---
title: WebSocket RFC (Cloud Connections)
slug: docuflow-for-s3/websocket-rfc-cloud-connections
docTags: 
createdAt: 2025-06-20T17:54:45.846Z
---

## Cloud Configuration

The Cloud Configuration allows on-premise solutions to communicate with Internet based docflow servers over **HTTPS/SSL**.

### Import Certificate

To allow SSL handshake between SAP and a hosted docflow Environment we require importing docflow public certificate into SAP's Trust Manager.

1. In SAP start the **Trust Manager** (**STRUST**)
2. **Import&#x20;**&#x74;he docflow public certificate into ***SSL Client (Standard)*** (This will enable SAP to identify Gimmal certificate during TLS handshake)
3. Enter **Change Mode (Ctrl + F1)**
4. Click **SSL Client Standard**. Click **Import&#x20;**&#x61;nd select the docflow public certificate provided. Click **Add to Certificate List** and **Save**

### Export Certificates

The docflow middleware requires an export of the SAP public root certificate for SSL Client and SSL Server. This is to identify the SAP system connecting into the hosted environment.

1. In SAP start the **Trust Manager (STRUST)**
2. Export the root certificate from **SSL Client (Standard) and SSL Server (Standard)**.&#x20;
3. Clic&#x6B;**&#x20;SSL server Standard&#x20;**&#x61;nd double click the subject
   ![](https://api.archbee.com/api/optimize/1hH4CNQG9tP4YS-TB-TC6/y4-PmOMlv6QKsXzoEzYKx_exp1.png)
4. It will be appear in the Certificate section
5. Scroll down and export (provided below is a sample image) of export icon
   ![](https://api.archbee.com/api/optimize/1hH4CNQG9tP4YS-TB-TC6/CZrLjYYsqbfQ9w3rJVQJC_root-cert-2.png)
6. Click **SSL server Client&#x20;**&#x61;nd double click the Subject
7. Scroll down and export the certificate
   ![](https://api.archbee.com/api/optimize/1hH4CNQG9tP4YS-TB-TC6/lWsasF1o0ZYHXUBh6N8dP_exp2.png)
8. Send both certificates to your Gimmal representative

### Setup RFC Destination

To enable a endpoint for the SAP to connect into the middleware we require an **RFC Destination** to be created

1. Visit transaction **SM59**
2. Click **Create&#x20;**&#x61;nd give the destination an appopriate name. An example is Z\<TYPE>\_\<NAME>
3. Ensure the connection type is type **'W'**
   ![](https://api.archbee.com/api/optimize/1hH4CNQG9tP4YS-TB-TC6/EkYksHsPCFz57o8WjU7oT_zweb.png)
4. Under technical settings we need to prove the **Target System Settings**
5. For **host name** enter the provided hostname given to you by your Gimmal Representative
6. For **port** enter the provided port given to you by your Gimmal Representative&#x20;
7. ![](https://api.archbee.com/api/optimize/1hH4CNQG9tP4YS-TB-TC6/Yrpx4JlTuSoTO4IlhGLSu_initalsettings.png)
8. Click the **Logon & Security** tab and enter Language as **EN**
9. Set th&#x65;**&#x20;Explicit Client** to **by Hostname**
10. Set the **Authentication Method** to by **X.509 certificate**
11. Under **Security Options** set to **SSL Client (Standard)**
12. ![](https://api.archbee.com/api/optimize/1hH4CNQG9tP4YS-TB-TC6/fqsL5NnIBlPywM9A8scW5_securiy.png)
13. Click **Save**
14. ***Provide the RFC Destination to your Gimmal representative***

### Firewall

The firewall needs to be configured to allow **HTTPS&#x20;**&#x74;raffic through to the docflow server. To find or define these ports:

***Inbound Rule***

- In SAP, review the value for ***icm/server\_port\_x*** (where x=0,1,2,3...,n) that is used for **HTTPS**. This port will need to be opened for inbound traffic to the SAP system.

***Outbound Rule***

- Review the section ***Setup RFC Destination*** for the port that has been configured in **SM59&#x20;**&#x66;or the ***WebSocket RFC*** communication to the docflow Server.&#x20;
- This port will be given to you by the Gimmal representative

### Changing Profile Parameters

To allow quick setup of websocket connetivity we can dynamically change the parameters to quickly confirm connectivity. Work with your SAP BASIS to configure the parameters to hold.

1. Enter transacation RZ11.
2. Type in rfc/websocket/external\_active&#x20;
3. Change the value from 2 to 1. (This will allow us to bypass UCONN and enable logon, even if UCON is not activated and configured)
4. Confirm ucon/websocketrfc/active is set to 1.&#x20;

### Middleware Setup

Configure websockets through rfc destinations in middleware. INI File configuration.

| **settings**      | **Description**                                           | **Sample Value(s)&#xA0;** |
| ----------------- | --------------------------------------------------------- | ------------------------- |
| enable websockets | Enable websocket when a websocket connection is required. | true/false                |
| wsPortClient      | SAP client port number.                                   | 44300                     |
| wsPortServer      | middleware port configured to websockets.                 | 8812                      |
| wsportHost        | SAP host name/ ip address                                 | XX.XX.XXX.XX              |

