Home > SAP software/management Tips > SAP ABAP/Java developer tips > Synchronizing SAP with an external user registry
SAP Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SAP ABAP/JAVA DEVELOPER TIPS

Synchronizing SAP with an external user registry


Austin Sincock
12.01.2003
Rating: -3.92- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The ever-growing exposure of SAP to the Internet, coupled with the frequency and violence of hacker attacks, means that more and more BASIS administrators are taking an active role in extranet security. One of the greatest challenges in any mixed IT environment is the ability to maintain a single source of record for a company's user registry.

So why do you care about a single user registry? As more companies expose internal systems to the Internet, managing individual user identities across a disparate environment becomes paramount. For many companies, the advantage to productivity far outweighs the risk, but these risks must be adequately assessed and dealt with before moving heavily onto the Internet.

One of the greatest risks to multiple identities for the same user is simply that of being able to track down and turn off that user should they leave the company. Suppose an employee quit, the email account shut down, file-system access revoked, but someone forgot to shut the employee down in SAP. Once this company exposes any aspect of SAP to the Internet, the former employee just might be able to get into the system, because he's still a functioning named user.

The easiest way to mitigate this risk is to provide a single user registry that every back office system must synchronize with. That way, the user must only be turned off in this user registry, which causes all of their system logons to be shutdown. Unfortunately, SAP has not always made this task a simple one. It is only with the release of the Web Application Server 6.10 that an SAP application server can sychronize transparently with an external user registry.

One of the most common user registries is a directory services database called LDAP. LDAP stands for Lightweight Directory Access Protocol, and provides a straightforward implementation of services targeted specifically at maintaining users. You can even download a free, commercial LDAP server from IBM, called IBM Directory Server.

Many other back office applications can sychronize with an LDAP directory server. You can even build front-end authentication schemes based on user data within LDAP. Web servers, such as Apache, provide native authentication support using LDAP and OS level authentication.

To synchronize SAP with an LDAP server, start by creating a new RFC destination for the LDAP connector. This allows SAP to reach the LDAP server via its standard ABAP applications. Once configured, go to the SAP transaction "LDAP".

Here you configure the actual LDAP connector, including the physical server address of the LDAP host and test the LDAP connector. Once that is complete, you must extend the LDAP schema in the directory server to include the additional fields required for an authorized SAP user.

The next step is to map the user fields to those appropriate within the LDAP directory. Again, this function takes places in transaction LDAP. The final step is to configure how SAP pulls/pushes data to the server then execute the synchronization process.

Of course, this tip is not meant to be a comprehensive review of the SAP/LDAP configuration. Rather, I hope that it has given you some good ideas regarding single user registries and gotten you thinking about how your company could use directory services. Do a search over at http://help.sap.com on "LDAP" for a step-by-step walkthrough of LDAP synchronization. With LDAP part of standard WAS 6.10 and IBM's FREE LDAP Directory Server, you can get started today with a single user registry for you entire company.

Author Austin Sincock is a freelance Java/SAP consultant who contributes regularly to Web and print journals. He can be reached at austin@opensourceguru.com. Check out his book Enterprise Java for SAP

Rate this Tip
To rate tips, you must be a member of SearchSAP.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SAP ABAP/Java developer tips
How to do additional dialog processing after SAP COMMIT WORK statement
How to find a piece of SAP ABAP code without debugging
How to read an SAP transaction in an ABAP code
How to provide an SAP R/3 4.5B application server with a Web service interface
How to find owners and transports of deleted ABAP programs
Fixing a common OPEN_FORM and START_FORM error in SAPscript
Select Text fields: Case-insensitive
Is this the quickest way to find a BADI?
Easily debug error messages in SAP processes
Accessing private attributes in ABAP Objects

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



NetWeaver SAP White Papers
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
SearchSAP.com is a search service provided by TechTarget and is completely
independent of and not affiliated with SAP AG.
  TechTarget - The IT Media ROI Experts