Prerequisites to Use the Client Certificate-Based Security Policy

You must satisfy the following prerequisites if you want to use the Client Certificate-Based security policy with the SAP S/4HANA Cloud Adapter.

Create a Communication User

  1. Log in to the SAP S/4HANA Cloud application with administrator credentials.
  2. Search for Communication Management in the search box in the upper right pane, then click Maintain Communication Users in the search results.
  3. Click New to create a new communication user.
  4. On the Create Communication User page, enter a user name, description, and password. You can click Propose Password to get a system-generated password.
  5. Upload the certificate (.pem file) on the Certificates page.
  6. Click Create.

Create a Communication System

Perform the following steps to create a communication system and assign a communication user to the communication system.

  1. Log in to the SAP S/4HANA Cloud application with administrator credentials.
  2. Search for Communication Management in the search box in the upper right pane, then click Communication Systems in the search results.
  3. Click New to create a new communication system.
  4. Enter a system ID and system name, then click Create.
  5. Click a communication system in the list.
  6. Under Technical Data, enter localhost in the Host Name field.
  7. In the Logical System field, enter a system name.
  8. Click the User for Inbound Communication tab, then click the add (+) icon.
  9. Assign the communication user you created and select the authentication method as SSL Client Certificate.
  10. Click the User for Outbound Communication tab, then click the add (+) icon.
  11. Select the authentication method as User Name and Password, and enter the username and password.
  12. Click Create.
  13. Click Save.
  14. Check that the status is Active.

Create a Communication Arrangement

Follow the steps to create a communication agreement. See Create Communication Agreement.

Upload Client Certificate X.509 into Oracle Integration

Upload the X.509 client certificate. See Upload an SSL Certificate.