Transcription of MDM 7.1 Security Guide - docshare02.docshare.tips
1 SAP NetWeaver MDM Security Guide SAP NetWeaver MDM SP08 Document Version April 3, 2012 October 2011 April 2012 Copyright 2012 SAP AG. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. Microsoft, Windows, Outlook, and PowerPoint are registered trademarks of Microsoft Corporation.
2 IBM, DB2, DB2 Universal Database, OS/2, Parallel Sysplex, MVS/ESA, AIX, S/390, AS/400, OS/390, OS/400, iSeries, pSeries, xSeries, zSeries, z/OS, AFP, Intelligent Miner, WebSphere, Netfinity, Tivoli, and Informix are trademarks or registered trademarks of IBM Corporation in the United States and/or other countries. Oracle is a registered trademark of Oracle Corporation. UNIX, X/Open, OSF/1, and Motif are registered trademarks of the Open Group. Citrix, ICA, Program Neighborhood, MetaFrame, WinFrame, VideoFrame, and MultiWin are trademarks or registered trademarks of Citrix Systems, Inc. HTML, XML, XHTML and W3C are trademarks or registered trademarks of W3C , World Wide Web Consortium, Massachusetts Institute of Technology.
3 Java is a registered trademark of Sun Microsystems, Inc. JavaScript is a registered trademark of Sun Microsystems, Inc., used under license for technology invented and implemented by Netscape. MaxDB is a trademark of MySQL AB, Sweden. SAP, R/3, mySAP, , xApps, xApp, SAP NetWeaver, and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and in several other countries all over the world. All other product and service names mentioned are the trademarks of their respective companies. Data contained in this document serves informational purposes only.
4 National product specifications may vary. These materials are subject to change without notice. These materials are provided by SAP AG and its affiliated companies ("SAP Group") for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. Disclaimer Some components of this product are based on Java.
5 Any code change in these components may cause unpredictable and severe malfunctions and is therefore expressively prohibited, as is any decompilation of these components. Any Java Source Code delivered with this product is only to be used by SAP s Support Services and may not be modified or altered in any way. Documentation on SAP Service Marketplace You can find this documentation at October 2011 April 2012 Typographic Conventions Type Style Represents Example Text Words or characters quoted from the screen. These include field names, screen titles, pushbuttons labels, menu names, menu paths, and menu options.
6 Cross-references to other documentation. Example text Emphasized words or phrases in body text, graphic titles, and table titles. EXAMPLE TEXT Technical names of system objects. These include report names, program names, transaction codes, table names, and key concepts of a programming language when they are surrounded by body text, for example, SELECT and INCLUDE. Example text Output on the screen. This includes file and directory names and their paths, messages, names of variables and parameters, source text, and names of installation, upgrade and database tools. Example text Exact user entry. These are words or characters that you enter in the system exactly as they appear in the documentation.
7 <Example text> Variable user entry. Angle brackets indicate that you replace these words and characters with appropriate entries to make entries in the system. EXAMPLE TEXT Keys on the keyboard, for example, F2 or ENTER. Icons Icon Meaning Caution Example Note / Tip Recommendation Syntax MDM Security Guide April 2012 Document History Document Version Description of Change 3. 1/ April 2012 Consolidated information from the MDM Console Reference Guide into the following sections: o LDAP Support (page 10) o Authentication of Trusted Connections (page 23) / September 2011 Guide updated for MDM SP08 Secure Trusted Connection support added.
8 See Authentication of Trusted Connections (page 23). New option added for securing connections to Microsoft Active Directory LDAP Server. See Secure Connection to Microsoft Active Directory Configuration (page 23). Default Admin user password changed to sapmdm. See Standard User (page 9). New CLIX commands added for password management operations. See CLIX Commands for Managing Passwords (page 9). New CLIX command added for emergency Admin user password creation. See Emergency User Concept (page 10). / May 2011 Guide updated for MDM SP07 SSL support added. See Network and Communication Security (page 17).
9 MDM Security Guide April 2012 Contents MDM Security Guide .. 1 1 COMPONENTS OF SAP NETWEAVER MDM .. 2 2 USERS, ROLES AND AUTHENTICATION .. 3 Users .. 3 Roles and Authorizations .. 3 Roles .. 3 Authorizations .. 3 Predefined Users, Roles and Passwords .. 4 Single Sign-On Support .. 4 Authentication and SSO-like Feature in MDM Java Components .. 4 User Management .. 4 Trusted Connection .. 4 iViews and UWL Authentication and the SSO-like Feature .. 5 MDM Web Services Generator Security .. 5 MDM Web Services Security .. 5 Password Change Enforcement .. 6 Minimum Length of Password.
10 6 Password Validity Timeframe .. 7 Strong and Secure 8 Deactivating Authorization Credentials .. 8 Password History .. 8 Locking User Accounts .. 8 CLIX Commands for Managing Passwords .. 9 User Administration Tools .. 9 Standard User .. 9 Emergency User Concept .. 10 LDAP Support .. 10 What is LDAP? .. 10 How LDAP Works .. 10 Basic MDM LDAP .. 11 MDM LDAP Fields .. 11 LDAP Access .. 11 MDM LDAP Algorithm (Basic) .. 13 MDM LDAP Algorithm (Alternative) .. 14 MDM LDAP Algorithm (Fallback) .. 14 MDM Architecture in LDAP .. 15 Restrictions and Limitations .. 15 LDAP Errors and MDM.