Skip to Content
avatar image
Former Member

PI connecting to WS using Kerberos

Hi

From PI we are supposed to connect to a web service using kerberos authentication.

We have not found much information regarding a "how-to" on this. Maybe you could help?

-> Do we use SOAP or WS adapter?

-> If WS adapter, what authentication method do we use?

-> If SOAP adapter, we assume it is "Axis" message protocol, but what authentication method do we use? Certificate?

-> Any other things we have to be aware of when configuring Kerberos authentication?

Thanks!

regs S

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

2 Answers

  • Sep 09, 2011 at 02:35 PM

    Use SOAP adapter. Regarding authentication use certificate. I think you can use both Axis or plain SOAPadapter for authentication (Depends on the end system requirement).

    Add comment
    10|10000 characters needed characters exceeded

    • Former Member

      Hi

      Thank you!

      Still I am not sure if this is the whole solution - don't we have to configure anything in PI, only provide a certificate?

      Do we have to provide 2 interfaces, one towards the Active Directory and one towards the service?

      I have searched notes and forums, but there is no resource explaining the steps needed in PI, only how to configure java stack etc, so that is why I'm asking if a certificate should be enough.

  • avatar image
    Former Member
    Oct 29, 2011 at 03:43 PM

    Hi,

    Kerberos authentication is not supported for SOAP Web Serices with the WS Adapter neither as consumer nor as provider.

    Wheter it's possible with SOAP Adapter? I don't know for sure but I doubt it will work.

    If it would be supported you would't need to specify any certificate. The whole trust setup (you usually do this by exchanging certificates) would be based on the fact that the application server where the ABAP runs on is part of o kerberos realm (e.g. MS Active Directory Domain). So the trust setup has already been done on operating system level.

    What other authentication options instead of Kerberos are available on the provider side?

    Regards,

    Mathias

    Edited by: Mathias Essenpreis on Oct 29, 2011 5:47 PM

    Add comment
    10|10000 characters needed characters exceeded