Knowledge Article

SAP Secure Network Communication (SNC) For SAP Source in IdentityNow

Author

  • Ganesh_Kulkarni

    SailPoint

SAP Secure Network Communication (SNC) Introduction

In the SAP system architecture, SNC is a software layer that offers an interface for the external software programs for a secure connection. SNC secures the Remote Function Call (RFC) connections to SAP Advanced Business Application Programming (ABAP) systems.

SNC only protects the logical link between the end points of a communication. This link is initiated from one side (Initiator) and accepted by the other side (Acceptor). For example, when the SAP source in IdentityNow as a client makes a remote function call to SAP System, the SAP source is the initiator of the communication and the SAP application server is the acceptor. Both the sides of the communication link must be configured for SNC and need to specify SNC options.

The initiator (the SAP source in IdentityNow) must specify:

  • Whether the communication should use SNC protection
  • SNC Partner Name
  • SNC Library Path
  • SNC level of security

NOTE: For more information, refer to the SAP Direct Source Configuration Reference Guide

The acceptor (SAP System) must specify:

  • Whether or not it should accept only SNC protected communications
  • Its own SNC name
  • The location of its the external library
  • The data protection levels to accept

 clipboard_image_1.png

NOTE: SAP Client is the SAP Direct source in IdentityNow.

When SNC is initialized, the SAP client and SAP system dynamically load the functions provided by the external library.

The SAP client and SAP system communicate through the SNC layer, it first processes the messages and sends them over the network using the SAP Network Interface. During this step, the SNC layer uses the functions provided by the external library to process the messages (for example, to apply encryption).

The SNC layer accesses the external library using the GSS-API V2 interface. After processing the messages, the system sends them over the SAP Network Interface.

Upon receipt, the SAP System component receiving the messages, applies the corresponding external library functions in a similar manner, but reverses the process (for example, the decryption).

NOTE: The GSS-API is a generic API for securing client-server communications.

SNC on Virtual Appliance (SAP Source in IdentityNow)

clipboard_image_2.png

There are three main components:

  • IdentityNow Cloud
  • Virtual Appliance Cluster with Cloud Connector Gateway (CCG)
  • Customer Environment

The IdentityNow cloud has the UI and the REST API interface. The interface has the internal services such as:

  • Access Review
  • Password
  • Provisioning
  • Task Processing Engine: performs aggregation, refresh, synchronization operations and serves multiple tenants.

The Virtual Appliances: These virtual appliances are in the customer’s controlled environment and updated by SailPoint.

SNC Layer: The SAP Source in IdentityNow as a client and SAP system communicate through the SNC layer

SAP Server-side Configuration

Refer to Configuring Secure Network Communications for using SAPCRYPTOLIB on the SAP Application Server ABAP.

NOTE: This is a reference guide on the SAP Server configuration provided as a guideline, only.

SNC Configuration on VA

Prerequisites

  • Download the following files from SAP marketplace.
    • libsapcrypto.so
    • sapgenpse.sh
  • SAP SNC server configuration must be complete and SNC certificate must be ready to export.

For more information on the SAP SNC server configuration and export of certificate, see:

Environment Preparation

  • Login to VA with SailPoint user credentials and create a sub-directory: /home/sailpoint/sec
  • Copy the libsapcrypto.so and sapgenpse.sh files to the /home/sailpoint/sec sub-directory.
    • Choose the required tools like PuTTY SCP (PSCP), Cygwin/ssh client or WinSCP to copy the files.
  • Change the file permission of sapgenpse.sh to include the execute permission using the following command:

chmod a+x /home/sailpoint/sec/sapgenpse.sh

NOTE: In the CCG docker image, these environment variables are added in a startup script. When the CCG service is restarted it sets the environment parameters (SECUDIR and LD_LIBRARY_PATH) as a prerequisite. It is not mandatory to point both the environment variables to the same directory.

The command to check: sudo /usr/bin/docker exec ccg env

Ensure the SECUDIR and LD_LIBRARY_PATH variables are set to libsapcrypto.so jar path.

Create Personal Security Environment (PSE)

Personal Security Environment (PSE) is a secure location that stores the information of a public-key of a communication user/ component.

Go to directory /home/sailpoint/sec and execute the following command as a SailPoint user:

./sapgenpse gen_pse -v -p Client.pse

Refer below command syntax for more information
./sapgenpse gen_pse <additional_options> [-p <PSE_name>]

Option

Parameter

Description

-p

<pse-file>

filename for (new) PSE

-r

<req-file>

filename for PKCS#10 request (default: stdout)

-Ips

use LPS to protect the new PSE

-a

<alg>

algorithm DSA, ECDSA or RSA (default is RSA) with GOST plugin: GostR3410-2001

-a also supports an extended syntax for specifying key type, strength and signature algorithm:

  • Use this syntax if the CA requires that the certification request is signed with a specific algorithm:

<keyType>:<strength>:<hashAig>

  • keyType: DSA, ECDSA or RSA
  • strength: key size or the name of the ECDSA curve

(P-192, P-224, P-256, P-384 or P-521)

  • hashAig: hash algorithm used for the signature of the self-signed certificate and the certification request

(SHA1, SHA224, SHA256, SHA384, SHA512) Examples: RSA:2048:SHA256, DSA:1024:SHA1, ECDSA:P-256:SHA1

-s

<size>

key size in Bits (default=alg-specific, rsa=DEFAULT_RSA_KEYSIZE, dsa=DEFAULT_DSA_KEYSIZE)

-X

<password>

Password for PSE (default: query interactively)

-noreq

Do not create/print a PKCS#10 certification request

-onlyreq

Create PKCS#10 certification request for an existing PSE

-2

Create PSE format v2

-4

Create PSE format v4

-j

Add Subject Alternative Names from existing PSE certificate to the certification request (with -onlyreq)

-k

<name>

Add Subject Alternative Names to the certification request. Multiple -k <name> parameters are supported to create a list of alternative names in the request.

If the type of the name is not derivable, the respective prefix must be given:

  • 'GN-rfc822Name:', 'GN-dNSName:', 'GN-uRI:',
  • 'GN-iPAddress:', 'GN-directoryName:', 'GN-registerediD:'

Syntax to specify a name of type 'otherName':

  • GN-otherName:<oid>:<valueType>:<value> oid : 'UPN' or object identifier (1.2.840...)
  • valueType: Encoding type of value
  • 'HEX': value is hex string of ASN.1 DERCode
  • 'UTF8String': value will be encoded as UTF8String
  • value: Name value (hex ASN.1 DERCode or string)

Examples:

  • -k GN-dNSName:www.sap.com
  • -k GN-iPAddress:127.0.0.1
  • -k GN-otherName:UPN:UTF8String:john.doe@sap.com
  • -k GN-otherName:1.3.6.1.4.1.694.2.2.2.444:HEX:0403020507

-h

print this help

-v

verbose

  • Specify the distinguished name as CN=XX, OU=XX, O=XX, C=XX

For example: CN=CLIENT, OU=IDM, O=SAILPOINT, C=IN

Where: CN= Common Name, OU= Organisational Unit, O= Organization, C= Country

Client.pse file is created in the /home/sailpoint/sec directory.

Export Client Certificate

  • Execute the following command from /home/sailpoint/sec directory with the sailpoint user:

./sapgenpse export_own_cert -v -p Client.pse -o Client.crt

This command generates Client.crt in the /home/sailpoint/sec directory.

Refer to the following syntax:

sapgenpse export_own_cert -p <PSE_name> -o <output_file>

Refer to the following table:

Option

Parameter

Description

-o

<output_file>

Export the certificate the named file

-p

<PSE_name>

Path and file name of the server's PSE

NOTE: Copy this client certificate (Client.crt) into the SAP server machine. Refer to how to import client certificate into SAP server, here.

Import Server Certificate into Client PSE

  • Copy the server certificate under the /home/sailpoint/sec directory as mentioned in Prerequisites section.
  • Execute the following command from /home/sailpoint/sec directory with the sailpoint user: ./sapgenpse maintain_pk -v -a Server.crt -p Client.pse
    NOTE: When there are multiple SAP servers, execute the above mentioned command from each server and client to import the certificate on each server.
  • Refer to the following syntax:

./sapgenpse maintain_pk [<additional options>] [-a <cert_file>] [-d <number>] -p <PSE_name> [-x <PIN>]

Option

Parameter

Description

-a

<cert_file>

Add certificate from file <cert_file> to the certificate list

-m

<cert_file>

Add multiple certificates from file <cert_file> to the certificate list

-M

<store>

Add multiple certificates from the CryptoAPI certificate store to the certificate list

-d

<number>

Delete certificate number <number> from certificate list

-p

<PSE_Name>

Path and file name for the server's PSE

-x

<PIN>

PIN that protects the PSE

NOTE: Server.crt is a public key certificate of the SAP server.

Create cred_v2 file

  • Create a cred_v2 file by executing the following command from /home/sailpoint/sec directory:

./sapgenpse seclogin -p Client.pse

  • Verify the certificate by logging in with the SailPoint user and executing the following command

./sapgenpse seclogin –l

NOTE: SailPoint no longer makes use of the root user, therefore the following message will be displayed when running the above command. This message will not affect the setup.

As shown in the above screenshot, the readable certificate is generated.

NOTE: Refer to the Map Client SNC Name to the SAP Service Account section in the SNC SAP server document.

Restart CCG Service

Restart CCG service using the sudo systemctl restart ccg command

VA Cluster Configuration

Cluster with multiple VAs

To know the VAs in cluster:

  • Login to IdentityNow.
  • Navigate to Connections > Virtual Appliances
  • You can check the Virtual Appliances number on the screen for your VA cluster.
  • Copy all the files from the /home/sailpoint/sec directory of the existing VA (where SNC is configured) except the cred_v2 file onto all the new VA's in the cluster in the /home/sailpoint/sec directory where you want to configure the SNC. If /home/sailpoint/sec directory is not created, create it.
  • Login to each VA in the cluster.
  • Navigate to /home/sailpoint/secdirectory and create cred_v2 file separately.

Multiple SAP servers communicating to one client

  • Import all the SAP server certificates into the client PSE.
  • Recreate the cred_v2 file with the updated client PSE.

Verification of SNC Connection

To ensure that SNC has been configured correctly, perform the following procedure:

  1. Login to the SAP Server UI using the SAP GUI and execute SU01 transaction.
  2. Search for the service account user that is mapped to SNC as mentioned in Map Client SNC Name to the SAP Service Account.
  3. Click on Display and open the SNC tab.
  4. Ensure that the SNC is active on this application server message is displayed as follows:

SNC Verification4.png

Perform the following steps to verify the SNC connection:

  1. Login to SAP GUI with SNC logon with user/password.

SNC verification1.png

2. Enter the user details for which the SNC certificates are added.

SNC Verification2.png

3. User would be able to successfully login based on the password and X509 certificate as displayed in the following screenshot.

SNC Verification3.png

Source Configuration

Refer to the SAP Direct Source Configuration Reference Guide.

Troubleshooting

  1. Test Connection failed with the following error:

No credentials were supplied Unable to establish the security

Root cause could one or many of the following:

  • The environment variable SECUDIR is not set correctly.
  • The environment variable USER is not set correctly (on UNIX systems only).
  • The cred_v2 file is not found in the directory specified in SECUDIR.
  • The cred_v2 file does not contain the credentials for the PSE to be accessed.
  • The credentials found in the cred_v2 file for the PSE, are not readable for the active user.
  • The PSE is not found at the place indicated by the credentials.
  • Password provided by the credentials differs from the password used to encrypt the PSE.
  • No location for the PSE and credentials has been defined.
  • The certificates on the client and server side have not been configured properly.
  • The SAP SNC port is not open and not able to communicate correctly.

Resolution: Verify the following:

  • The SECUDIR environment variable is correctly set for the root user.
  • On UNIX systems, the environment variable USER is correctly set for the active user.
  • The container file for credentials the cred_v2 file is in the directory indicated by SECUDIR.
  • A readable credential exists for the root user for the PSE.

2. Test Connection fails with the following error:

SNCERR_INVALID_NAMETYPE

Resolution: Ensure that the SNC Partner Name and SNC Name are prefixed with a lower case "p:". For example, you can use p:CN=IIQ, OU=IDM, O=SPT, C=IN and p:CN=Linux, OU=IDM, O=SPT, C=IN

3. Test Connection fails with the following error:

Verification of own certificate by server failed.

Resolution: Ensure while creating the server certificate you double-click the server's certificate.

4. Test Connection failed with the following error:

Connection closed without a message (CM_NO_DATA_RECEIVED)

Resolution: Restart the SAP server. This error occurs if the connection to SAP server is unexpectedly closed before the SAP GUI is loaded.



Related Content