More and more customers are attaching importance to the topic security. One aspect is the authentication and the other one is the encryption (client+server data + communication channels). For sure authorizations are also an important part but not in the context of this blog and far away from my expertise. As you may read between the lines – I’m not a fan of authorization concepts. These are all pretty broad topic and for now we will focus on the x.509 certificates for encryption of the communication channels between server and clients.
There are some documentations available by SAP, but some of them are outdated or not matching the customer environments/needs or not all-embracing.
Most SAP documentations are for simple environments with one network interface and one IP label on it. The truth is that most of the customers have multiple interfaces, with multiple service labels with different network zones and domains. Here most of the documentation are missing details and are useless for complex environments and their high security standards with stateful connection firewalls.