Enabling HTTPS for Secure Communications

You can enable the use of HTTPS protocol for secure communications where the information that is exchanged between your application and SAP NetWeaver Gateway server is sensitive.

Context

First, configure the use of secure socket layer (SSL) in the SAP NetWeaver Gateway landscape, and then configure SSL in the framework.

The following is an overview of how to enable HTTPS protocol for secure communications:

  1. Obtain and install in your work station, the root certificate (CA root certificate) of the SAP NetWeaver Gateway server that has been configured as the SSL server.
  2. Add information about the SSL server certificate to the Java Runtime Environment (JRE) Keystore using the application, Keytool.
    Note You can obtain the CA root certificate directly from the system administrator of the SAP NetWeaver Gateway server.

Obtain and Install the CA certificate from the SAP NetWeaver Gateway server

Context

To export an SSL server certificate from the SSL Server Standard PSE in the SAP NetWeaver Gateway host:

Procedure

  1. Use the Trust manager (transaction STRUST) in the SAP NetWeaver Gateway system to export the CA’s Root certificate.
  2. Select SSL Server Standard node in right-hand side tree.
  3. Choose the SSL certificate under Own Certificate, choose Certificate, and then choose Export.
  4. Specify the location of the certificate in your file system.

Add Information about the Gateway Server Certificate to Your Keystore

Context

Download the utility, Keytool, to help you create and manage digital certificates.

You can obtain the utility at: http://java.sun.com/j2se/1.3/docs/tooldocs/win32/keytool.htmlInformation published on non-SAP site

Keytool is a command-line utility that allows you to create and manage keystores for digital certificates in the Java environment.

You can list the current certificates contained within the keystore using the -list command of the keytool.

The initial password for the ca certs keystore is changeit.

Example

C:\Program Files\Java\jdk1.6.0_26\jre\bin>keytool -list –keystore ..\lib\security\cacerts

Enter keystore password: changeit.

The following displays:

Keystore type: jks Keystore provider: SUN
Your keystore contains 11 entries: engweb, Wed Apr 11 16:22:49 EDT 2001, trustedCertEntry, 
Certificate fingerprint (MD5): 8C:24:DA:52:7A:4A:16:4B:8E:FB:67:44:C9:D2:E4:16 thawtepersonalfreemailca, Fri Feb 12 15:12:16 EST 1999,trustedCertEntry, 
Certificate fingerprint (MD5):1E:74:C3:86:3C:0C:35:C5:3E:C2:7F:EF:3C:AA:3C:D9 thawtepersonalbasicca, Fri Feb 12 15:11:01 EST 1999, trustedCertEntry, 
Certificate fingerprint (MD5): E6:0B:D2:C9:CA:2D:88:DB:1A:71:0E:4B:78:EB:02:41 verisignclass3ca, Mon Jun 29 13:05:51 EDT 1998, trustedCertEntry, 
Certificate fingerprint (MD5): 78:2A:02:DF:DB:2E:14:D5:A7:5F:0A:DF:B6:8E:9C:5D thawteserverca, Fri Feb 12 15:14:33 EST 1999, trustedCertEntry, 
Certificate fingerprint (MD5): C5:70:C4:A2:ED:53:78:0C:C8:10:53:81:64:CB:D0:1D thawtepersonalpremiumca, Fri Feb 12 15:13:21 EST 1999, trustedCertEntry, 
Certificate fingerprint (MD5): 3A:B2:DE:22:9A:20:93:49:F9:ED:C8:D2:8A:E7:68:0D verisignclass4ca, Mon Jun 29 13:06:57 EDT 1998, trustedCertEntry, 
Certificate fingerprint (MD5): 1B:D1:AD:17:8B:7F:22:13:24:F5:26:E2:5D:4E:B9:10 verisignclass1ca, Mon Jun 29 13:06:17 EDT 1998, trustedCertEntry, 
Certificate fingerprint (MD5): 51:86:E8:1F:BC:B1:C3:71:B5:18:10:DB:5F:DC:F6:20 verisignserverca, Mon Jun 29 13:07:34 EDT 1998, trustedCertEntry, 
Certificate fingerprint (MD5): 74:7B:82:03:43:F0:00:9E:6B:B3:EC:47:BF:85:A5:93 thawtepremiumserverca, Fri Feb 12 15:15:26 EST 1999, trustedCertEntry, 
Certificate fingerprint (MD5): 06:9F:69:79:16:66:90:02:1B:8C:8C:A2:C3:07:6F:3A verisignclass2ca, Mon Jun 29 13:06:39 EDT 1998, trustedCertEntry, 
Certificate fingerprint (MD5): EC:40:7D:2B:76:52:67:05:2C:EA:F2:3A:4F:65:F0:D8

Add the CA Root Certificate to the Keystore

Context

You must add the CA certificate you received from the SAP NetWeaver Gateway server to the Eclipse keystore.

From the command line, enter keytool –import, to import the file into your cacerts keystore.

Example

C:\Program Files\Java\jdk1.6.0_26\jre\bin>keytool -import –keystore ..\lib\security\cacerts -file c:\ SAProotca.cer 
To check, run keytool -list again to verify that your private root certificate was added. For example,
C:\Program Files\Java\jdk1.6.0_26\jre\bin>keytool -list -keystore ..\lib\security\cacerts
You should now see a list of all the certificates including the one you just added.
In addition, verify that the JAVA home location is defined in the file, eclipse.ini. For example,
-vm C:/Program Files/Java/jdk1.6.0_21/bin/javaw.exe

Configure HTTPS in the Framework

Context

After you have configured the use of SSL in the SAP NetWeaver Gateway landscape, you can configure SSL in the framework.

To configure SSL in the framework:

Procedure

  1. From the main menu, select Start of the navigation path Window Next navigation step  Preferences  Next navigation step  OData Development  Next navigation step  SAP NetWeaver Gateway  Next navigation step  Connections End of the navigation path. The Create Connections dialog displays.
  2. Choose Add. The Connections displays.
  3. Select Use HTTPS (Certificate needed), and enter the connection settings for the SAP NetWeaver Gateway host.