Set up an incoming connection in SAP Solution Manager

Configure the incoming connection in the ICF Service tree in SAP transaction /nsicf.

  1. In SAP transaction /nsicf, enter ICT_SERVICE_DESK_API as service name.
  2. Execute the search of the service.
  3. Double-click the Service to edit (or navigate to /default_host/sap/bc/srt/rfc/sap/ and select ICT_SERVICE_DESK_API).
  4. Open the Create/Change a Service dialog.
  5. In the Logon tab, select Required with client Certificates (SSL).
  6. Save the settings. Service ICT_SERVICE_DESK_API is configured for SSL connection only. In this procedure the lowest possible security level is specified. If “Required with Logon Data” is configured, then connecting via SSL and the client certificate is allowed.

    Note For SSL communication, ensure that the ICM uses HTTPS.

    Define the user mapping to the DN of the Certificate. The different ways of mapping are described in the SAP online help. Defining a user mapping to a DN is described below.

  7. In SAP transaction /nse16, open the view VUSREXTID (enter VUSREXTID in the table Name field).
  8. Select the Work Area DN of Certificate X.500.
  9. In the user mapping dialog, as an external ID add the DN of the client certificate of Apache Tomcat (see Create keystore and truststore). Specify the exact DN of the certificate. For example:

    CN=helen2006.asiapacific.hpqcorp.net, OU=TEST, O=GDCC, L=SH, SP=CN, C=CN

  10. For Seq. No, enter 000, 001… (for internal use only).
  11. Assign the SAP user for the Web Service. This user has all required permissions for managing incidents in SAP Solution Manager.