Afaria Setup 3: Install roles – Certificate Authority

Published by Tobias Hofmann on

1 min read

SAP Afaria needs to have a Certificate Authority (CA) available to emit certificates and to enroll iOS devices, or the make use of SCEP so your users can obtain their user certificate. Therefore, a new CA is installed. In Windows Server, select the add role option:

Select the role: Active Directory Certificate Services

Select Certification Authority Web Enrollment. Add required dependencies

In the next shown dialog, select both

  • Certificate Authority and
  • Certification Authority Web Enrollment

Service type: Enterprise

While you can set up a CA in standalone mode, Afaria will need Enterprise mode to work. This is also the reason why you have to use Windows Server 2008 R2 Enterprise version. Only there the Enterprise option for the CA is available. With Windows Server 2012 the standard version also offers a CA needed by Afaria, but right now, Afaria is not supporting Windows Server 2012.

Install a Root CA. Needed as this will be the first and only CA available.

Create private key.

Select key strength.

Inform name of CA as shown in the root certificate.

Validity period of certificate. While normally a CA’s certificate is valid for 10 or 20 years, mine will be only 5 years. But that value is up to you.

Confirm location of CA database on the server.

Role services dialog is shown. Add ASP.NET

Select in the security section the authentication method to be used. Add:

  • Basic Authentication
  • Digest Authentication

Confirm the configuration data.

CA is going to be installed and configured.

Check installation result.


Let the world know

Tobias Hofmann

Doing stuff with SAP since 1998. Open, web, UX, cloud. I am not a Basis guy, but very knowledgeable about Basis stuff, as it's the foundation of everything I do (DevOps). Performance is king, and unit tests is something I actually do. Developing HTML5 apps when HTML5 wasn't around. HCP/SCP user since 2012, NetWeaver since 2002, ABAP since 1998.


Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.