This section describes how to install and configure the PingFederate Integration Kit for SAP NetWeaver for an IdP.

  1. Shut down the PingFederate server.
  2. Unzip the distribution .zip archive.
  3. Copy the pf-netweaver-adapter-1.0.jar file from the dist directory to this location:
    [PingFederate installation directory]/server/default/deploy
  4. Obtain the SSO extension library from SAP and install the libraries on the system running PingFederate (see System requirements).
  5. Restart the PingFederate server.
  6. Log on to the PingFederate administrative console and click Adapters from the My IdP Configuration side of the Main Menu.

    For more information, see Configuring an IdP Adapter instance in the PingFederate documentation.

  7. Click Create New Adapter Instance.
  8. Enter the Instance Name and Instance ID. Select PF4 NetWeaver IdP Adapter v1.0 as the Type and click Next.
  9. Enter the values for adapter configuration described below and click Next.
    Property Description

    Domain Name

    Your domain name, preceded by a period (e.g., “.pingidentity.com”).

    SAP TicketName

    The name of SAP session ticket for SSO.

    PSE File

    The path to verify.pse. This file contains the public key for verifying the digital signature. Contact SAP support to obtain this file.

    PAB Password

    The private address-book password for accessing the public key.

    Login URL

    An optional URL where the user is redirected if SAP session ticket is not found.

  10. Optionally, on the Extended Contract tab, you can configure additional attributes for the adapter. For more information, see Key concepts in the PingFederate documentation.

    For instance, you can use the extended adapter contract for Policy Server response-object attributes. Click Next.

  11. On the Adapter Attributes tab, select userId under Pseudonym. You can also select any extended attributes specified in the previous tab. Click Next.

    For more information about this tab, see Setting pseudonym and masking options in the PingFederate documentation.

  12. On the Summary tab, verify that the information is correct and click Done.
  13. Click Save to complete the adapter configuration.