Forum Discussion
SSO to SAP fiori apps accessed via internet using F5 instead of SAP Webdispatcher
I believe this can be achieved being that the SAP Fiori application supports both Kerberos and SAML authentication.
F5's APM can serve up a login page tied to your Azure AD for its auth for the client side. APM can then obtain a Kerberos ticket on the users behalf if Azure AD is properly set up to handle ticket distribution. You can then pass the ticket along to SAP Fiori for transparent server side SSO.
It sounds like you could alternatively setup APM to replace the ABAP front-end server component in a SAML configuration even though SAP's documentation says it only supports the ABAP server in the SAML scenario. APM is a flexible beast.
All the better if LTM is already load balancing the traffic. A lab license on a VE and a proof of concept config would tell you everything you want to know. These gentlemen had a brief discussion about what you want to do:
https://devcentral.f5.com/questions/sap-fiori-apps
Kind regards,
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
