This documentation contains general information about SAP System installation – SAP ERP Central Component 2004 SR1 (SAP ECC 5.0), SAP ERP Central Component 2005 SR1 (SAP ECC 6.0) – on Windows when your database is MS SQL Server. It focuses on the ABAP part of the installation and covers the post-installation, which is the fourth section of the first part of the installation. For more information and for the detailed installation procedure see the documentation on SAP Service Marketplace at service.sap.com/erp-inst.
This section provides information on how to perform the post-installation steps of your SAP System. You perform the following steps:
-
Starting and Stopping the SAP System
Check that you can start and stop the SAP System after the installation with the SAP Microsoft Management Console (SAP MMC). With a newly installed MMC you can start or stop installed SAP System administration, you can start or stop the entire system from a single host.
Prerequisites:
You have logged on to the SAP System host as user [sapsid]adm. -
Logging On to the SAP System
You need to check that you can log on to the SAP System using the following standard users. ABAP users:
User
User Name
Client
SAP System user
SAP*
000, 001, 066
DDIC
000, 001
Prerequisites:
-
You have already started the SAP system.
- You have already installed a front end.
-
Installing the SAP License
You must install a permanent SAP license. When you install your SAP System, a temporary license is automatically installed. This temporary license allows you to use the system for only four weeks from the date of installation. Before the temporary license expires, you must apply for a permanent license key from SAP. It is recommended that you apply for a permanent license key as soon as possible after installing your system.
-
Installing the SAP Online Documentation
SAP currently provides an HTML-based solution for the online documentation, including the Application Help, Glossary, Implementation Guide (IMG), and Release Notes. You can display the documentation with a Java-compatible web browser on all front-end platforms supported by SAP. Install the SAP online documentation in your SAP System as described in the README.TXT file contained in the root directory of the online documentation DVD, delivered as part of the installation package.
-
Configuring Remote Connection to SAP Support
SAP offers its customers access to support and a number of remote services such as the EarlyWatch Service or the GoingLive Service. Therefore, you have to set up a remote network connection to SAP. For more information, see SAP Service Marketplace at service.sap.com/remoteconnection.
-
Performing Initial ABAP Configuration
Here you find information about how to perform initial ABAP system configuration.
-
Go to the following place in the SAP Library:
help.sap.com/nw2004s - SAP NetWeaver Library - SAP NetWeaver by Key Capability
-
Check the documentation on the following configuration steps:
-
Configuring the transport management system
For more information, see Solution Life Cycle Management by Key Capability - Software Life Cycle Management - Software Logistics - Change and Transport System.
-
Performing basic operations
For more information, see Solution Life Cycle Management by Key Capability - System Management:
Operation
Section in SAP Documentation
Set up operation modes – transaction RZ04
Configuration - Operation Modes
Set up logon groups – transaction SMLG
Configuration - Logon Load Distribution - SAP Logon
Set up administrators
Background Processing - Authorizations for Background Processing
Schedule background jobs
Background Processing
Install a printer
SAP Printing Guide
Configure the system log
Tools for Monitoring the System - System Log - Configuring the System Log
Configuring work processes
SAPinst install SAP Systems with a minimum number of work processes. This is only an initial configuration to get you started after the installation. It is not detailed enough for a production system because the optimal number for each type of work process depends on the system resources and on the number of users working in each SAP System application. For a detailed configuration contact SAP Technical Consulting. For more information about instance profiles, which is where work processes are defined, see Solution Life Cycle Management by Key Capability - System Management - Configuration - Profiles - Profile Files - Instance Profiles.
-
Installing languages and performing language transport
-
Installing languages using transaction I18N:
- If you want to use English only, you must activate the default language once.
- If you want to use languages other than English, you must install them and activate the language settings.
For more information on configuring the language settings, see the online documentation in transaction I18N - I18N Menu - I18N Customizing.
-
Performing language transport using transaction SMLT:
For more information on performing the language transport using transaction SMLT, see Solution Life Cycle Management by Key Capability - Software Life Cycle Management - Software Logistics - Change and Transport System - Language Transport.
-
-
Activating and configuring the integrated Internet Transaction Server (ITS)
-
For more information on activating and configuring the ITS, which is installed automatically with the SAP kernel, see Application Platform by Key Capability - ABAP Technology - UI Technology - ITS / SAP@Web Studio (BC-FES-ITS).
-
For more information about ITS, see SAP Note 742048, where you can find the necessary information if you do not want to use the ITS.
-
-
Maintaining address data
You must maintain your company address to create ABAP system users. For more information on maintaining the company address in your SAP System using transaction SU01, see Application Platform by Key Capability - Business Services - Business Address Services (BC-SRV-ADR) - Addresses in User Administration - Maintenance of Address Data.
Configuring business applications
For more information about how to prepare the SAP System for using business applications, which includes customizing the ABAP system and the business components, see Solution Life Cycle Management by Key Capability - Customizing.
-
-
-
Applying the Latest Kernel and Support Packages
You must always replace the installed kernel with the latest kernel from SAP Service Marketplace. In particular, you must replace the installed kernel if:
-
You installed the kernel executables locally on every host.
- Your central instance host runs on a different operating system than your dialog instance host.
For more information about how to download a kernel, see SAP Note 19466.
You use the Support Package Manager to apply the latest ABAP support packages. For more information about the Support Package Manager and how to use it, see help.sap.com/nw2004s - SAP NetWeaver Library - SAP NetWeaver by Key Capability - Solution Life Cycle Management by Key Capability - Software Life Cycle Management - Software Maintenance - Support Package Manager.
-
-
Performing a Full Installation Backup
You must perform an offline full backup at the end of the installation.
Prerequisites:
-
You have completed client maintenance (for example, client copy).
-
You have stopped:
- The SAP System
- SAP-related services (SAP[SAPSID]-[instance] and SAPOSCol)
- The database
-
You are logged on as user [sapsid]adm.
-
You have shut down the SAP System and database.
-
-
Single Sign-On with Microsoft LAN Manager SSP
Single Sign-On (SSO) is a secure method of logging on to the SAP System that simplifies the logon procedure without reducing security. When your system is configured for SSO, an authorized user who has logged on to the operating system can access the SAP System simply by selecting it in the SAP logon window or clicking the shortcut. No SAP System user name or password is necessary. SSO makes it significantly easier for you to manage SAP System user.
This section describes the option that is the easiest to implement when using a full 32-bit Microsoft Windows landscape. It is a tailored version for SSO with Secure Network Communication (SNC), which uses Microsoft’s domain authentication, LAN Manager Security Service Provider (NTLM SSP). For more information on SNC, see the SNC User’s Guide in the SAP Service Marketplace at service.sap.com/security.
-
Typically, SNC requires an external security product that adheres to the Genuine Security Service API V2 (GSS-API V2) interface and that has been certified by the SAP Software Partner Program. However, in this scenario, SAP provides a library that adheres to the GSS-API V2 interface on one side and that communicates with Microsoft’s NTLM SSP on the other. Since NTLM SSP is already built into Microsoft Windows 32-bit platforms, you do not need to purchase an additional security product to use SSO.
Note that the Microsoft NTLM SSP only provides authentication based on a challenge-response authentication scheme. It is does not provide data integrity or data confidentiality protection for the authenticated network connection. All third-party SNC certified security products offer data integrity and privacy protection. If you want to use these security features, you have to obtain a certified security product. If you use Windows 2000 and higher, alternatively you can use Microsoft Kerberos SSP instead of the NTLM SSP for authentication. For more information, see Single Sign-On with Microsoft Kerberos SSP on the next section.
-
A pure Microsoft Win32 environment is required (Windows 9x, Windows ME, Windows NT, Windows 2000 and higher). The Microsoft NTLM SSP is not available for UNIX or any other operating system.
-
Bi-directional trust between windows domains is required if there are separate domains for users, front-end PC’s, and SAP application servers.
-
The GSS-API V2 library wrapper (gssntlm.dll) must be installed on every application server. For more information about how to get the gssntlm.dll file, see SAP Note 595341.
-
The GSS-API V2 library wrapper must also be installed on every front-end PC.
-
It is recommended that you use 7-bit ASCII character set for all Windows user IDs.
-
When the code page of the SAP System is different from the code page on the Windows machines, it is not possible to enter Windows user IDs that contain 8-bit characters into the USRACL table (for example, by calling transaction SU01). The combination of Windows ANSI (=ISO Latin 1) and the default SAP code page 1100 provides the same encoding of 8-bit characters and permits the use of 8-bit characters with gssntlm.dll.
-
For more information on how to improve the security of your system with third party products, see help.sap.com/nw2004s - SAP NetWeaver Library - SAP NetWeaver by Key Capability - Security - Network and Transport Layer Security - Secure Network Communications.
-
-
Single Sign-On with Microsoft Kerberos SSP
Kerberos Single Sign-On (SSO) is a secure method of logging on to the SAP System that simplifies the logon procedure without reducing security. It is suitable if you use Windows 2000 and higher in your system landscape. When your system is configured for SSO, an authorized user who has logged on to Windows can access the SAP System simply by selecting it in the SAP logon window or clicking the shortcut. No SAP System user name or password is necessary. SSO makes it significantly easier for you to manage SAP System user.
The Application Programming Interface (API) and Kerberos provide the security required for authentication. The advantage of the Kerberos SSO solution is that the security information that has to be exchange between the SAP front-end and the SAP application server is encrypted. In contrast, encryption is not implemented for SSO with Microsoft NTLM SSP, which is based on the Generic Security Service API (GSS-API) interface. When using gsskrb5.dll, the Microsoft Kerberos Security Service Provider (SSP) is interoperable with Kerberos implementations from other vendors and suppliers. To use SSO with application server on UNIX and Windows front-end with gsskrb5.dll, you might have to purchase a Kerberos implementation for the UNIX machines.
Prerequisites:
SSO based on Kerberos can only be set up for users that are members of a Windows 2000 and higher domain.
-
Accessing Configuration Documentation in the SAP Solution Manager
To access configuration documentation in the SAP Solution Manager, you have to connect your newly-installed SAP System to the SAP Solution Manager. For SAP NetWeaver 2004s usage types you can also find configuration documentation in the Implementation Guide at: help.sap.com/nw2004s - SAP NetWeaver Library - Technology Consultant’s Guide.
Prerequisites:
-
You have installed an SAP Solution Manager system as described in the documentation Installation Guide – SAP Solution Manager [3.2 or 4.0] on [OS]: [Database].
-
You have connected your SAP System to the SAP Solution Manager as described in the documentation Configuration Guide – SAP Solution Manager [3.2 or 4.0].
For more information, see SAP Service Marketplace at service.sap.com/instguides - SAP Components - SAP Solution Manager - Release [3.2 or 4.0].
-
-
Implementing ERP ABAP Add-On Components
You can install several Add-On Components to your ERP ABAP system. You can find a detailed description on how to implement each available ERP Add-On Components in the related SAP Notes on SAP Service Marketplace at service.sap.com/erp-inst - MySAP ERP [2004 or 2005] - SAP Notes.
-
Ensuring User Security
You need to ensure the security of the user that SAPinst creates during the installation. For security reasons, you also need to copy the installation directory to a separate, secure location – such as a DVD – and then delete the installation directory. In all cases, the user ID and password are only encoded when transported across the network. Therefore, using encryption at the network layer, either by using the Secure Sockets Layer (SSL) protocol for HTTP connections, or Secure Network Communications (SNC) for the SAP protocols dialog and RFC, is recommended. Make sure that you perform this procedure before the newly installed SAP System goes into production.
Prerequisites:
If you change user passwords, be aware that SAP System users might exist in multiple SAP System clients (for example, if a user was copied as part of the client copy). Therefore, you need to change the passwords in all the relevant SAP System clients.
Procedure:
For the users listed below, take the precautions described in the relevant SAP security guide, which you can find on SAP Service Marketplace at service.sap.com/securityguie:
ABAP Users
User
User Name
Comment
SAP System user
SAP*
User exists at least in SAP System clients 000, 001, and 066
DDIC
User exists at least in SAP System clients 000 and 001
EARLYWATCH
User exists at least in SAP System clients 066.
SAPCPIC
User exists at least in SAP System clients 000 and 001.


