Managing Security of the Intercompany Integration Solution

Managing Security of the Intercompany Integration Solution

This section explains how to implement a security policy for the intercompany integration solution for SAP Business One and provides recommendations for meeting security demands.

Managing Security of the Intercompany Landscape

The intercompany integration solution is powered by the SAP Integration Framework 2.0 (B1if) which manages and controls the security aspects related to the intercompany integration solution.

The integration framework security guide gives you information that explains how to implement a security policy and provides recommendations for meeting security demands for the integration framework.

To optimize the security of the intercompany integration solution, you should do the following:
  1. Implement security policies as suggested in the  Integration Framework - Online Help For more information, choose  Start  →  All programs  →  Integration solution for SAP Business One  →  Integration Framework , and then choose  Help  →  Online Help  →  Operations Part Two , section 3, Security
  2. Use the HTTPS protocol to access the  Administration Console Assign a strong login password and change the password periodically.
  3. Create additional users for managing access to the  Administration Console . This avoids logins with the same credentials by multiple users, and thus produces traceability to specific users.  Monitor audit logs to track changes regularly.
  4. To make communication safer, you have the option to use HTTPS for the sessions in the integration framework. On the server side you can configure the communication protocol (HTTP or HTTPS). On the client side, you have the option to switch to the HTTPS protocol. By default, the solution runs with HTTPS, and the integration framework allows incoming calls through HTTPS only.  Default: port 8080 for HTTP, or port 8443 for HTTPS

Managing Security of the Integration Solutions Add-On

To optimize the security of the integration solutions add-on, you should do the following:
  1. Implement security policies as suggested in the  section   Managing Security in SAP Business One  in SAP Business One Administrator's Guide on  SAP Help Portal .
  1. Set up additional authorizations for the new screens created by the  intercompany integration solution. Choose  Administration  →  System Initialization  →  Authorizations  →  General Authorizations 
  2. In the  Subject column, click on the arrow to expand the  User Authorization field. Expand the  Intercompany field and set up the relevant authorizations for the users.   
  3. Change the encryption key periodically. Choose  Administration  →  Setup  →  Intercompany  →  Encryption Key
  1. Use the HTTPS protocol for executing reports and consolidations. Choose  Administration  →  Setup  →  Intercompany  →  B1i Server Details . Enter the following details:
Field Description
Definition
HTTPS

Check this box to enable the solution to use HTTPS. 

B1i Server Address

Enter the server name of the B1i server.

B1i Port

Enter the HTTPS port of the B1i Server. 

The default port is 8443.

User Name

Enter the user name of an active B1iP user

Password

Enter the password of the B1iP user



Caution

To use the HTTPS protocol, you must first configure the communication protocol on the server side and install the self-signed certificate generated during installation of the SAP Business One integration components.