SlideShare a Scribd company logo
1 of 9
Download to read offline
SAP	
  Router	
  Installa0on	
  with	
  SNC	
  
•  SAP  Router  is  a  program  that  acts  as  a  proxy  between  SAP  
systems  and  external  networks
•  It  controls  access  to  your  network  from  external  network  
systems  such  as  SAP  AG
•  It  acts  as  an  applica?on  level  gateway  and  is  useful  for    
enhancing  an  exis?ng  firewall
•  This  document  focuses  on  the  installa?on  of  SAP  Router  using  
Secure  Network  Communica?on  (SNC)  and  is  aimed  at  system  
administrators  responsible  for  seGng  up  connec?vity  from  SAP  
to  customer
Introduc0on	
  
•  Download  of  the  latest  installa?on  media  for  SAP  Router  and  
the  SAP  Cryptographic  library  from  SAP  Support  Portal
•  Register  your  with  SAP  Router  with  SAP
o  obtain  public  IP  and  hostname  of  your  SAP  Router  host
o  fill  in  remote  connec?on  data  sheet  from  note  28976
o  raise  incident  with  SAP  under  component  XX-­‐SER-­‐NET-­‐NEW
o  SAP  will  provide  your  Dis?nguished  Name
•  E.g.  CN=<SAP  Router  host>,  OU=<Customer  Number>,  OU=SAProuter,  O=SAP,  C=DE
•  Prepare  SAP  Router  host
o  create  a  user  e.g.  “sapadm”  in  group  sapsys
o  create  and  installa?on  filesystem  e.g.  /usr/sap/saprouter
o  set  ownership  of  installa?on  filesystem  to  “sapadm:sapsys”
Pre-­‐Requisites	
  
Installa0on	
  
•  Perform  the  installa?on  as  user  sapadm
•  Unpack  the  so]ware  into  your  installa?on  file  system  
o  SAPCAR  -­‐xvf  <saprouter  so]ware  archive>
o  SAPCAR  -­‐xvf  <sapcryptographic  so]ware  archive>
•  Update  environment  of  sapadm
o  PATH  =  ${PATH}:<installa?on  directory>
o  SECUDIR  =  <installa?on  directory>
o  SNC_LIB  =  <installa?on  directory>/<sapcryptographic_library>
o  LD_LIBRARY_PATH  =  <installa?on  directory>
Registering	
  SAP	
  Router	
  
•  Go  to  
hfps://support.sap.com/remote-­‐support/saprouter/saprouter-­‐
cer?ficates.html
•  Generate  SAP  Router  cer?ficate  request  using  dis?nguished  name  
registered  at  SAP  with  sapadm  and  command  sapgenpse
o  sapgenpse  get_pse  -­‐v  -­‐a  sha256WithRsaEncryp?on  -­‐s  2048  -­‐r  certreq  -­‐p  
local.pse  “<Dis?nguished  Name>”
•  Copy  and  paste  the  content  of  text  file  (certreq)  created  by  
sapgenpse  into  the  SAP  support  page  and  request  cer?ficate
•  Copy  and  paste  the  result  of  the  cer?ficate  request  onto  the  
saprouter  host  as  a  text  file  “srcert”  under  the  /usr/sap/saprouter  
directory
Import	
  Cer0ficate	
  
•  Import  “srcert”  onto  saprouter  using  sapgenpse  command  
below  and  create  creden?als  for  user  “sapadm”  to  access  local  
pse
o  sapgenpse  import_own_cert  -­‐c  srcert  -­‐p  local.pse
o  sapgenpse  seclogin  -­‐p  local.pse  -­‐O  sapadm
Create	
  Router	
  Table	
  
•  The  SAP  Router  table  is  a  permission  file  containing  details  of  
who  can  communicate  through  the  SAP  Router
•  As  “sapadm”  create  the  text  file  saproufab  under  /usr/sap/
saprouter  and  configure  similar  to  the  example  below
Opera0ng	
  SAP	
  Router	
  
•  Operate  SAP  Router  with  the  user  created  for  the  installa?on
•  Issue  start/stop  commands  from  the  installa?on  directory
•  Start  the  SAP  Router  with  the  following  command
–  saprouter  -­‐r  -­‐S  <port>  -­‐G  saprouter.log  -­‐K  "<DN>"  &  
–  where:
o  -­‐K 
:  to  start  with  loading  SNC  library
o  <DN> 
:  Dis?nguished  Name
o  -­‐S 



:  saprouter  port
o  -­‐G 
:  name  of  the  log  file
•  Stop  the  SAP  Router  with  the  following  command
–  saprouter  -­‐s
Thank-­‐you	
  

More Related Content

What's hot

2 ewa overview_info day
2 ewa overview_info day2 ewa overview_info day
2 ewa overview_info day
Md Kamruzzaman
 
Sap Upgrade Project Brief
Sap Upgrade Project BriefSap Upgrade Project Brief
Sap Upgrade Project Brief
vpallapothu
 
Enhancement framework the new way to enhance your abap systems
Enhancement framework   the new way to enhance your abap systemsEnhancement framework   the new way to enhance your abap systems
Enhancement framework the new way to enhance your abap systems
Kranthi Kumar
 

What's hot (20)

Data archiving in sales and distribution (sd)
Data archiving in sales and distribution (sd)Data archiving in sales and distribution (sd)
Data archiving in sales and distribution (sd)
 
Sap basis made easy
Sap basis made easySap basis made easy
Sap basis made easy
 
2 ewa overview_info day
2 ewa overview_info day2 ewa overview_info day
2 ewa overview_info day
 
SAP Cloud Platform Integration Services – L1 Deck
SAP Cloud Platform Integration Services – L1 DeckSAP Cloud Platform Integration Services – L1 Deck
SAP Cloud Platform Integration Services – L1 Deck
 
How to run v3 job
How to run v3 jobHow to run v3 job
How to run v3 job
 
Difference between sap cloud delivered erp vs sap on premise erp
Difference between sap cloud delivered erp vs sap on premise erpDifference between sap cloud delivered erp vs sap on premise erp
Difference between sap cloud delivered erp vs sap on premise erp
 
sap hana|sap hana database| Introduction to sap hana
sap hana|sap hana database| Introduction to sap hanasap hana|sap hana database| Introduction to sap hana
sap hana|sap hana database| Introduction to sap hana
 
12753028 scot-configuration-troubleshooting
12753028 scot-configuration-troubleshooting12753028 scot-configuration-troubleshooting
12753028 scot-configuration-troubleshooting
 
Hadoop Summit Tokyo Apache NiFi Crash Course
Hadoop Summit Tokyo Apache NiFi Crash CourseHadoop Summit Tokyo Apache NiFi Crash Course
Hadoop Summit Tokyo Apache NiFi Crash Course
 
Sap Change And Transport Management
Sap Change And Transport ManagementSap Change And Transport Management
Sap Change And Transport Management
 
Sap Upgrade Project Brief
Sap Upgrade Project BriefSap Upgrade Project Brief
Sap Upgrade Project Brief
 
How to do a SAP PI/PO Migration 2019
How to do a SAP PI/PO Migration 2019 How to do a SAP PI/PO Migration 2019
How to do a SAP PI/PO Migration 2019
 
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
 
Introduction to OData
Introduction to ODataIntroduction to OData
Introduction to OData
 
Enhancement framework the new way to enhance your abap systems
Enhancement framework   the new way to enhance your abap systemsEnhancement framework   the new way to enhance your abap systems
Enhancement framework the new way to enhance your abap systems
 
Sap basis administration handbook
Sap basis administration handbookSap basis administration handbook
Sap basis administration handbook
 
SAP Document Management System Integration with Content Servers
SAP Document Management System Integration with Content Servers SAP Document Management System Integration with Content Servers
SAP Document Management System Integration with Content Servers
 
SAP S_4HANA Migration Cockpit - Migrate your Data to SAP S_4HANA.pdf
SAP S_4HANA Migration Cockpit - Migrate your Data to SAP S_4HANA.pdfSAP S_4HANA Migration Cockpit - Migrate your Data to SAP S_4HANA.pdf
SAP S_4HANA Migration Cockpit - Migrate your Data to SAP S_4HANA.pdf
 
SAP HANA Overview
SAP HANA OverviewSAP HANA Overview
SAP HANA Overview
 
Healthcare Claim Reimbursement using Apache Spark
Healthcare Claim Reimbursement using Apache SparkHealthcare Claim Reimbursement using Apache Spark
Healthcare Claim Reimbursement using Apache Spark
 

Similar to SAP Router Installation with SNC

Accelerate2022-Solving the SAP Security Gap through Application-aware Network...
Accelerate2022-Solving the SAP Security Gap through Application-aware Network...Accelerate2022-Solving the SAP Security Gap through Application-aware Network...
Accelerate2022-Solving the SAP Security Gap through Application-aware Network...
PeterSmetny1
 
Real Time Analytics with Dse
Real Time Analytics with DseReal Time Analytics with Dse
Real Time Analytics with Dse
DataStax Academy
 

Similar to SAP Router Installation with SNC (20)

Principal Propagation with SAP Cloud Platform
Principal Propagation with SAP Cloud PlatformPrincipal Propagation with SAP Cloud Platform
Principal Propagation with SAP Cloud Platform
 
TechTalkThai webinar SAP HANA
TechTalkThai webinar SAP HANATechTalkThai webinar SAP HANA
TechTalkThai webinar SAP HANA
 
MLflow Model Serving
MLflow Model ServingMLflow Model Serving
MLflow Model Serving
 
Learn about Cloud and Scalability in SAP Hybris Commerce Technology Strategy
Learn about Cloud and Scalability in SAP Hybris Commerce Technology StrategyLearn about Cloud and Scalability in SAP Hybris Commerce Technology Strategy
Learn about Cloud and Scalability in SAP Hybris Commerce Technology Strategy
 
Accelerate2022-Solving the SAP Security Gap through Application-aware Network...
Accelerate2022-Solving the SAP Security Gap through Application-aware Network...Accelerate2022-Solving the SAP Security Gap through Application-aware Network...
Accelerate2022-Solving the SAP Security Gap through Application-aware Network...
 
Overview and Walkthrough of the Application Programming Model with SAP Cloud ...
Overview and Walkthrough of the Application Programming Model with SAP Cloud ...Overview and Walkthrough of the Application Programming Model with SAP Cloud ...
Overview and Walkthrough of the Application Programming Model with SAP Cloud ...
 
Process big data within an hour, with the OVH Public Cloud
Process big data within an hour, with the OVH Public CloudProcess big data within an hour, with the OVH Public Cloud
Process big data within an hour, with the OVH Public Cloud
 
Real Time Analytics with Dse
Real Time Analytics with DseReal Time Analytics with Dse
Real Time Analytics with Dse
 
Building iot applications with Apache Spark and Apache Bahir
Building iot applications with Apache Spark and Apache BahirBuilding iot applications with Apache Spark and Apache Bahir
Building iot applications with Apache Spark and Apache Bahir
 
Nagios Conference 2014 - Leland Lammert - Distributed Heirarchical Nagios
Nagios Conference 2014 - Leland Lammert - Distributed Heirarchical NagiosNagios Conference 2014 - Leland Lammert - Distributed Heirarchical Nagios
Nagios Conference 2014 - Leland Lammert - Distributed Heirarchical Nagios
 
MLflow Model Serving - DAIS 2021
MLflow Model Serving - DAIS 2021MLflow Model Serving - DAIS 2021
MLflow Model Serving - DAIS 2021
 
(BIZ301) Getting Started: Running SAP on AWS | AWS re:Invent 2014
(BIZ301) Getting Started: Running SAP on AWS | AWS re:Invent 2014(BIZ301) Getting Started: Running SAP on AWS | AWS re:Invent 2014
(BIZ301) Getting Started: Running SAP on AWS | AWS re:Invent 2014
 
Converting Your Existing SAP Server Infrastructure to a Modern Cloud-Based Ar...
Converting Your Existing SAP Server Infrastructure to a Modern Cloud-Based Ar...Converting Your Existing SAP Server Infrastructure to a Modern Cloud-Based Ar...
Converting Your Existing SAP Server Infrastructure to a Modern Cloud-Based Ar...
 
CCNP Data Center Centralized Management Automation
CCNP Data Center Centralized Management AutomationCCNP Data Center Centralized Management Automation
CCNP Data Center Centralized Management Automation
 
SAP SDM Hacking
SAP SDM HackingSAP SDM Hacking
SAP SDM Hacking
 
TIAD 2016 : Real-Time Data Processing Pipeline & Visualization with Docker, S...
TIAD 2016 : Real-Time Data Processing Pipeline & Visualization with Docker, S...TIAD 2016 : Real-Time Data Processing Pipeline & Visualization with Docker, S...
TIAD 2016 : Real-Time Data Processing Pipeline & Visualization with Docker, S...
 
Real-Time Data Processing Pipeline & Visualization with Docker, Spark, Kafka ...
Real-Time Data Processing Pipeline & Visualization with Docker, Spark, Kafka ...Real-Time Data Processing Pipeline & Visualization with Docker, Spark, Kafka ...
Real-Time Data Processing Pipeline & Visualization with Docker, Spark, Kafka ...
 
A Big Data Lake Based on Spark for BBVA Bank-(Oscar Mendez, STRATIO)
A Big Data Lake Based on Spark for BBVA Bank-(Oscar Mendez, STRATIO)A Big Data Lake Based on Spark for BBVA Bank-(Oscar Mendez, STRATIO)
A Big Data Lake Based on Spark for BBVA Bank-(Oscar Mendez, STRATIO)
 
LambHack: A Vulnerable Serverless Application
LambHack: A Vulnerable Serverless ApplicationLambHack: A Vulnerable Serverless Application
LambHack: A Vulnerable Serverless Application
 
Big data processing with Apache Spark and Oracle Database
Big data processing with Apache Spark and Oracle DatabaseBig data processing with Apache Spark and Oracle Database
Big data processing with Apache Spark and Oracle Database
 

More from Gary Jackson MBCS

More from Gary Jackson MBCS (19)

SAP ASCS on Kubernetes - A Proposal
SAP ASCS on Kubernetes - A ProposalSAP ASCS on Kubernetes - A Proposal
SAP ASCS on Kubernetes - A Proposal
 
SAP on Azure Web Dispatcher High Availability
SAP on Azure Web Dispatcher High AvailabilitySAP on Azure Web Dispatcher High Availability
SAP on Azure Web Dispatcher High Availability
 
Office 365 SaaS Mail Integration with SAP on Azure
Office 365 SaaS Mail Integration with SAP on AzureOffice 365 SaaS Mail Integration with SAP on Azure
Office 365 SaaS Mail Integration with SAP on Azure
 
OpenText Archive Server on Azure
OpenText Archive Server on AzureOpenText Archive Server on Azure
OpenText Archive Server on Azure
 
SAP OS/DB Migration using Azure Storage Account
SAP OS/DB Migration using Azure Storage AccountSAP OS/DB Migration using Azure Storage Account
SAP OS/DB Migration using Azure Storage Account
 
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
SAP HANA System Replication (HSR) versus SAP Replication Server (SRS)
 
High Availability of SAP ASCS in Microsoft Azure
High Availability of SAP ASCS in Microsoft AzureHigh Availability of SAP ASCS in Microsoft Azure
High Availability of SAP ASCS in Microsoft Azure
 
Azure Custom Backup Solution for SAP NetWeaver
Azure Custom Backup Solution for SAP NetWeaverAzure Custom Backup Solution for SAP NetWeaver
Azure Custom Backup Solution for SAP NetWeaver
 
SAP Adaptive Computing Design
SAP Adaptive Computing DesignSAP Adaptive Computing Design
SAP Adaptive Computing Design
 
SAP LaMa Cloud Manager Azure
SAP LaMa Cloud Manager AzureSAP LaMa Cloud Manager Azure
SAP LaMa Cloud Manager Azure
 
SAP Host Agent x509 authentication
SAP Host Agent x509 authenticationSAP Host Agent x509 authentication
SAP Host Agent x509 authentication
 
SAP LVM Integration with SAP BPA
SAP LVM Integration with SAP BPASAP LVM Integration with SAP BPA
SAP LVM Integration with SAP BPA
 
SAP LVM Post Copy Automation Integration
SAP LVM Post Copy Automation IntegrationSAP LVM Post Copy Automation Integration
SAP LVM Post Copy Automation Integration
 
SAP LVM Customer Operations
SAP LVM Customer OperationsSAP LVM Customer Operations
SAP LVM Customer Operations
 
SAP LVM Customer Instances
SAP LVM Customer InstancesSAP LVM Customer Instances
SAP LVM Customer Instances
 
SAP ASE Migration Lessons Learned
SAP ASE Migration Lessons LearnedSAP ASE Migration Lessons Learned
SAP ASE Migration Lessons Learned
 
SAP Rolling Kernel Switch RKS
SAP Rolling Kernel Switch RKSSAP Rolling Kernel Switch RKS
SAP Rolling Kernel Switch RKS
 
SAP Post Copy Automation
SAP Post Copy AutomationSAP Post Copy Automation
SAP Post Copy Automation
 
SAP Web Dispatcher - Best Bits
SAP Web Dispatcher - Best BitsSAP Web Dispatcher - Best Bits
SAP Web Dispatcher - Best Bits
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 

SAP Router Installation with SNC

  • 1. SAP  Router  Installa0on  with  SNC  
  • 2. •  SAP  Router  is  a  program  that  acts  as  a  proxy  between  SAP   systems  and  external  networks •  It  controls  access  to  your  network  from  external  network   systems  such  as  SAP  AG •  It  acts  as  an  applica?on  level  gateway  and  is  useful  for     enhancing  an  exis?ng  firewall •  This  document  focuses  on  the  installa?on  of  SAP  Router  using   Secure  Network  Communica?on  (SNC)  and  is  aimed  at  system   administrators  responsible  for  seGng  up  connec?vity  from  SAP   to  customer Introduc0on  
  • 3. •  Download  of  the  latest  installa?on  media  for  SAP  Router  and   the  SAP  Cryptographic  library  from  SAP  Support  Portal •  Register  your  with  SAP  Router  with  SAP o  obtain  public  IP  and  hostname  of  your  SAP  Router  host o  fill  in  remote  connec?on  data  sheet  from  note  28976 o  raise  incident  with  SAP  under  component  XX-­‐SER-­‐NET-­‐NEW o  SAP  will  provide  your  Dis?nguished  Name •  E.g.  CN=<SAP  Router  host>,  OU=<Customer  Number>,  OU=SAProuter,  O=SAP,  C=DE •  Prepare  SAP  Router  host o  create  a  user  e.g.  “sapadm”  in  group  sapsys o  create  and  installa?on  filesystem  e.g.  /usr/sap/saprouter o  set  ownership  of  installa?on  filesystem  to  “sapadm:sapsys” Pre-­‐Requisites  
  • 4. Installa0on   •  Perform  the  installa?on  as  user  sapadm •  Unpack  the  so]ware  into  your  installa?on  file  system   o  SAPCAR  -­‐xvf  <saprouter  so]ware  archive> o  SAPCAR  -­‐xvf  <sapcryptographic  so]ware  archive> •  Update  environment  of  sapadm o  PATH  =  ${PATH}:<installa?on  directory> o  SECUDIR  =  <installa?on  directory> o  SNC_LIB  =  <installa?on  directory>/<sapcryptographic_library> o  LD_LIBRARY_PATH  =  <installa?on  directory>
  • 5. Registering  SAP  Router   •  Go  to   hfps://support.sap.com/remote-­‐support/saprouter/saprouter-­‐ cer?ficates.html •  Generate  SAP  Router  cer?ficate  request  using  dis?nguished  name   registered  at  SAP  with  sapadm  and  command  sapgenpse o  sapgenpse  get_pse  -­‐v  -­‐a  sha256WithRsaEncryp?on  -­‐s  2048  -­‐r  certreq  -­‐p   local.pse  “<Dis?nguished  Name>” •  Copy  and  paste  the  content  of  text  file  (certreq)  created  by   sapgenpse  into  the  SAP  support  page  and  request  cer?ficate •  Copy  and  paste  the  result  of  the  cer?ficate  request  onto  the   saprouter  host  as  a  text  file  “srcert”  under  the  /usr/sap/saprouter   directory
  • 6. Import  Cer0ficate   •  Import  “srcert”  onto  saprouter  using  sapgenpse  command   below  and  create  creden?als  for  user  “sapadm”  to  access  local   pse o  sapgenpse  import_own_cert  -­‐c  srcert  -­‐p  local.pse o  sapgenpse  seclogin  -­‐p  local.pse  -­‐O  sapadm
  • 7. Create  Router  Table   •  The  SAP  Router  table  is  a  permission  file  containing  details  of   who  can  communicate  through  the  SAP  Router •  As  “sapadm”  create  the  text  file  saproufab  under  /usr/sap/ saprouter  and  configure  similar  to  the  example  below
  • 8. Opera0ng  SAP  Router   •  Operate  SAP  Router  with  the  user  created  for  the  installa?on •  Issue  start/stop  commands  from  the  installa?on  directory •  Start  the  SAP  Router  with  the  following  command –  saprouter  -­‐r  -­‐S  <port>  -­‐G  saprouter.log  -­‐K  "<DN>"  &   –  where: o  -­‐K :  to  start  with  loading  SNC  library o  <DN> :  Dis?nguished  Name o  -­‐S :  saprouter  port o  -­‐G :  name  of  the  log  file •  Stop  the  SAP  Router  with  the  following  command –  saprouter  -­‐s