SAP NETWEAVER STANDARDS SUPPORT:
Security
SAP offers a broad range of security mechanisms and services to meet the highest demands for data integrity, protection, and confidentiality – and to support authentication, authorization, and secure information exchange.
SAP NetWeaver supports a variety of authentication mechanisms to ensure that the right people have access to the right applications – including standard X.509 digital certificates, smart cards, ticketing, and username and password authentication. Pluggable authentication and support for the Java Authorization and Authentication Service (JAAS) let you integrate your preferred authentication technique. Single sign-on removes the burden of remembering various usernames and passwords.
A comprehensive authorization mechanism allows both coarse and fine-grain authorization management. Users can be granted access to information, applications, and services automatically based on their specific roles. User information can be managed centrally and synchronized with an LDAP-enabled directory. Authorization mechanisms based on access control lists are also available.
Encryption features ensure that information exchanged among users remains private. Support for HTTPS, the secure variant of HTTP, is included. Plus, a feature for secure network communications uses external security solutions to protect communications links among the distributed components of your SAP solution.
To enable secure interoperability, SAP NetWeaver supports industry standards such as Security Assertions Markup Language (SAML) and XML-Signature. Secure store-and-forward mechanisms can take advantage of external security solutions to protect data. Digital signatures offer nonrepudiation, while digital envelopes wrap data and documents in secure formats before they are stored or transmitted. Trust center services for public key infrastructure (PKI) are also provided.
Finally, the security audit log records events, such as log-on attempts and transaction starts, while the Audit Info System offers a summary of reports that provide key security information.