Week 2 Unit 1: Security Concept

Similar documents
Week 1 Unit 1: Basics. January, 2015

SAP Solution Manager Focused Insights Setup for ST-OST SP4. AGS Solution Manager SAP Labs France

Week 1 Unit 5: Application Example: Natural Language Processing

SAP Hybris Marketing Cloud Implementation Steps for 1711

S4F05. Asset Accounting in SAP S/4HANA: Customizing and Conversion COURSE OUTLINE. Course Version: 05 Course Duration: 2 Day(s)

SAP Education: Reporting Access User Guide

Complementary Demo Guide

PLM210. Master Data Configuration in SAP Project System COURSE OUTLINE. Course Version: 16 Course Duration: 2 Day(s)

Week 2 Unit 1: Introduction to HTML5 Applications and Git

C4C50. SAP Hybris Cloud for Customer Integration with On-premise SAP Solutions COURSE OUTLINE. Course Version: 20 Course Duration: 4 Day(s)

S4F41. Implementing Cash Management in SAP S/4HANA COURSE OUTLINE. Course Version: 06 Course Duration: 5 Day(s)

S4100. Business Processes in SAP S/4HANA Product Development COURSE OUTLINE. Course Version: 05 Course Duration: 5 Day(s)

S4F00. Overview of Financials in SAP S/4HANA COURSE OUTLINE. Course Version: 08 Course Duration: 2 Day(s)

S4F02. Management Accounting in SAP S/4HANA COURSE OUTLINE. Course Version: 05 Course Duration: 3 Day(s)

TS4C01. SAP S/4HANA Cloud On-boarding Fundamentals COURSE OUTLINE. Course Version: 04 Course Duration: 3 Day(s)

Complementary Demo Guide

Week 3 Unit 3: Adapting Your Custom Code

CLD900. SAP Cloud Platform, Integration Service, Overview COURSE OUTLINE. Course Version: 16 Course Duration: 3 Day(s)

THR94. SAP SuccessFactors Employee Central Time Off COURSE OUTLINE. Course Version: 64 Course Duration: 3 Day(s)

E2E600. Implementation Projects with SAP Solution Manager 7.2 COURSE OUTLINE. Course Version: 18 Course Duration: 5 Day(s)

Week 1 Unit 1: Introducing SAP Screen Personas

SM72D. SAP Solution Manager 7.2 Delta Training COURSE OUTLINE. Course Version: 17 Course Duration: 3 Day(s)

PLM560. SAP Product Lifecycle Costing COURSE OUTLINE. Course Version: 02 Course Duration: 2 Day(s)

S4H01. Introduction to SAP S/4HANA COURSE OUTLINE. Course Version: 03 Course Duration: 2 Day(s)

S4615. SAP S/4HANA Sales - Invoice Processing COURSE OUTLINE. Course Version: 08 Course Duration: Minutes

Intercompany Integration Solution for SAP Business One Centralized Payment

Week 1 Unit 6: Initial Data Analysis & Exploratory Data Analysis

SAPTEC. SAP NetWeaver Application Server - Fundamentals COURSE OUTLINE. Course Version: 16 Course Duration: 3 Day(s)

S4C10. Implementing SAP S/4HANA Cloud - Procurement COURSE OUTLINE. Course Version: 03 Course Duration: 2 Day(s)

S4525. Consumption-Based Planning and Forecasting in SAP S/4HANA COURSE OUTLINE. Course Version: 09 Course Duration:

CP100 SAP Cloud Platform

GTS200. Configuring SAP Global Trade Services COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

SAPX03. SAP Fiori Implementation, Administration and Configuration COURSE OUTLINE. Course Version: 15 Course Duration: 5 Day(s)

Connected Handel: Wie Vernetzung Wertschöpfungsketten

CP100 SAP Cloud Platform

C4C14 SAP Service Cloud

S4C01. SAP S/4HANA Cloud On-boarding Fundamentals COURSE OUTLINE. Course Version: 05 Course Duration: 3 Day(s)

Automated VAT Adjustment for Payments with PPD - Workaround

FS250. Bank Analyzer Overview in Banking Services from SAP 9.0 COURSE OUTLINE. Course Version: 15 Course Duration: 1 Day(s)

S4F40 Cash Management in SAP S/4HANA

S4F01. Financial Accounting in SAP S/ 4HANA COURSE OUTLINE. Course Version: 03 Course Duration: 2 Day(s)

S4F01 Financial Accounting in SAP S/4HANA for SAP ERP FI Professionals

Smarter, Faster, Simpler IoT and the Digitization of Ports Value Chains

S4F29 Profitability Analysis in SAP S/4HANA

PLM310 Maintenance and Service Processing: Preventive

Installation The Intercompany Integration Solution for SAP Business One

UX100 SAP Fiori - Foundation

S4F03. Conversion of Accounting to SAP S/4HANA COURSE OUTLINE. Course Version: 08 Course Duration: 2 Day(s)

S4H00 SAP S/4HANA Overview

C4C12 SAP Hybris Sales Cloud

S4DEV. Hands-on Introduction to Application Programming on SAP S/4HANA COURSE OUTLINE. Course Version: 10 Course Duration: 3 Day(s)

S4PR1 SAP S/4HANA Sourcing & Procurement - Functions & Innovations

S4H01 SAP Business Suite to SAP S/4HANA Delta

S4MA1. SAP S/4HANA Manufacturing - Functions & Innovations COURSE OUTLINE. Course Version: 09 Course Duration:

SG IR8A/IR8E/IR8S Form 2014 new layout (PDF) Configuration document

Tabular Maintenance SAP Product Structure Management

S4H100. SAP S/4HANA Implementation Scenarios COURSE OUTLINE. Course Version: 05 Course Duration: 3 Day(s)

BOCL01 SAP BusinessObjects Cloud

S4H00 S/4HANA Overview

UX102. Introduction to SAP User Experience UIs for Application Consultants COURSE OUTLINE. Course Version: 02 Course Duration: 2 Day(s)

SM255. Change Request Management with SAP Solution Manager Configuration COURSE OUTLINE. Course Version: 18 Course Duration: 5 Day(s)

SAPX01. SAP User Experience Fundamentals and Best Practices COURSE OUTLINE. Course Version: 15 Course Duration: 3 Day(s)

S4F01 Financial Accounting in SAP S/4HANA for SAP ERP FI Professionals

UX102. Introduction to SAP User Experience UIs for Application Consultants COURSE OUTLINE. Course Version: 03 Course Duration: 2 Day(s)

I am connected! Now what?

S4F10. Business Processes in Financial Accounting in SAP S/4HANA COURSE OUTLINE. Course Version: 08 Course Duration: 5 Day(s)

S4130. Business Processes in S/4HANA Asset Management COURSE OUTLINE. Course Version: 05 Course Duration: 5 Day(s)

S4220 Production Planning in SAP S/4HANA

Transform Procurement & Total Spend Management

UX100 SAP Fiori Foundation

FAQs Opportunity Management SAP Hybris Cloud for Customer PUBLIC

SAP Smart Business Service

EWM130. Production Integration with SAP EWM COURSE OUTLINE. Course Version: 16 Course Duration: 2 Day(s)

S4EA1. SAP S/4HANA Asset Management - Functions and Innovations COURSE OUTLINE. Course Version: 05 Course Duration: 1 Day(s)

ACT100 SAP Activate Methodology

S4F80 SAP BPC Optimized for SAP S/4HANA

Intercompany Integration Solution for SAP Business One Discover How the Intercompany Solution Enables Financial Data Consolidation & Provides

BIT665 SAP Information Lifecycle Management (SAP ILM)

S4SD1. SAP S/4HANA Sales - Functions & Innovations COURSE OUTLINE. Course Version: 05 Course Duration: 1 Day(s)

S4F04. SAP S/4HANA Central Finance COURSE OUTLINE. Course Version: 05 Course Duration:

S4225. SAP S/4HANA Production Orders COURSE OUTLINE. Course Version: 09 Course Duration: 5 Day(s)

S4F80 SAP BPC Optimized for SAP S/4HANA

UX412. Mobilizing SAP Fiori Standard Apps COURSE OUTLINE. Course Version: 02 Course Duration: 3 Day(s)

SAP Machine Learning for Hadoop. Customer

ACT200 Agile Project Delivery

ACT200 Agile Project Delivery

FS300 SAP Insurance Overview

Integration Framework for SAP Business One

EWM110. Basic Customizing SAP Extended Warehouse Management COURSE OUTLINE. Course Version: 17 Course Duration:

S4F22. Cost Center and Internal Order Accounting in SAP S/4HANA COURSE OUTLINE. Course Version: 08 Course Duration: 5 Day(s)

S4PR1 SAP S/4HANA Sourcing & Procurement - Functions & Innovations

Week 2 Unit 2: System Landscape Setup and Installation

ACT100 SAP Activate Methodology

5 Steps for Using AI to Avoid Bias in Decision Making

Intercompany Integration Solution for SAP Business One Intercompany Reporting

COURSE LISTING. Courses Listed. Training for Cloud with SAP Enable Now in Manage Sustainable Content. Grundlagen

E2E220. SAP Test Management Overview COURSE OUTLINE. Course Version: 17 Course Duration: 3 Day(s)

PLM315 Customizing Maintenance Processing

BW465. SAP BW/4HANA - User Management and Authorizations COURSE OUTLINE. Course Version: 14 Course Duration:

SAP Business One Service Mobile App

Transcription:

Week 2 Unit 1: Security Concept

Security Concept Topics Authentication & Single Sign-On Authorization Management Web API Protection Identity Propagation 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 2

Security Concept Authentication & single sign-on Your Cloud Platform Web application(s) User Web browser Access-protected Web resources App XS Cloud Platform Authenticate / single sign-on Delegate authentication & identity management Identity Provider (IdP) 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 3

Security Concept Identity provider options on Cloud Platform SAP s public identity provider on the Internet Free service Default identity provider for HCP trial accounts SAP ID service Internet Cloud solution for identity lifecycle management Pay-per-logon requests Preconfigured identity provider for productive HCP accounts SAP Cloud Identity Cloud Platform Integration with a corporate Identity and Access Management solution Prerequisite: SAML 2.0 compliance Bring your own identity provider Corporate network 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 4

Security Concept Authorization management Group is assigned to (static OR federated assignment) is assigned to (static assignment) XS App User is assigned to (static assignment) Role 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 5

Security Concept Web API protection Web browser Native mobile app Desktop / server application Your REST API on Cloud Platform API XS Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 6

Security Concept Identity propagation Initial login App XS API XS API Cloud Platform SAP / Non-SAP Cloud Cloud Connector API SAP/Non-SAP Back-End System(s) Corporate Network Propagated identity 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 7

Security Concept Outlook for this week Unit 2: Securing HTML5 Apps Authenticating users via SAML Managing permissions and roles Unit 3: Securing Java Apps Authenticating users via SAML Managing groups and roles Unit 4: Securing Web APIs Protecting an API using OAuth 2.0 Testing with a REST client Units 5 & 6: Securing Native Services Configuring identity propagation between an HTML5 app and an XS service 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 8

Thank you Contact information: open@sap.com

2016 SAP SE or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://global12.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forwardlooking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions. 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 10

Week 2 Unit 2: Securing HTML5 Apps

Securing HTML5 Apps Authentication: SAML 2.0 neo-app.json { } "authenticationmethod": "saml", "logoutpage": "logout.html",... "routes": [... ], "securityconstraints": [... ],... 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 2

Securing HTML5 Apps Authorization: Roles and permissions User accessprojectdata (Permission) Cloud Platform Employee (Custom Role) Public Resources HTML5 App Protected Resources /projects neo-app.json { }... "securityconstraints": [ "permission": "accessprojectdata", "description": "Protected Project Data", "protectedpaths": [ "/projects" ], ],... 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 3

Thank you Contact information: open@sap.com

2016 SAP SE or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://global12.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forwardlooking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions. 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 5

Week 2 Unit 3: Securing Java Apps

Securing Java Apps Authentication jdoe Username/Password X.509 Client Certificate Cloud Platform web.xml <login-config> <auth-method> [BASIC CERT FORM ] </auth-method> </login-config> SAML 2.0 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 2

Securing Java Apps Authorization User web.xml... <security-role> <role-name>projectmanager</role-name> </security-role> ProjectManager (Predefined Role) Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 3

Thank you Contact information: open@sap.com

2016 SAP SE or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://global12.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forwardlooking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions. 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 5

Week 2 Unit 4: Securing Web APIs

Securing Web APIs OAuth access token REST Client (e.g. native mobile app) Your REST API on Cloud Platform poai3-36d24fd wq59 API Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 2

Securing Web APIs OAuth 2.0 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 3

Securing Web APIs End-to-end flow 1. 1 HCP administrator registers OAuth client for the native mobile app 2. 2 App requests an access token from the OAuth authorization server. This requires the user to authenticate via SAML. 3. 3 App stores the access token and uses it to send an authorized API call 4. 4 The API can verify the token with the OAuth authorization server and returns the response to the app REST Client (e.g. native mobile app) 3 poa wq59 OAuth API 2 4 SAML OAuth 2.0 authorization server Cloud Platform Your REST API on Cloud Platform SAML 1 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 4

Securing Web APIs Using OAuth on Cloud Platform web.xml <filter> <display-name>oauth Filter to view sales data</display-name> <filter-name>oauthviewsalesdatafilter</filter-name> <filter-class> com.sap.cloud.security.oauth2.oauthauthorizationfilter </filter-class> <init-param> OAuth <param-name>http-method</param-name> API <param-value>get</param-value> </init-param> </filter> <filter-mapping> <filter-name>oauthviewsalesdatafilter</filter-name> <servlet-name>salesdataservlet</servlet-name> </filter-mapping>... Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 5

Thank you Contact information: open@sap.com

2016 SAP SE or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://global12.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forwardlooking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions. 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 7

Week 2 Unit 5: Securing SAP HANA Native Services Part 1

Securing Native Services Part 1 Using XS on Cloud Platform Your HCP Account User REST/ ODATA API Cloud Platform XS Dedicated or shared 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 2

Securing Native Services Part 1 User authentication and propagation Your HCP Account User SAML Login Identity Propagation API XS Authentication & SSO Dedicated or shared Identity Provider (IdP) Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 3

Securing Native Services Part 1 Focus of Units 5 and 6 Your HCP Account User SAML Login Identity Propagation API XS Authentication & SSO Dedicated or shared Identity Provider (IdP) Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 4

Securing Native Services Part 1 Identity propagation between HTML5/Java and XS Your HCP Account HTTP Destination (App2AppSSO*) API (SAML) XS Dedicated or shared Cloud Platform * Application-to-Application SSO Authentication 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 5

Securing Native Services Part 1 Trust setup Your HCP Account Local Service Provider TRUST SAML Identity Provider HTTP Destination (App2AppSSO*) API (SAML) XS Cloud Platform * Application-to-Application SSO Authentication 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 6

Securing Native Services Part 1 User management Your HCP Account Dynamic User Creation HTTP Destination (App2AppSSO*) API (SAML) SAML Identity Provider XS DB User Cloud Platform * Application-to-Application SSO Authentication 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 7

Securing Native Services Part 1 Configuration steps of the end-to-end scenario Unit 5 Part 1 Configure the local service provider for HTML5 apps Set up trust in XS to the HTML5 local service provider Enable dynamic user creation in XS Unit 6 Part 2 Configure HTTP destination for application-to-application SSO Configure SAML in XS Test the scenario 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 8

Securing Native Services Part 1 What you ve learned in this unit How to build Cloud Platform applications using HTML5 and XS The difference between authentication and propagation of a user s identity Configuration of trust between HTML5 and XS as a prerequisite for secure identity propagation 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 9

Securing Native Services Part 1 Further reading!i Additional Material http://scn.sap.com/community/developer-center/cloudplatform/blog/2016/03/21/principal-propagation-betweenhtml5-and-sap-hana-xs-on-sap-hana-cloud-platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 10

Thank you Contact information: open@sap.com

2016 SAP SE or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://global12.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forwardlooking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions. 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 12

Week 2 Unit 6: Securing SAP HANA Native Services Part 2

Securing Native Services Part 2 Identity propagation scenario Your HCP Account User SAML Login Identity Propagation API XS Authentication & SSO Dedicated or shared Identity Provider (IdP) Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 2

Securing Native Services Part 2 What we did in Part 1 Your HCP Account Local Service Provider TRUST SAML Identity Provider Dynamic User Creation XS DB User Cloud Platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 3

Securing Native Services Part 2 What we will do in Part 2 Local Service Provider Your HCP Account TRUST SAML Identity Provider Dynamic User Creation HTTP Destination (App2AppSSO*) API (SAML) XS DB User Cloud Platform * Application-to-Application SSO Authentication 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 4

Securing Native Services Part 2 What you ve learned in this unit How to configure a destination to propagate the user s identity from HTML5 to XS How to configure SAML in XS to support identity propagation from HTML5 How to test the scenario end-to-end 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 5

Securing Native Services Part 2 Further reading!i Additional Material http://scn.sap.com/community/developer-center/cloudplatform/blog/2016/03/21/principal-propagation-betweenhtml5-and-sap-hana-xs-on-sap-hana-cloud-platform 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 6

Thank you Contact information: open@sap.com

2016 SAP SE or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://global12.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices. Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE s or its affiliated companies strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forwardlooking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions. 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 8