Quantcast
Channel: SCN : Discussion List - Security
Viewing all articles
Browse latest Browse all 2353

How do I configure RFCs for SNC communication?

$
0
0

Hello Everyone,

 

I'm an Oracle DBA / Basis Admin and am new to configuring SNC.  So far I've been able to configure SAPgui sessions to communicate with systems using SNC but am having difficulty locating documentation to tell me how to get systems to use SNC with their RFC communication.  Everything seems to assume you already have the prerequisite configuration complete and just says to go to SM59, go to the Logon & Security tab and click the SNC button.  I, however, believe I'm missing the steps where I'm guessing I need to install a certificate for the other server/system.

 

I've exported different certificates out of STRUST on one system (SBX) and imported them into SNC SAPCryptolib on the other (SD2) and vice versa, and restarted the ICM each time but the connection test failes with this error:

 

LogonCancel
Error DetailsGSS-API(maj): Miscellaneous failure GSS-API(min): A221021F:Server refuses certif
Error DetailsERROR: GSS-API(maj): Miscellaneous failure GSS-API(min): A221021F:Server refu
Error DetailsLOCATION: SAP-Server SSBX4_SBX_00 on host SSBX4 (wp 4)
Error DetailsDETAIL: SncPEstablishContext
Error DetailsCALL: gss_init_sec_context
Error DetailsCOMPONENT: SNC (Secure Network Communication)
Error DetailsCOUNTER: 43
Error DetailsMODULE: sncxxall.c
Error DetailsLINE: 3551
Error DetailsRETURN CODE: -4
Error DetailsSUBRC: 0
Error DetailsRELEASE: 721
Error DetailsTIME: Tue Apr 05 09:12:25 2016
Error DetailsVERSION: 6

 

I don't even know if the partner name specified on the Logon & Security tab for the RFC definition under the SNC button is correct.  I at least no longer get the "Unable to Determine Canonical SNC Name RC= 4-" error that I used to get but have no indication if what I do have is correct:  The format for the Partner name that I'm using is:

 

p:CN=<FQDN>, OU=<SAP Customer ID>, OU=<Long Company Name>, O=<Short Company Name>, L=<City>, SP=<State>, C=<Country>

 

This partner name matches the X.509 name used in the other system's SSL server Standard PSE in STRUST.

 

Can someone help me with this, please, either by pointing me to documentation and/or by giving me a step by step for what to do to get this working?

 

Please let me know if there's any other information you need to help with this.

 

Thanks in advance!

 

Jeff


Viewing all articles
Browse latest Browse all 2353

Trending Articles