
Application Migrations at Scale AWS Summit SG 2017
Amazon Web Services
 
CSA14_Congress%20Top_5%2075_Brokering_PPT
CSA14_Congress%20Top_5%2075_Brokering_PPTCSA14_Congress%20Top_5%2075_Brokering_PPT
CSA14_Congress%20Top_5%2075_Brokering_PPT
Jon-Michael C. Brook, CISSP
 
SAPonAzureCaseStudyMay2020.pptx
SAPonAzureCaseStudyMay2020.pptxSAPonAzureCaseStudyMay2020.pptx
SAPonAzureCaseStudyMay2020.pptx
Shashidhar Badisha B
 
Confluent_AWS_ImmersionDay_Q42023.pdf
Confluent_AWS_ImmersionDay_Q42023.pdfConfluent_AWS_ImmersionDay_Q42023.pdf
Confluent_AWS_ImmersionDay_Q42023.pdf
Ahmed791434
 
Build real-time streaming data pipelines to AWS with Confluent
Build real-time streaming data pipelines to AWS with ConfluentBuild real-time streaming data pipelines to AWS with Confluent
Build real-time streaming data pipelines to AWS with Confluent
confluent
 
Service-Level Objective for Serverless Applications
Service-Level Objective for Serverless ApplicationsService-Level Objective for Serverless Applications
Service-Level Objective for Serverless Applications
alekn
 
MuleSoft London Community October 2017 - Hybrid and SAP Integration
MuleSoft London Community October 2017 - Hybrid and SAP IntegrationMuleSoft London Community October 2017 - Hybrid and SAP Integration
MuleSoft London Community October 2017 - Hybrid and SAP Integration
Pace Integration
 
Cloudify 4.6 highlights webinar
Cloudify 4.6 highlights webinarCloudify 4.6 highlights webinar
Cloudify 4.6 highlights webinar
Cloudify Community
 
AWS Summit Nordics - Enterprise Apps on AWS
AWS Summit Nordics - Enterprise Apps on AWSAWS Summit Nordics - Enterprise Apps on AWS
AWS Summit Nordics - Enterprise Apps on AWS
Amazon Web Services
 
Enterprise Cloud Transformation
Enterprise Cloud TransformationEnterprise Cloud Transformation
Enterprise Cloud Transformation
Cloud Best Practices Network
 

Similar to Principal Propagation with SAP Cloud Platform (20)

The impact of SaaS on cloud integration
The impact of SaaS on cloud integrationThe impact of SaaS on cloud integration
The impact of SaaS on cloud integration
 
SAP Hana Cloud Platform - Development Landscape Planning
SAP Hana Cloud Platform - Development Landscape PlanningSAP Hana Cloud Platform - Development Landscape Planning
SAP Hana Cloud Platform - Development Landscape Planning
 
Confluent Partner Tech Talk with Reply
Confluent Partner Tech Talk with ReplyConfluent Partner Tech Talk with Reply
Confluent Partner Tech Talk with Reply
 
SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...
SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...
SAP on AWS: Big Businesses, Big Workloads, Big Time featuring Ingram-Micro - ...
 
HP: Implementácia cloudu s HP
HP: Implementácia cloudu s HPHP: Implementácia cloudu s HP
HP: Implementácia cloudu s HP
 
Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...
Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...
Using Mainframe Data in the Cloud: Design Once, Deploy Anywhere in a Hybrid W...
 
Lessons from Building Large-Scale, Multi-Cloud, SaaS Software at Databricks
Lessons from Building Large-Scale, Multi-Cloud, SaaS Software at DatabricksLessons from Building Large-Scale, Multi-Cloud, SaaS Software at Databricks
Lessons from Building Large-Scale, Multi-Cloud, SaaS Software at Databricks
 
Confluent Partner Tech Talk with Synthesis
Confluent Partner Tech Talk with SynthesisConfluent Partner Tech Talk with Synthesis
Confluent Partner Tech Talk with Synthesis
 
UTF-8'en'IBM_Cloud_SCO_Content_20130702c
UTF-8'en'IBM_Cloud_SCO_Content_20130702cUTF-8'en'IBM_Cloud_SCO_Content_20130702c
UTF-8'en'IBM_Cloud_SCO_Content_20130702c
 
SAP ASCS on Kubernetes - A Proposal
SAP ASCS on Kubernetes - A ProposalSAP ASCS on Kubernetes - A Proposal
SAP ASCS on Kubernetes - A Proposal
 
Application Migrations at Scale AWS Summit SG 2017
Application Migrations at Scale AWS Summit SG 2017Application Migrations at Scale AWS Summit SG 2017
Application Migrations at Scale AWS Summit SG 2017
 
CSA14_Congress%20Top_5%2075_Brokering_PPT
CSA14_Congress%20Top_5%2075_Brokering_PPTCSA14_Congress%20Top_5%2075_Brokering_PPT
CSA14_Congress%20Top_5%2075_Brokering_PPT
 
SAPonAzureCaseStudyMay2020.pptx
SAPonAzureCaseStudyMay2020.pptxSAPonAzureCaseStudyMay2020.pptx
SAPonAzureCaseStudyMay2020.pptx
 
Confluent_AWS_ImmersionDay_Q42023.pdf
Confluent_AWS_ImmersionDay_Q42023.pdfConfluent_AWS_ImmersionDay_Q42023.pdf
Confluent_AWS_ImmersionDay_Q42023.pdf
 
Build real-time streaming data pipelines to AWS with Confluent
Build real-time streaming data pipelines to AWS with ConfluentBuild real-time streaming data pipelines to AWS with Confluent
Build real-time streaming data pipelines to AWS with Confluent
 
Service-Level Objective for Serverless Applications
Service-Level Objective for Serverless ApplicationsService-Level Objective for Serverless Applications
Service-Level Objective for Serverless Applications
 
MuleSoft London Community October 2017 - Hybrid and SAP Integration
MuleSoft London Community October 2017 - Hybrid and SAP IntegrationMuleSoft London Community October 2017 - Hybrid and SAP Integration
MuleSoft London Community October 2017 - Hybrid and SAP Integration
 
Cloudify 4.6 highlights webinar
Cloudify 4.6 highlights webinarCloudify 4.6 highlights webinar
Cloudify 4.6 highlights webinar
 
AWS Summit Nordics - Enterprise Apps on AWS
AWS Summit Nordics - Enterprise Apps on AWSAWS Summit Nordics - Enterprise Apps on AWS
AWS Summit Nordics - Enterprise Apps on AWS
 
Enterprise Cloud Transformation
Enterprise Cloud TransformationEnterprise Cloud Transformation
Enterprise Cloud Transformation
 

More from Gary Jackson MBCS

SAP on Azure Web Dispatcher High Availability
SAP on Azure Web Dispatcher High AvailabilitySAP on Azure Web Dispatcher High Availability
SAP on Azure Web Dispatcher High Availability
Gary Jackson MBCS
 
Office 365 SaaS Mail Integration with SAP on Azure
Office 365 SaaS Mail Integration with SAP on AzureOffice 365 SaaS Mail Integration with SAP on Azure
Office 365 SaaS Mail Integration with SAP on Azure
Gary Jackson MBCS
 
OpenText Archive Server on Azure
OpenText Archive Server on AzureOpenText Archive Server on Azure
OpenText Archive Server on Azure
Gary Jackson MBCS
 
SAP OS/DB Migration using Azure Storage Account
SAP OS/DB Migration using Azure Storage AccountSAP OS/DB Migration using Azure Storage Account
SAP OS/DB Migration using Azure Storage Account
Gary Jackson MBCS
 
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
Gary Jackson MBCS
 
High Availability of SAP ASCS in Microsoft Azure
High Availability of SAP ASCS in Microsoft AzureHigh Availability of SAP ASCS in Microsoft Azure
High Availability of SAP ASCS in Microsoft Azure
Gary Jackson MBCS
 
Azure Custom Backup Solution for SAP NetWeaver
Azure Custom Backup Solution for SAP NetWeaverAzure Custom Backup Solution for SAP NetWeaver
Azure Custom Backup Solution for SAP NetWeaver
Gary Jackson MBCS
 
SAP Adaptive Computing Design
SAP Adaptive Computing DesignSAP Adaptive Computing Design
SAP Adaptive Computing Design
Gary Jackson MBCS
 
SAP LaMa Cloud Manager Azure
SAP LaMa Cloud Manager AzureSAP LaMa Cloud Manager Azure
SAP LaMa Cloud Manager Azure
Gary Jackson MBCS
 
SAP Host Agent x509 authentication
SAP Host Agent x509 authenticationSAP Host Agent x509 authentication
SAP Host Agent x509 authentication
Gary Jackson MBCS
 
SAP LVM Integration with SAP BPA
SAP LVM Integration with SAP BPASAP LVM Integration with SAP BPA
SAP LVM Integration with SAP BPA
Gary Jackson MBCS
 
SAP LVM Post Copy Automation Integration
SAP LVM Post Copy Automation IntegrationSAP LVM Post Copy Automation Integration
SAP LVM Post Copy Automation Integration
Gary Jackson MBCS
 
SAP LVM Customer Operations
SAP LVM Customer OperationsSAP LVM Customer Operations
SAP LVM Customer Operations
Gary Jackson MBCS
 
SAP Router Installation with SNC
SAP Router Installation with SNCSAP Router Installation with SNC
SAP Router Installation with SNC
Gary Jackson MBCS
 
SAP LVM Customer Instances
SAP LVM Customer InstancesSAP LVM Customer Instances
SAP LVM Customer Instances
Gary Jackson MBCS
 
SAP ASE Migration Lessons Learned
SAP ASE Migration Lessons LearnedSAP ASE Migration Lessons Learned
SAP ASE Migration Lessons Learned
Gary Jackson MBCS
 
SAP Rolling Kernel Switch RKS
SAP Rolling Kernel Switch RKSSAP Rolling Kernel Switch RKS
SAP Rolling Kernel Switch RKS
Gary Jackson MBCS
 
SAP Post Copy Automation
SAP Post Copy AutomationSAP Post Copy Automation
SAP Post Copy Automation
Gary Jackson MBCS
 
SAP Web Dispatcher - Best Bits
SAP Web Dispatcher - Best BitsSAP Web Dispatcher - Best Bits
SAP Web Dispatcher - Best Bits
Gary Jackson MBCS
 

More from Gary Jackson MBCS (19)

SAP on Azure Web Dispatcher High Availability
SAP on Azure Web Dispatcher High AvailabilitySAP on Azure Web Dispatcher High Availability
SAP on Azure Web Dispatcher High Availability
 
Office 365 SaaS Mail Integration with SAP on Azure
Office 365 SaaS Mail Integration with SAP on AzureOffice 365 SaaS Mail Integration with SAP on Azure
Office 365 SaaS Mail Integration with SAP on Azure
 
OpenText Archive Server on Azure
OpenText Archive Server on AzureOpenText Archive Server on Azure
OpenText Archive Server on Azure
 
SAP OS/DB Migration using Azure Storage Account
SAP OS/DB Migration using Azure Storage AccountSAP OS/DB Migration using Azure Storage Account
SAP OS/DB Migration using Azure Storage Account
 
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
 
High Availability of SAP ASCS in Microsoft Azure
High Availability of SAP ASCS in Microsoft AzureHigh Availability of SAP ASCS in Microsoft Azure
High Availability of SAP ASCS in Microsoft Azure
 
Azure Custom Backup Solution for SAP NetWeaver
Azure Custom Backup Solution for SAP NetWeaverAzure Custom Backup Solution for SAP NetWeaver
Azure Custom Backup Solution for SAP NetWeaver
 
SAP Adaptive Computing Design
SAP Adaptive Computing DesignSAP Adaptive Computing Design
SAP Adaptive Computing Design
 
SAP LaMa Cloud Manager Azure
SAP LaMa Cloud Manager AzureSAP LaMa Cloud Manager Azure
SAP LaMa Cloud Manager Azure
 
SAP Host Agent x509 authentication
SAP Host Agent x509 authenticationSAP Host Agent x509 authentication
SAP Host Agent x509 authentication
 
SAP LVM Integration with SAP BPA
SAP LVM Integration with SAP BPASAP LVM Integration with SAP BPA
SAP LVM Integration with SAP BPA
 
SAP LVM Post Copy Automation Integration
SAP LVM Post Copy Automation IntegrationSAP LVM Post Copy Automation Integration
SAP LVM Post Copy Automation Integration
 
SAP LVM Customer Operations
SAP LVM Customer OperationsSAP LVM Customer Operations
SAP LVM Customer Operations
 
SAP Router Installation with SNC
SAP Router Installation with SNCSAP Router Installation with SNC
SAP Router Installation with SNC
 
SAP LVM Customer Instances
SAP LVM Customer InstancesSAP LVM Customer Instances
SAP LVM Customer Instances
 
SAP ASE Migration Lessons Learned
SAP ASE Migration Lessons LearnedSAP ASE Migration Lessons Learned
SAP ASE Migration Lessons Learned
 
SAP Rolling Kernel Switch RKS
SAP Rolling Kernel Switch RKSSAP Rolling Kernel Switch RKS
SAP Rolling Kernel Switch RKS
 
SAP Post Copy Automation
SAP Post Copy AutomationSAP Post Copy Automation
SAP Post Copy Automation
 
SAP Web Dispatcher - Best Bits
SAP Web Dispatcher - Best BitsSAP Web Dispatcher - Best Bits
SAP Web Dispatcher - Best Bits
 

Recently uploaded

Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j
 
DDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systemsDDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systems
Gerardo Pardo-Castellote
 
E-commerce Application Development Company.pdf
E-commerce Application Development Company.pdfE-commerce Application Development Company.pdf
E-commerce Application Development Company.pdf
Hornet Dynamics
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
Łukasz Chruściel
 
socradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdfsocradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdf
SOCRadar
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate
 
ALGIT - Assembly Line for Green IT - Numbers, Data, Facts
ALGIT - Assembly Line for Green IT - Numbers, Data, FactsALGIT - Assembly Line for Green IT - Numbers, Data, Facts
ALGIT - Assembly Line for Green IT - Numbers, Data, Facts
Green Software Development
 
Hand Rolled Applicative User Validation Code Kata
Hand Rolled Applicative User ValidationCode KataHand Rolled Applicative User ValidationCode Kata
Hand Rolled Applicative User Validation Code Kata
Philip Schwarz
 
Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
Deuglo Infosystem Pvt Ltd
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
NYGGS Automation Suite
 
What is Augmented Reality Image Tracking
What is Augmented Reality Image TrackingWhat is Augmented Reality Image Tracking
What is Augmented Reality Image Tracking
pavan998932
 
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdfVitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke
 
SWEBOK and Education at FUSE Okinawa 2024
SWEBOK and Education at FUSE Okinawa 2024SWEBOK and Education at FUSE Okinawa 2024
SWEBOK and Education at FUSE Okinawa 2024
Hironori Washizaki
 
OpenMetadata Community Meeting - 5th June 2024
OpenMetadata Community Meeting - 5th June 2024OpenMetadata Community Meeting - 5th June 2024
OpenMetadata Community Meeting - 5th June 2024
OpenMetadata
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
Drona Infotech
 
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling ExtensionsUI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
Peter Muessig
 
GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
Green Software Development
 
LORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptx
LORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptxLORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptx
LORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptx
lorraineandreiamcidl
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Łukasz Chruściel
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
Fermin Galan
 

Recently uploaded (20)

Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit ParisNeo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
Neo4j - Product Vision and Knowledge Graphs - GraphSummit Paris
 
DDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systemsDDS-Security 1.2 - What's New? Stronger security for long-running systems
DDS-Security 1.2 - What's New? Stronger security for long-running systems
 
E-commerce Application Development Company.pdf
E-commerce Application Development Company.pdfE-commerce Application Development Company.pdf
E-commerce Application Development Company.pdf
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
 
socradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdfsocradar-q1-2024-aviation-industry-report.pdf
socradar-q1-2024-aviation-industry-report.pdf
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
 
ALGIT - Assembly Line for Green IT - Numbers, Data, Facts
ALGIT - Assembly Line for Green IT - Numbers, Data, FactsALGIT - Assembly Line for Green IT - Numbers, Data, Facts
ALGIT - Assembly Line for Green IT - Numbers, Data, Facts
 
Hand Rolled Applicative User Validation Code Kata
Hand Rolled Applicative User ValidationCode KataHand Rolled Applicative User ValidationCode Kata
Hand Rolled Applicative User Validation Code Kata
 
Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
 
What is Augmented Reality Image Tracking
What is Augmented Reality Image TrackingWhat is Augmented Reality Image Tracking
What is Augmented Reality Image Tracking
 
Vitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdfVitthal Shirke Java Microservices Resume.pdf
Vitthal Shirke Java Microservices Resume.pdf
 
SWEBOK and Education at FUSE Okinawa 2024
SWEBOK and Education at FUSE Okinawa 2024SWEBOK and Education at FUSE Okinawa 2024
SWEBOK and Education at FUSE Okinawa 2024
 
OpenMetadata Community Meeting - 5th June 2024
OpenMetadata Community Meeting - 5th June 2024OpenMetadata Community Meeting - 5th June 2024
OpenMetadata Community Meeting - 5th June 2024
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
 
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling ExtensionsUI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
UI5con 2024 - Boost Your Development Experience with UI5 Tooling Extensions
 
GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
 
LORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptx
LORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptxLORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptx
LORRAINE ANDREI_LEQUIGAN_HOW TO USE WHATSAPP.pptx
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
 
Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604Orion Context Broker introduction 20240604
Orion Context Broker introduction 20240604
 

Principal Propagation with SAP Cloud Platform

  • 1. Principal  Propagation  with  SAP  Cloud  Platform
  • 2. Automation  Core • Technology  improvements  mean  computing  tasks  previously  requiring  interaction  with  people,  can  be  fully  automated. • Automation  brings  repeatability,  reduced  error  rates,  easy  scalability  of  service  provision. Platform  Agnostic • Future  interoperability  and  open  standards  will  mean  businesses   can  swap  easily  between  cloud  providers. • It  is  key  that  solutions   are  designed  to  operate  in  such  a  platform  agnostic  manner  outside  the  bounds  of  normal   technical  architecture  design  (i.e.  no  fixed  O/S  choices  or  fixed  DB  platforms). Established  Technological  Principals • Solutions   today,  should   be  built  using  already  established  technological  principals. • Using  bleeding  edge  rarely  produces  the  perceived  benefits  in  places  such  as  core  business   systems,  without  significant   buy-­‐in  from  business   leaders. • Pre-­‐empting  standards  not  already  widely  adopted,  could  produce  a  “Beta-­‐Max”  scenario. Future  Assurance • Technology  solutions  should  deliver  for  a  minimum  timeframe  within  the  context  of  the  lifecycle  of  the  related  business  system. • Example:  Re-­‐writing  scripts  during  any  platform  migration  should  not  just  use  the  coolest  scripting  language,  they  should  use  a  commonly   known  language  widely  used  and  understood. Drivers
  • 3. • Permits  federated   authentication  (single-­‐sign-­‐on)   into  customer  SAP  systems   via  an  IdP such  as  SAP  IDM. • Authentication  to  on-­‐premise   SAP  IDM  is  possible. • Subsequent   SAP  system  can  authenticate   against  the  IDM  generated  SAP  logon   ticket  (MYSAPSSO2  cookie)  or  SAML2  token. • SAP  Cloud  Platform  (SCP)  users  (S-­‐users)   can  use  SAP  Cloud  Platform  services   such  as  Web  IDE,  authenticating  into  the  customer  SAP  systems  against  their   respective   SAP  system  account  in  the  IdP (usually  their  corporate  identity). About  Principal  Propagation
  • 4. • SAP  Cloud  Platform  a.k.a.  SCP  (previously   called  SAP  HANA  Cloud). • A  PaaS  set  of  tools,  utilities  and  cloud  capabilities  for  use  with  SAP  and  non-­‐ SAP  products,  all  provided  in  the  cloud. • Accessed   over  the  internet. • Is  the  future  of  SAP  software   integration  and  will  provide  the  basis  for  many   SAP  SaaS  applications  also. • Can  be  accessed   from  “on-­‐premise”   (or  your  cloud  provider)   using  the  SAP   Cloud  Connector  (SCC),  which  acts  as  a  reverse   proxy.   About  SAP  Cloud  Platform
  • 5. SCP SAP  Cloud  Platform   Developer  with  S-­‐user   account. Destinations: BE1:1234 SAP  Cloud  Connector Sub-­‐ Account:  ABC123 BE1:1234  =   https://be1.corp Trust  Store CA  Cert System  Cert BE1  SSL  Cert  Chain Cloud “On-­‐Premise”  (Cloud  be   cloud  hosted  IaaS) IdP (SAP  IDM) UME Developer  corporate   identity  and  account. BE1  – SAP (https://be1.corp) Optional Web  Dispatcher Trust  Store SCC  CA  Cert Target  ICF  Service ICM  (+Web  Dispatcher)  Parameters: login/certificate_mapping_rulebased=”1“ icm/trusted_reverse_proxy_0=<SCC  System  CA> icm/HTTPS/verify_client=1 ICM Trust  Store SCC  CA  Cert SSL HTTP  HEADER SCC  Cert   Chain x.509 Client  Cert SAML   Token Customise: STRUST CERTRULE RZ10 Wdisp SSL  Chain Architecture  Overview
  • 6. SCP: • Create  S-­‐user  account(s). • Create  destination  to  back-­‐end  SAP  system  via  SCC  with  Principal  Propagation  enabled  and  pointing  to  your  IdP. IdP: • SAML:  Configure  SAML  token  creation  for  SCP  users  after  authentication. SCC: • Sub-­‐Account:  Register  SCP  sub-­‐accounts  for  incoming  connections  from  SCP. • On-­‐Premise:  Configure  trust  store  with  back-­‐end  SAP  system  SSL  server  cert  and  optional  Web  Disp SSL  cert. • On-­‐Premise:  Configure  Principal  Propagation  user  x.509  client  cert  creation  upon  SAML  token  receipt. BE1: • ICM:  Transaction  STRUST  to  trust  the  SCC  client  x.509  cert. • AUTH:  Transaction  CERTRULE  to  map  SCC  dynamic  x.509  client  cert  CN  to  SAP  system  user  accounts. • ICM:  Transaction  RZ10  to  configure  ICM  params to  enable  trusting  of  client  x.509  certs  forwarded  in  HTTP   header. Optional  Web  Dispatcher: • ICM:  Adding  SCC  client  x.509  cert  to  the  SAPSSLS  PSE. • ICM:  DEFAULT.PFL  to  configure  ICM  params to  enable  trusting  of  client  x.509  certs  forwarded  in  HTTP  header. Areas  for  Configuration
  • 7. • Principal  Propagation  should  enable  smooth  efficient   access  to  back-­‐end  SAP   systems  via  the  SAP  Cloud  Connector   from  the  SAP  Cloud  Platform. • A  secure  setup  is  always  recommended,   paying  attention  to  SAP   recommendations   for  the  SCC  networking  and  HA. • The  future  direction  of  SAP  integration  will  need  to  use  the  SCC  more  and   more.    Example:  SAP  Analytics  Coud. • The  Principal  Propagation  trust  setup  is  complex  and  involves  multiple   certificates,   leaving  you  open  to  the  probability  of  certificate  expiration   causing  an  outage. Summary
  • 8. SAP  Notes: • SAP  note  2462533  -­‐ Configuring  Principal  Propagation  to  an  ABAP  System. • SAP  note  2052899  -­‐ ICM  -­‐ Multiple  Trusted  Reverse   Proxies • SAP  note  2461375  -­‐ How  to  connect  SAP  Cloud  Platform  Identity   Authentication  Service   to  on-­‐premise   user  store SAP  Guides: • SCC  secure   setup  recommendations: https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-­‐ US/e7ea82a4bb571014a4ceb61cb7e3d31f.html • Configure  Principal  Propagation  for  an  ABAP  system: https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-­‐ US/a8bb87a72d094e0d981d2b1f67df7bc3.html References