Tuesday, July 28, 2009

Configure SAProuter SNC Certificate

1. Use the same account that the SAProuter server runs as
2. stop the router service
3. backup the router folder
4. change to the sap router directory
5. rename or delete these files: certreq, srcert, local.pse, and cred_v2
6. generate the certificate request using the following command:
sapgenpse get_pse –v –r certreq –p local.pse “CN=SAProuter CA, OU=SAProuter, O=SAP, C=DE”  do not enter a PIN (just press enter)
7. copy the contents of certreq to the clipboard
8. browse to http://www.service.sap.com/saprouter-sncadd
9. paste the contents of the clipboard into the form
10. step through form to generate new certificate information
11. copy and paste new certificate data into a file called srcert
11. import the certificate using the following command
./sapgenpse import_own_cert –c srcert –p local.pse
do not enter a PIN (press enter)
12. setup the login using the following command
sapgenpse seclogin –p local.pse
this will create a final file called cred_V2
13. check if the certificate has been loaded correctly by using the following command:
sapgenpse get_my_name –v –n Issuer
14. start the router service
15. delete backup router directory made in step 3 if it is no longer needed
CN and OU information will be different and based on the configuration for your company.

No comments:

Post a Comment