Get started

From installer to protected landscape in an afternoon

What CertiHANA needs, how it is installed and how the first HANA system is registered. The installer and your licence key are delivered by CERTICONS after your order.

Requirements

System requirements

CertiHANA serverWindows Server 2016 or later, or Windows 10/11. 2 CPU cores, 4 GB RAM, 2 GB disk for the product plus space for exports and fetched backups. Runs as a Windows Service.
NetworkAccess to the SAP HANA SQL ports (3xx13 for the SYSTEMDB, 3xx15 or 3xx41+ for tenants). Optional SSH (port 22) to the HANA host for host-level tasks and the rclone engine. Outbound access to your offsite storage.
SAP HANASAP HANA 2.0 SPS 04 or later, SYSTEMDB and tenants, on Linux. Verified on SPS 08 (revision 87) with SAP Business One 10.0.
HANA userA dedicated technical user per database with the documented system privileges. The compatibility check and the connection test report missing privileges; a commented grant script ships with the product.
BrowserCurrent Chrome, Edge, Firefox or Safari. The console is served over HTTPS on port 8080 by default.
LicenceA key from CERTICONS for the Hardware ID of the server and the number of HANA systems. Demo systems are free; no trial mode.

Installation

Five steps

Run the installer

About 20 MB, with the Python runtime and the SAP HANA client included. Set the administrator password; the service starts and the firewall port is opened.

Open the console

https://server:8080, sign in as administrator, set your mail server and notification channels.

Activate the licence

Settings › License shows the Hardware ID and a prepared request. Activate the key you receive in the console or on the command line.

Register systems

Add the SYSTEMDB and tenants with the technical user. The connection test and compatibility check confirm every privilege.

Apply the schedule

One click applies the SAP-recommended jobs. Add an offsite target and the first sync starts within the hour.

HANA privileges

Least privilege, scripted

CertiHANA works with a dedicated technical user and a documented set of system privileges. The grant script delivered with the product creates everything in two parts: tenant privileges for monitoring, backup, housekeeping and Schema Manager, and SYSTEMDB privileges for database-level backups, recovery and tenant operations.

  • No SYSTEM user, no DBA role, no software inside HANA
  • The compatibility check in the console shows every task and whether the user may run it
  • Privilege audit task reports sensitive roles and grants on your systems

Tenant user, excerpt

CREATE USER CERTIHANA PASSWORD "…" NO FORCE_FIRST_PASSWORD_CHANGE;
ALTER USER CERTIHANA DISABLE PASSWORD LIFETIME;
GRANT CATALOG READ, MONITOR ADMIN, BACKUP ADMIN, BACKUP OPERATOR,
      LOG ADMIN, TRACE ADMIN, RESOURCE ADMIN, SAVEPOINT ADMIN,
      INIFILE ADMIN, SERVICE ADMIN, SESSION ADMIN TO CERTIHANA;
GRANT MONITORING TO CERTIHANA;
-- SYSTEMDB additionally:
GRANT DATABASE ADMIN, DATABASE BACKUP ADMIN,
      DATABASE RECOVERY OPERATOR, DATABASE START, DATABASE STOP TO CERTIHANA;

Ready to protect your HANA systems?

Tell us how many systems you run and we send the quote, the installer and the privileges script.