ADM960. SAP NetWeaver Application Server Security COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)

Similar documents
ADM960. SAP NetWeaver Application Server Security COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day

ADM950. Secure SAP System Management COURSE OUTLINE. Course Version: 10 Course Duration: 2 Day(s)

ADM900 SAP System Security Fundamentals

BIT460. SAP Process Integration Message Mapping COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

BC100. Introduction to Programming with ABAP COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

EWM125. Labor Management in SAP EWM COURSE OUTLINE. Course Version: 16 Course Duration: 4 Hours

PLM210. Master Data Configuration in SAP Project System COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

AC507. Additional Functions of Product Cost Planning COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

ADM100 AS ABAP - Administration

ADM950. Secure SAP System Management COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

MDG100 Master Data Governance

BC430 ABAP Dictionary

BC410. Programming User Dialogs with Classical Screens (Dynpros) COURSE OUTLINE. Course Version: 10 Course Duration: 3 Day(s)

DS50. Managing Data Quality with SAP Information Steward COURSE OUTLINE. Course Version: 10 Course Duration: 2 Day(s)

NET311. Advanced Web Dynpro for ABAP COURSE OUTLINE. Course Version: 10 Course Duration: 4 Day(s)

DEV523 Customizing and Extending PowerDesigner

BOCE20. SAP Crystal Reports for Enterprise: Advanced Report Design COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

BOC320. SAP Crystal Reports - Business Reporting and Report Processing Strategies COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

BC490 ABAP Performance Tuning

ADM920 SAP Identity Management

BC480 PDF-Based Print Forms

BC405 Programming ABAP Reports

BC400 Introduction to the ABAP Workbench

EDB367. Powering Up with SAP Adaptative Server Enterprise 15.7 COURSE OUTLINE. Course Version: 10 Course Duration: 2 Day(s)

EDB785 SAP IQ Administration

BC404. ABAP Programming in Eclipse COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

BOC310. SAP Crystal Reports: Fundamentals of Report Design COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)

TBIT44 PI Mapping and ccbpm

EDB358. System and Database Administration: Adaptive Server Enterprise COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)

HA150 SQL Basics for SAP HANA

AFA461 SAP Afaria 7.0 System Administration (SP03)

BC400. ABAP Workbench Foundations COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

EP200. SAP NetWeaver Portal: System Administration COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)

GRC100. GRC Principles and Harmonization COURSE OUTLINE. Course Version: 10 Course Duration: 2 Day(s)

EDB116. Fast Track to SAP Adaptive Server Enterprise COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

EP350. Innovated Content Management and Collaboration COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)

BW310. BW - Enterprise Data Warehousing COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)

EDB377. Fast Track to SAP Replication Server Administration COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

TBIT40 SAP NetWeaver Process Integration

SMP541. SAP Mobile Platform 3.0 Native and Hybrid Application Development COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

BC401. ABAP Objects COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

SMP521. SAP Mobile Platform - Native and Hybrid Application Development COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)

TBW60. BW: Operations and Performance COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)

Single Sign-on For SAP NetWeaver Mobile PDA Client

NET312. UI Development with Web Dynpro for ABAP COURSE OUTLINE. Course Version: 10 Course Duration: 4 Day(s)

Duet Enterprise: Tracing Reports in SAP, SCL, and SharePoint

SAP NetWeaver Identity Management Identity Center Minimum System Requirements

TBW30 SAP BW Modeling & Implementation

How to Enable Single Sign-On for Mobile Devices?

HA200 SAP HANA Installation & Operations SPS10

SAP AddOn Quantity Distribution. by Oliver Köhler, SAP Germany

SAP BusinessObjects Predictive Analysis 1.0 Supported Platforms

How to Handle the System Message in SAP NetWeaver Mobile 7.1

Manual Activities of SAP Note Globalization Services, 2012/06/05

Configuring relay server in Sybase Control Center

How to Find Suitable Enhancements in SAP Standard Applications

Duplicate Check and Fuzzy Search for Accounts and Contacts. Configuration with SAP NetWeaver Search and Classification (TREX) in SAP CRM WebClient UI

Visual Composer Modeling: Data Validation in the UI

Crystal Reports 2008 FixPack 2.4 Known Issues and Limitations

Quick View Insider Microblog: Why Is There No Inbox?

Enterprise Search Extension for SAP Master Data Governance

How to reuse BRFplus Functions Similar to R/3 Function Modules using BRF+ Expression Type Function Call

Visual Composer for SAP NetWeaver Composition Environment - Connectors

How to Download Software and Address Directories in SAP Service Marketplace

Message Alerting for SAP NetWeaver PI Advanced Adapter Engine Extended

Testing Your New Generated SAP NetWeaver Gateway Service

SAP Afaria Post- Installation Part 1

Quick View Insider: Understanding Quick View Configuration

Visual Composer Modeling: Migrating Models from 7.1.X to 7.2.0

Installing SAP NetWeaver Mobile Client (eswt) on a Storage Card

How to Set Up Data Sources for Crystal Reports Layouts in SAP Business One, Version for SAP HANA

How to Work with Analytical Portal

Quick View Insider: How Can I Change the Colors? (SNC 7.0)

BW Text Variables of Type Replacement Path

SAP Plant Connectivity 2.2

How to Guide to create Sample Application in IOS using SUP ODP 2.2

Using JournalEntries and JournalVouchers Objects in SAP Business One 6.5

Using Default Values in Backend Adapter

Architecture of the SAP NetWeaver Application Server

Visual Composer s Control Types

How to Check or Derive an Attribute Value in MDG using BRFPlus

SAP ME Build Tool 6.1

SAP BusinessObjects Dashboards 4.0 SAP Crystal Dashboard Design 2011 SAP Crystal Presentation Design 2011

Upgrade MS SQL 2005 to MS SQL 2008 (R2) for Non-High-Availability NW Mobile ABAP System

Quality Inspection Engine (QIE) Security Guide

LO Extraction - Part 6 Implementation Methodology

Quick View Insider: How Do I Set Quick View as SNC s Entry Screen?

Web Dynpro: Column Coloring in ALV

The Dbmlsync API. A whitepaper from Sybase ianywhere Author: Joshua Savill, Product Manager Date: October 30 th, 2008

Obtain Configuration Parameters for LPD_CUST Provide the base path of your BSP application (1/2)

Working with Data Sources in the SAP Business One UI API

Remote Monitoring User for IBM DB2 for LUW

How to Package and Deploy SAP Business One Extensions for Lightweight Deployment

Business Reasons For Mobilizing Oracle Databases Using SQL Anywhere. A whitepaper from Sybase ianywhere

Business Objects Integration Scenario 2

Building a Real-time Dashboard using Xcelsius and Data Integrator

Extending DME Transfer Files According to Spanish Banking Control Council to Support Non- Euro Payments

What s New / Release Notes SAP Strategy Management 10.1

July, SAP Crystal Reports 2011 SP04 Product Availability Matrix (PAM)

How to Set Up and Use Electronic Tax Reporting

Transcription:

ADM960 SAP NetWeaver Application Server Security. COURSE OUTLINE Course Version: 10 Course Duration: 5 Day(s)

SAP Copyrights and Trademarks 2013 SAP AG. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. Microsoft, Windows, Excel, Outlook, and PowerPoint are registered trademarks of Microsoft Corporation. IBM, DB2, DB2 Universal Database, System i, System i5, System p, System p5, System x, System z, System z10, System z9, z10, z9, iseries, pseries, xseries, zseries, eserver, z/vm, z/os, i5/os, S/390, OS/390, OS/400, AS/400, S/390 Parallel Enterprise Server, PowerVM, Power Architecture, POWER6+, POWER6, POWER5+, POWER5, POWER, OpenPower, PowerPC, BatchPipes, BladeCenter, System Storage, GPFS, HACMP, RETAIN, DB2 Connect, RACF, Redbooks, OS/2, Parallel Sysplex, MVS/ESA, AIX, Intelligent Miner, WebSphere, Netfinity, Tivoli and Informix are trademarks or registered trademarks of IBM Corporation. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries. Adobe, the Adobe logo, Acrobat, PostScript, and Reader are either trademarks or registered trademarks of Adobe Systems Incorporated in the United States and/or other countries. Oracle is a registered trademark of Oracle Corporation UNIX, X/Open, OSF/1, and Motif are registered trademarks of the Open Group. Citrix, ICA, Program Neighborhood, MetaFrame, WinFrame, VideoFrame, and MultiWin are trademarks or registered trademarks of Citrix Systems, Inc. HTML, XML, XHTML and W3C are trademarks or registered trademarks of W3C, World Wide Web Consortium, Massachusetts Institute of Technology. Java is a registered trademark of Sun Microsystems, Inc. JavaScript is a registered trademark of Sun Microsystems, Inc., used under license for technology invented and implemented by Netscape. SAP, R/3, SAP NetWeaver, Duet, PartnerEdge, ByDesign, SAP BusinessObjects Explorer, StreamWork, and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries. Business Objects and the Business Objects logo, BusinessObjects, Crystal Reports, Crystal Decisions, Web Intelligence, Xcelsius, and other Business Objects products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of Business Objects Software Ltd. Business Objects is an SAP company. Sybase and Adaptive Server, ianywhere, Sybase 365, SQL Anywhere, and other Sybase products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of Sybase, Inc. Sybase is an SAP company.

All other product and service names mentioned are the trademarks of their respective companies. Data contained in this document serves informational purposes only. National product specifications may vary. These materials are subject to change without notice. These materials are provided by SAP AG and its affiliated companies ("SAP Group") for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. Copyright. All rights reserved. iii

iv Copyright. All rights reserved.

About This Handbook This handbook is intended to complement the instructor-led presentation of this course, and serve as a source of reference. It is not suitable for self-study. Typographic Conventions American English is the standard used in this handbook. The following typographic conventions are also used. This information is displayed in the instructor s presentation Demonstration Procedure Warning or Caution Hint Related or Additional Information Facilitated Discussion User interface control Example text Window title Example text Copyright. All rights reserved. v

vi Copyright. All rights reserved.

Contents ix Course Overview 1 Unit 1: Computer Security Overview 1 Lesson: Analyzing Security Threats 1 Lesson: Evaluating the SAP System Environment 3 Unit 2: Network Basics 3 Lesson: Describing the Basics of Networks 3 Lesson: Determining the Key Points of Network Security 3 Lesson: Installing and Configuring SAProuter 3 Lesson: Installing and Configuring the SAP Web Dispatcher 5 Unit 3: Basic Security for SAP Systems 5 Lesson: Securing the Front End 5 Lesson: Setting Up User Security in SAP Systems 5 Lesson: Defining Authorizations in SAP Systems 5 Lesson: Setting Up Interface Security in SAP Systems 6 Lesson: Providing Development Protection and Applying Security Patches 6 Lesson: Monitoring SAP Systems 6 Lesson: Monitoring and Analyzing Security with SAP Solution Manager 7 Unit 4: Introduction to Cryptography 7 Lesson: Evaluating Cryptography for Security 7 Lesson: Evaluating Authentication and Digital Signatures for Security 7 Lesson: Applying Cryptography in SAP Systems 9 Unit 5: Secure Network Communication (SNC) 9 Lesson: Setting up Secure Network Communication (SNC) 11 Unit 6: Secure Socket Layer (SSL) 11 Lesson: Enabling Secure Socket Layer with SAP NetWeaver AS 11 Lesson: Enabling Secure Socket Layer (SSL) on the SAP NetWeaver AS ABAP 11 Lesson: Enabling Secure Socket Layer (SSL) on SAP NetWeaver AS Java 11 Lesson: Enabling Secure Socket Layer (SSL) on SAP Web Dispatcher and SAP Management Console Copyright. All rights reserved. vii

13 Unit 7: Authentication and Single Sign-On (SSO) Mechanisms in SAP Systems 13 Lesson: Evaluating SAP System Authentications 13 Lesson: Enabling Session Security 13 Lesson: Using Single Sign-On (SSO) viii Copyright. All rights reserved.

Course Overview TARGET AUDIENCE This course is intended for the following audiences: Technology Consultant Project Manager Systems Architect System Administrator Copyright. All rights reserved. ix

x Copyright. All rights reserved.

UNIT 1 Computer Security Overview Lesson 1: Analyzing Security Threats Analyze security threats and safeguards Lesson 2: Evaluating the SAP System Environment Identify the components of SAP Business Suite Evaluate the SAP NetWeaver Application Server (SAP NetWeaver AS) architecture Copyright. All rights reserved. 1

Unit 1: Computer Security Overview 2 Copyright. All rights reserved.

UNIT 2 Network Basics Lesson 1: Describing the Basics of Networks Describe network communication in the SAP environment Lesson 2: Determining the Key Points of Network Security Describe the important topics of network security in an SAP landscape Lesson 3: Installing and Configuring SAProuter Install and configure SAProuter Lesson 4: Installing and Configuring the SAP Web Dispatcher Install and configure the SAP Web Dispatcher using a dedicated port Copyright. All rights reserved. 3

Unit 2: Network Basics 4 Copyright. All rights reserved.

UNIT 3 Basic Security for SAP Systems Lesson 1: Securing the Front End Configure security features of SAP GUI for Windows Lesson 2: Setting Up User Security in SAP Systems Deal with the tools for user administration Name standard users Recognize different user types Lesson 3: Defining Authorizations in SAP Systems Explain authorizations in SAP systems Manage passwords in SAP systems Securely store user and password information Configure password parameters Lesson 4: Setting Up Interface Security in SAP Systems Secure Remote Function Call (RFC) communication Ensure SAP Gateway security Secure Internet Communication Manager (ICM) Ensure SAP Message Server security Copyright. All rights reserved. 5

Unit 3: Basic Security for SAP Systems Establish interface security Lesson 5: Providing Development Protection and Applying Security Patches Protect development Apply security patches Lesson 6: Monitoring SAP Systems Explore the various options of security configuration monitoring Use the security audit log Use other monitoring tools Understand the security audit logs and reports Lesson 7: Monitoring and Analyzing Security with SAP Solution Manager Obtain a landscape-wide overview of the security configuration 6 Copyright. All rights reserved.

UNIT 4 Introduction to Cryptography Lesson 1: Evaluating Cryptography for Security Evaluate cryptography for security Understand encryption Lesson 2: Evaluating Authentication and Digital Signatures for Security Evaluate the basic concepts of digital certificates and digital signatures Lesson 3: Applying Cryptography in SAP Systems Apply cryptography in SAP systems Copyright. All rights reserved. 7

Unit 4: Introduction to Cryptography 8 Copyright. All rights reserved.

UNIT 5 Secure Network Communication (SNC) Lesson 1: Setting up Secure Network Communication (SNC) Secure Dynamic Information and Action Gateway (DIAG) and Remote Function Call (RFC) communication Copyright. All rights reserved. 9

Unit 5: Secure Network Communication (SNC) 10 Copyright. All rights reserved.

UNIT 6 Secure Socket Layer (SSL) Lesson 1: Enabling Secure Socket Layer with SAP NetWeaver AS Use Secure Socket Layer (SSL) on SAP NetWeaver AS Lesson 2: Enabling Secure Socket Layer (SSL) on the SAP NetWeaver AS ABAP Enable Secure Socket Layer (SSL) on the SAP NetWeaver AS ABAP Lesson 3: Enabling Secure Socket Layer (SSL) on SAP NetWeaver AS Java Enable Secure Socket Layer (SSL) on SAP NetWeaver AS Java Lesson 4: Enabling Secure Socket Layer (SSL) on SAP Web Dispatcher and SAP Management Console Enable Secure Socket Layer (SSL) on the SAP Web Dispatcher Enable Secure Socket Layer (SSL) for SAP Management Console Copyright. All rights reserved. 11

Unit 6: Secure Socket Layer (SSL) 12 Copyright. All rights reserved.

UNIT 7 Authentication and Single Sign- On (SSO) Mechanisms in SAP Systems Lesson 1: Evaluating SAP System Authentications Describe authentication mechanisms Configure Application Server ABAP (AS ABAP) for usage of logon tickets Configure Application Server Java (AS Java) for usage of logon tickets Use X.509 client certificates Use Security Assertion Markup Language (SAML) for authentication Lesson 2: Enabling Session Security Enable session security Lesson 3: Using Single Sign-On (SSO) Use Single Sign-On (SSO) for SAP systems Copyright. All rights reserved. 13