Configuring provisioning for SAP Netweaver

This configuration provisioning guide provides the basic information that you need to install and configure the NetWeaver adapter. The adapter enables connectivity between the IBM® Security Verify server and a system that runs the SAP Netweaver server.

Before you begin

Note: SAP Netweaver provisioning is not supported for trial subscriptions.
  1. Make sure Security Directory Integrator (SDI) v7.2 (PN CJ30YML) is installed for your operating system. See https://www.ibm.com/support/knowledgecenter/SSIGMP_1.0.0/com.ibm.itim_pim.doc/dispatcher/install_config/dispatcher_html_mstr.htm.
    Table 1. SDI part numbers
    eAssembly number Operating system eImage number
    CJ30YML AIX CIS7MML
    Linux CIS7TML
    Solaris CIS7UML
    Windows CIS7QML
    For more information, see IBM Security Directory Integrator Version 7.2 Download Document.
    Note: The default document is for AIX. Scroll down to step 3 to select your operating system.
  2. Install and configure Security Directory Verify Adapter RMI Integrator dispatcher for Security Directory Integrator v7.2 (P/N CC7ZMML). See https://www.ibm.com/support/pages/ibm-security-identity-adapters-v7x and SDI Dispatcher installation and configuration.
  3. Onboard the SAP Netweaver application. See, Onboarding the SAP Netweaver Application.

About this task

Provisioning provides the following features.

Create new users
New users that are created through Verify are also created in the SAP Netweaver application.
Delete users
Deactivating the user or disabling the user's access to the application through Verify deletes the user in the SAP Netweaver application.
Modify user profile
Updates made to the user's profile through Verify are pushed to the SAP Netweaver application.
User suspend and restore
Suspending a user through Verify deactivates the user and restoring the user through Verify activates the user in the SAP Netweaver application.
User synchronization and remediation
Synchronization fetches all the SAP Netweaver application users, creates the users on Verify, and according to the remediation policy, modifies the attributes. Group synchronization fetches all the target application groups in Verify.
Fine grained entitlement
Fine grained entitlement is supported for the SAP Netweaver application. Synchronization fetches all SAP Netweaver application groups. Users can be added to or removed from groups.

Procedure

  1. Login to Verify as an administrator.
  2. Select Applications > Applications.
  3. Select Add application.
  4. Select application of type SAP Netweaver.
  5. To configure user provisioning in Verify, you need the following information:
    • Tivoli Directory Integrator location
    • SAP System (DNS hostname or IP)
    • Target Client
    • Login ID
    • SAP System Number
    • Logon Language
    • Password
    • Identity agent
    • Description
    • SAP Gateway (DNS hostname or IP)
    • Optional RFC Connection Parameters?
    • Enable TDI Debugging?