Quantcast
Channel: SCN : Popular Discussions - SAP Single Sign-On
Viewing all articles
Browse latest Browse all 1248

SNC Name (SU01/USRACL) must be re-assigned after migrating SLL 2.0 from 1.0

$
0
0

Hi Experts,

 

today i have updated Secure Login Library 2.0 on a SAP NW AS ABAP 7.31 SPS05 test system which is based on Windows x64.

 

Installed this version:

 

Platform:   windows-x86-64   (windows-x86-64)

Versions:   SAPGENPSE     2.0 SP1 (May  2 2013)

            FILE-Version  8.4.2.0

            SAPCRYPTOLIB  5.5.5C pl35  (May  2 2013) MT-safe

 

After that i created the new kerberos keytab within the SAPSNCSKERB.pse using the new sapgenpse CLI commands and created the credentials as described in the implementation guide. After restarting the ABAP Stack i was not able to perform Single Sign-On (Kerberos) using SAP GUI. GUI told me there is no user with the SNC Name p:CN=<Username>@<MYDOMAIN>.

 

As the installation worked fine before and the user still exists with a valid SNC name mapping in SU01 i was confused.

Checked the SNC Name, everything correct, green tick existis (Canonical name determined)

 

Solution:

Delete the SNC Name and re-create the Canonical Name again. After this the logon by Kerberos Ticket worked.

 

Question:

Please tell me why this is the case and what is the best solution if this happens for thousands of users (SNC4?)

Anything changed in the name schema inside the new SNC lib?

 

Thanks a lot!

 

Regards,

Carsten


Viewing all articles
Browse latest Browse all 1248

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>