SAP BO 4.0 Single Sign-On (SSO) using SAP BW credentials

Hello Experts,

Did anyone succeed with configuring SSO-enabled OLAP Connection with SAP BW?
The error message:
“com.sap.conn.jco.JCoException: (103) JCO_ERROR_LOGON_FAILURE: Issuer of SSO ticket is not authorized on mspsap02.xxx.com sysnr 17”

The scenario:
SAP BW 7.01
SAP BusinessObjects 4.0 sp4 fp4

We followed steps from note 1311904 (How to set up and configure a Netviewer connection from the SAP Service Marketplace (SMP)).
Is anyone having the same problem?

Thanks in advance,
Stanislaw


stahn (BOB member since 2010-12-02)

hi Stahn,

I am facing the same problem!
did you manage to find out what is wrong!

cheers,
Mamood


Mamood04 (BOB member since 2008-02-04)

Hi Mamood04,

we had several calls with SAP support, but without any succeses so far.
How about you?
Do you know any workaround for that?

Thanks in advance,
Stanislaw


stahn (BOB member since 2010-12-02)

Hi Stanislaw,

I am still facing the same issue, I am not sure tho is it a BO problem or is there something on SAP BW side needs to be configured!

Have you heard from SAP! I am willing to get in touch with them and see if they can help.

Regards,
Mamood


Mamood04 (BOB member since 2008-02-04)

We have our setup little differently. Our authentication is based on SAP ERP system but we have recently setup SSO to SAP BW successfully.

We had to add SAP BW as a logical system (in addition to the existing SAP ERP) in BO 4.0 and map a dummy SAP role from BW into BO.

Prerequisite was to

  • generate the keystore file and the certificate
  • import them into SAP BW
  • import them in SAP BO

These steps are detailed well in Admin guide.


cpmohanraj :australia: (BOB member since 2002-09-23)

Hi cpmohanraj,

Thanks for input to this discussion.

Is your SSO setup works correct also with OLAP connections using BICS and SSO created in IDT (Information Design Tool) ?

Importing and mapping sap users to BO is working fine for us. But problem start with OLAP connection.

The same problem is describted by Mamood04 in separate post: BICS OLAP connection to BW with SSO


stahn (BOB member since 2010-12-02)

Our OLAP (BICS) connection was created in the CMC and not in IDT. And the users are able to test the SSO from Web Intelligence Rich Internet Application by running couple of BEx queries. Also our SAP Security Admin has mentioned that the CRYSTAL user had to be setup differently in SAP BW compared to SAP ERP. It needed additional authorizations

Cheers
Mohan


cpmohanraj :australia: (BOB member since 2002-09-23)

I have the same scenario, which SAP BO are you using? I am on SAP BO SP4.

what I did so far,

-SAP ERP Authentication to BO, imported the roles and all good
up to here and SAP ERP user who’s role imported to BO can log on to bo using SAP authentication

-generated the certificate and keystore, imported the cert into BW and the keystore into BO. (and added a new Logical system connecting to BW and imported 1 role, is there any recommended configuration for this role!).

Now I still can’t use SSO into BW,
I created few BICS connection using SAP ERP user name (Using specified user name and pass) and able to connect to IDT using the same user, but when I try SSO and test connection it it through back Test failed.

I have read all documents and so far can’t resolve this issue.

Regards,
Mamood


Mamood04 (BOB member since 2008-02-04)

The additional authorization was needed for the account with which we set up the SAP BW as a logical system in CMC. The roles imported do not need any special authorization.

Our SAP admin has enabled the trace on her side to see what was happening and found out that this account needed more authorizations.


cpmohanraj :australia: (BOB member since 2002-09-23)

Thanks Mohan for your contribution.
I used my BW user to import the role from BW ( when you log on to BI launch pad use BW info not SAP ERP) and it is working now, so will just have to recreate another crystal user and check with SAP BW admin on what rights the user needs.

Stahn any luck! Forget about IDT just create OLAP connections from CMC, I don’t know whats wrong with IDT, however, it even easier to use CMC.

let me know if it still didn’t work and I can review it with you step by step.

cheers.

Mamood


Mamood04 (BOB member since 2008-02-04)

hey,
can anyone of you guys give us the complete details as to how you went about the same?
I am trying to figure out how to implement the same via the admin guide and not able to figure out everything.


yuvi :india: (BOB member since 2009-10-04)

Hi Yuvi,

Please have a look on this:

http://wiki.sdn.sap.com/wiki/display/BOBJ/How+to+setup+SSO+against+SAP+BW+with+SAP+BO+BI4.0+Common+Semantic+Layer+(UNX)+or+BICS

Regards,
Mahmoud


Mamood04 (BOB member since 2008-02-04)

Hello All,

We have had a similar issue with the below error code in WebI and i have mentioned the solution that has worked for me below.

Error : "The following database error occurred: Unable to connect to SAP BW server System received an expired SSO ticket. For information about this error, please refer to SAP Knowledge Base Article 2054721 on the SAP Support Portal. (IES 10901) "

When i checked the Universe connection parameters and looked into the “Logon-Group” …it was using a old group name.
I updated it to the correct login group and it fixed the issue.

we are using BO 4.1 SP 4.4 and SAP BW as the data source.


frilto (BOB member since 2009-10-11)