We have added search box. Key in SAP issue keyword to search
TopBottom

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.

[sap-basis] SSO using windows kerbos by configuring SAP Front Ends automatically Win03

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Posted by pradeep reddy
on 06/29/2009 08:10:00 AM

Hi Everyone,
We are trying to confogure SSO for our SAP Environment using AD on Windows2003 DC.
We are running SAPECC5 on Win200364bit with Oracle10.2 and we have only ABAP and no JAVA .
I tried to follow the steps configuring frontends individually and it worked fine.
Since we have many users we tried to do it using Domain Constroller as Group Policy but getting SNC errors.
I followed the below steps but even after the MSI file is installed on users meachines it is still showing the SNC error. I verified that Kerbos is installed , Dll files are created but getting SNC error.
.Can any one please provide the extact steps which need to be followed on domain to make it work successfully .
To define the Group Policy:
1. Log on to a front-end machine as domain administrator of the Windows 2000 domain.
2. Copy the program SAPSSO.MSI from the sapserv<x> directory
general/R3Server/binaries/NT/W2K to a shared directory.
3. From the Windows 2000 menu choose Start ? Programs ? Administrative tools ? Active
Directory Users and Computers.
The dialog box Active Directory Users and Computers appears.
4. Select the domain for which you want to set up Single Sign-On. Right-click and choose
Properties from the context menu.
The dialog box <Domain_Name> Properties appears.
5. On the Group Policy tab, choose New to access the dialog box for creating a new policy
object.
6. Under Group Policy Object Links, enter a name for the new policy object, for example,
SAPSSO. Choose Edit to define the contents of the policy.
7. In the Group Policy Editor choose User Configuration ? Software Settings ? Software
Installation.
The Deploy Software dialog box opens.
8. Right-click and choose New ? Package from the context menu.
The Open dialog box appears.
9. Select the file SAPMSSO.MSI from the shared location. Specify the path with the UNC name
(\\<hostname>\<share>).
10. Select Assign and confirm with OK.
You have now created a new Group Policy. The next time any user logs on to the domain with the
SAP front end, the wizard SAP Single Sign-On Support for Windows 2000 is started and
automatically prepares the front end for Single Sign-On.
For making things more easy:
1. Which phase does the error locate? After ADS successfully distributed the solftware to client and client installations finished successfully?
2. Windows GUI settings for SNC were done?
3. What is the exact error here?
4. We definitely can get the trace as note 495911 for the exact missing.
I am getting the problem during domain phase.
1. After ADS successfully distributed the solftware to client and client installations finished successfully?
The Error " SAP System message : Secure Network Layer SNC error".
When I check under control pannel - Add & remove programs - Kerberos SSO support is not fully installed. I mean I can see the description but not the size of the application.
We are trying to apply the SAPMSSO.MSI as domain policy .
When I tried to do the install locally on meachines individualy ,it's working fine .
This project is currently on hold and we are not able to get much help even fron SAP support.
Any help is greately appreciated..
Regards
P
__.____._

Copyright © 2009 CEB Toolbox, Inc. and message author.

Toolbox.com
4343 N. Scottsdale Road
Suite 280
Scottsdale, AZ 85251

0 comments:

Post a Comment

T r a n s l a t e to your language