Setting Up Adobe Document Services (ADS) on SAP NetWeaver 7.5: ABAP Integration & Validation

Step-by-step setup of ADS on NetWeaver AS Java 7.5 for ABAP/S/4HANA: ADSUSER and ADS_AGENT, SM59 and Java callback destinations, ICF services, PDF validation, optional Reader Rights credentials, and troubleshooting.

1. Scope and Communication Flow #

This runbook configures Adobe Document Services (ADS) on SAP NetWeaver AS Java 7.5 for an AS ABAP / SAP S/4HANA system. It covers technical users, destinations, ICF services, PDF tests and optional Reader Rights credentials. ADS must already be installed; these steps do not install the Java system or the ADS software components.

The starting reference is the SAP Community article ADS Configuration in Netweaver 7.5, published on 2 November 2016. This runbook adds a diagnostic test sequence and configuration clarifications from SAP Help.

AS ABAP / S/4HANA
  |
  | SM59 destination ADS
  | Authentication: ADSUSER in the Java UME
  v
AS Java 7.5 / Adobe Document Services
  |
  | Java destination FP_ICF_DATA_<ABAP_SID>
  | Authentication: ADS_AGENT in the ABAP client
  v
AS ABAP ICF: /sap/bc/fp
             /sap/bc/fpads when distributed bundling is required

The two directions use different identities. ADSUSER authenticates calls to ADS. ADS_AGENT lets the Java destination access the ABAP forms repository. Confirm the Java UME data source before deciding where to create ADSUSER.

SAP documents automatic initial configuration followed by manual correction of individual steps. Its NetWeaver 7.5 Help pages also refer to SAP Note 2212573 for later corrections; check the instructions applicable to your installed support package. SAP Help: Basic ADS configuration for ABAP

2. Preparation #

Record the values below before changing either system. Values in angle brackets are placeholders, not settings to copy literally.

Item Value to record
ABAP system <ABAP_SID> and the business client <CLIENT>
ADS endpoint Java FQDN or the designated Web Dispatcher endpoint
ABAP callback endpoint ABAP HTTP(S) FQDN and port reachable from the Java hosts
Java identity source Local Java UME or ABAP-backed UME; identify its authentication client
Connection names Usually ADS and FP_ICF_DATA_<ABAP_SID>
Test output device An existing device configured for PDF-based forms

Verify DNS, routing and the required ports in both directions. Obtain access to Java NWA / UME and to SU01, PFCG, SM59, SICF and SA38 in ABAP. Record existing configuration before replacing it.

The classic examples use HTTP and Basic Authentication. For production, use the approved TLS configuration for your landscape. Server trust, client-certificate authentication and credential aliases are separate settings; changing only the port does not configure all of them. SAP Help: SSL connection to ADS

3. Configure ADSUSER and the ABAP-to-ADS Connection #

3.1 Java UME with a Local Identity Store #

  1. Open the Java Identity Management application, normally /useradmin.
  2. Locate the existing ADSUSER, or create the technical user if it is missing. Use the exact logon ID configured in your landscape.
  3. Select the technical-user security policy supported by your release.
  4. Assign the delivered UME role SAP_ADSCALLER directly to the user, or through an ADSCALLERS group.
  5. Save and confirm that the account is usable.

The community article also assigns SAP_ADSMONITOR. Treat monitoring privileges as a separate requirement; the caller role is the one documented for accessing ADS. SAP Help: Java user configuration

3.2 Alternative: Java UME Backed by ABAP #

  1. Log on to the ABAP client used by UME, which may differ from the forms business client.
  2. In SU01, create or maintain ADSUSER as a System user and set its password.
  3. In PFCG, create and activate the ADSCALLERS role, then assign it to ADSUSER. This role acts as the UME group mapping; it is not an ADS ICF authorization profile.
  4. In Java UME, assign SAP_ADSCALLER to the mapped user or group and verify the role assignment.

Do not create this mapping merely because an ABAP system exists: it applies when Java UME actually uses that ABAP identity source. SAP Help: ADS authentication user in an ABAP environment

3.3 Create Destination ADS in SM59 #

On the calling ABAP system, maintain the classic Basic Authentication destination:

SM59 field Setting
RFC Destination ADS, or the name explicitly used by your application
Connection Type G — HTTP connection to an external server
Target Host ADS Java host or the designated Web Dispatcher host
Service No. Actual HTTP port; commonly 5<Java_instance_number>00
Path Prefix /AdobeDocumentServices/Config?style=rpc
Authentication Basic Authentication
User / Password The ADS caller account and password maintained in UME

Save the destination. In the documented classic setup, the query-string warning can be acknowledged. A standalone SM59 connection test returning HTTP 404 does not prove ADS is broken: validate the ADS operation with FP_PDF_TEST_00. This exception is specific to that test and endpoint; investigate other 404 responses normally. SAP Help: ABAP Basic Authentication destination

4. Configure the Java-to-ABAP Callback #

4.1 ADS_AGENT in the Forms Client #

In SU01, create or maintain ADS_AGENT in the ABAP client containing the forms. The NetWeaver 7.5 Help procedure specifies user type Service. The community article uses System; check your approved account policy and release-specific instructions rather than treating those screenshots as the default.

Select the role for the actual topology:

Topology in SAP Help ADS_AGENT authorization role
Separate AS ABAP and AS Java systems SAP_BC_FPADS_ICF
Same-server / documented double-stack or Java-hub scenario SAP_BC_FP_ICF

Use the relevant delivered role or an approved customer copy. Do not automatically grant both roles or attach ADSCALLERS to this account: the caller mapping belongs to the ADSUSER / UME scenario. Record the client and password for the callback destination. SAP Help: Service user for communication with ADS

4.2 Activate the Required ICF Nodes #

In SICF, navigate to default_host → sap → bc → fp and activate the required service. For distributed form bundling, also activate default_host → sap → bc → fpads.

Limit activation to the services required by the scenario. /sap/bc/fp is the forms-repository path; /sap/bc/fpads supports the additional distributed-bundling flow. SAP Help: ICF activation

4.3 Java Destination FP_ICF_DATA_<ABAP_SID> #

On the Java system hosting ADS, open NWA Destinations. Menu labels vary by support package; SAP Help lists Configuration Management → Security Management → Destinations.

Field Setting
Destination name FP_ICF_DATA_<ABAP_SID> — use the ABAP SID, not the Java SID
Destination type HTTP
URL ABAP base URL: http://<ABAP_HOST>:<HTTP_PORT> or the configured HTTPS equivalent
Client Client in which ADS_AGENT was created
System ID / Language fields Leave empty for the documented basic setup
Authentication Basic
User / Password ADS_AGENT and its ABAP password

Save and verify connectivity. For HTTPS, configure certificate trust according to the platform procedure; do not adopt a legacy “ignore certificates” example as a production setting. SAP Help: Callback destination

5. Optional Configuration for Java Form Applications #

For a Java PDF Object Layer / Web Dynpro Java caller, maintain the corresponding destination template on the Java system hosting the application:

  1. In NWA, open SOA Management → Technical Configuration → Destination Template Management.
  2. Create or verify the case-sensitive name ConfigPort_Document.
  3. For the documented WSIL setup, select type WSIL and use http://<ADS_HOST>:<ADS_PORT>/inspection.wsil.
  4. Configure HTTP Authentication with Basic credentials for ADSUSER and save.

This is a different destination from FP_ICF_DATA_<ABAP_SID>. It is relevant to Java form callers and should not be confused with the ABAP SM59 configuration. SAP Help: Basic Authentication for Java forms

If this is a fresh installation, the ADS functional-unit configuration tool can perform the initial setup automatically. Select the Adobe Document Services functional unit and review its results before making manual corrections. SAP Help: Basic Java ADS configuration

6. Validate the Configuration #

6.1 ADS Version Test #

In SA38 or SE38, run FP_PDF_TEST_00 with destination ADS or the configured alternative. A successful result displays the ADS version. This verifies the forward connection and the ADS operation; it does not replace the callback and end-to-end tests. SAP Help: ABAP connection test

6.2 Destination-Service and ICF Test #

Run FP_CHECK_DESTINATION_SERVICE twice: first without With Destination Service, then with it. Both runs should report successful PDF generation and its size.

For isolation, test the ABAP layout URL with ADS_AGENT in the correct client:

http://<ABAP_HOST>:<ABAP_PORT>/sap/bc/fp/form/layout/fp_test_00.xdp?sap-client=<CLIENT>

Expect the form layout as XML. You can temporarily use this layout path in the Java destination and run Ping Destination, expecting HTTP 200 with XML content. Restore the destination to its base URL afterward. An authenticated layout check is more useful than pinging a generic root page. SAP Help: Destination and ICF tests

6.3 End-to-End PDF Preview #

Run FP_TEST_00 with form FP_TEST_00 and the ADS destination. Select a configured output device and choose Print Preview. The standard sample should render as a readable two-page form.

LP01 is only an example from the community article; use a device that exists and supports the required PDF output in your system. After the sample succeeds, test one representative business form and its real output path. SAP Help: ABAP ADS configuration test

7. Optional Reader Rights Credential #

Reader Rights adds usage rights for interactive PDF workflows. Treat it as a separate requirement from confirming that ADS can render a basic PDF. It does not itself certify or digitally sign a document. Obtain the company-specific credential through the applicable SAP process; SAP Help refers to SAP Note 736902. SAP Help: Reader Rights

  1. On the ADS Java system, open NWA Adobe Document Services → Document Security → Credentials.
  2. Under Manage P12 Files, upload the supplied PKCS#12 .pfx credential.
  3. Create its credential record with alias ReaderRights, type P12, and select the uploaded file.
  4. Enter the password supplied with the credential. Keep the SHA1 field empty for the ReaderRights alias in the documented procedure.
  5. Apply the required service restart in a planned change window, then repeat the applicable tests. The PKCS#12 installation procedure specifies Document Service Trust Manager Service, followed by PDF Manipulation Module; check release-specific restart instructions.

Do not confuse the P12 password with the ADSUSER or ADS_AGENT passwords. Digital signatures and certification use separate aliases, credentials and configuration.

References: PKCS#12 installation, Credential attributes, Credential types and aliases.

8. Troubleshooting and Handover #

The table below is a diagnostic checklist inferred from the communication flow and SAP test procedures. It is not a claim that every HTTP error has a single cause.

Symptom First checks
Timeout / connection refused Correct FQDN and port, DNS, firewall, listener and destination direction
401 or repeated credential prompt on the ADS call ADSUSER password, account state, UME data source and configured authentication
403 from ADS Caller role assignment and endpoint access; inspect the matching Java log entry
ADS version succeeds, callback test fails FP_ICF_DATA name, ABAP client, ADS_AGENT authorization, ICF activation and Java-to-ABAP reachability
Layout URL fails or returns a logon page Correct client, ICF node, credentials, virtual host and routed path
TLS handshake error Certificate chain, hostname, selected trust store and any required client-certificate mapping
Version test succeeds, PDF preview fails Output device, sample form, full error text and Java processing logs
Reader Rights operation fails Credential validity, alias, P12 password and required restart; isolate basic PDF rendering first

For caller-authentication isolation, SAP also documents invoking AdobeDocumentServicesVi → rpData in WS Navigator and checking the ADS version response. SAP Help: User/password test

Capture the failed report, ABAP SID/client, destination name, timestamp and matching NWA log details before changing settings. If distributed bundling is part of the application, validate that scenario separately after the basic form tests; SAP describes its prerequisites and FPCONNECT configuration separately. SAP Help: Form bundling

Completion Checklist #

  • ADS caller identity exists in the actual UME identity source and has the required caller role.
  • ADSUSER and ADS_AGENT are documented as separate identities with separate purposes.
  • SM59 ADS settings and the callback destination match the actual hosts and client.
  • Required ICF services are active.
  • ADS version test, destination-service test and sample PDF preview succeed.
  • One representative business form works through its intended output path.
  • Optional Java forms, bundling and Reader Rights are tested only where required.
  • The temporary layout-test URL has been removed from the callback destination.
  • Host/client values, credential owners, test evidence and any credential-expiry follow-up are recorded for operations.