Saturday 17 October 2020

Software Authenticity Verification

 An SAP HANA system can be installed using the SAP HANA database lifecycle manager (HDBLCM). Since the installation software is downloaded from outside your network, it cannot be trusted. Therefore, you should first make sure that the components are authentic, before starting the SAP HANA database lifecycle manager (HDBLCM). 

To verify the authenticity of a SAR archive, use the following command:

 /usr/sap/hostctrl/exe/SAPCAR -dVf /usr/sap/hostctrl/exe/ libsapcrypto.so 

To verify the signature the additional components, run hdblcm with the parameter verify_signature. For more information, see SAP Note 2577617. 


  •  the authenticity verification is only enabled by default if the SAP HANA database was installed or updated with an authentic signature. The signature file is located under <inst_path>/<SID>/hdblcm/SIGNATURE.SMF).
  •  If you are not sure whether the SAP HANA system was installed with a valid signature, you can run the SAP HANA resident HDBLCM with the parameter verify_signature. 

No comments:

Post a Comment