SAP XiSecure Releases
XiSecure SAP is the component used to integrate SAP to the XiSecure and Intercept tokenization platforms. It also has conversion programs to perform mass tokenization of credit cards.
XiSecure S/4HANA for SAP 2021SP2 - 2023

New Features
N/A
Problems Addressed
-
Fixed problems with transports when upgrading from ECC to HANA.
Release Notes

New Features
Intercept for PCI Pal and Securelink
Standard support added for PCI Pal and Securelink integrations.
Problems Addressed
N/A
Release Notes

New Features
- Validated support for S/4HANA 2021 SP2 and S/4HANA 2022
Problems Addressed
N/A
Release Notes
XiSecure S/4HANA for SAP 2020 - 2021

New Features
Intercept for PCI Pal and Securelink
Standard support added for PCI Pal and Securelink integrations.
Problems Addressed
N/A
Release Notes

New Features
-
Intercept configuration changes to provide more flexible workflow options without customizations.
-
Provide method to easily call SAP BADI for populating BP sub-screens from Intercept response.
Problems Addressed
N/A
Release Notes

New Features
-
Validated with S/4HANA 2021.
-
All programs now have SAP GUI for HTML, Java, and Windows enabled.
Problems Addressed
N/A
Release Notes

New Features
-
XiSecure and Intercept SAP have been validated with S/4HANA version 2020 on-premise.
Problems Addressed
N/A
Compatibility
-
SAP S/4HANA 2020 & 2021
-
SAP SP Stack: Initial Shipment Stack
Paymetric SAP components
-
PAS - 2.9.0 minimum
-
PCMA - 5.0.0 minimum
Install and Configuration Notes
For New Installs:
This is a full release of XiSecure Integration Kit (IK) for S4 HANA; no prior transports are required.
There are no release-specific installation notes. Refer to the XiSecure-Intercept SAP S4HANA Integration Guide for install, setup and integration details.
For Upgrades:
-
For ALL upgrades, even if XiSecure IMG modifications are not required for the upgrade, you must execute the XiSecure IMG transaction code (/n/PMENC/BIMG) to initiate the objects from the upgrade.
-
When importing the transport(s),
-
The 'overwrite existing objects' flag should be selected since many of these are existing objects.
-
Allow sufficient time for each transport to complete before loading the next one to prevent syntax errors.
-
Any custom changes (including userexits configured in the Paymetric IMG's) should be evaluated and may need to be replicated in the new later versions of these userexits. There may be new PUE's (Paymetric userexits) that were not in your previous version - please review the documentation for details.
-
-
If upgrading from a previous/older version of XiSecure SAP IK, it is advised you recreate any custom userexits that are configured in the /PMENC/BIMG. They should be recreated based on the new sample default userexits that are provided.
-
As always, please test thoroughly before moving to PRD. If you would like to obtain consulting assistance with this install, please contact Support or your Relationship Manager.
Known Issues or Limitations
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
-
XiSecure-XiIntercept SAP S/4HANA Integration Guide
-
XiSecure_SAP_S4HANA2020.zip
Document and transport are available for download from the Merchant Portal Resources page.
XiSecure S/4HANA for SAP 1909

New Features
-
All XiSecure token functionality is now compatible with S/4HANA version 1909.
Problems Addressed
N/A
Compatibility
-
SAP S/4HANA 1909
-
SAP SP Stack: Initial Shipment Stack
Paymetric SAP components
-
PAS - 2.9.0 minimum
-
PCMA - 4.4.0 minimum
Install and Configuration Notes
For New Installs:
This is a full release of XiSecure Integration Kit (IK) for S4 HANA; no prior transports are required.
There are no release-specific installation notes. Refer to the XiSecure-Intercept SAP S4HANA Integration Guide for install, setup and integration details.
For Upgrades:
-
For ALL upgrades, even if XiSecure IMG modifications are not required for the upgrade, you must execute the XiSecure IMG transaction code (/n/PMENC/BIMG) to initiate the objects from the upgrade.
-
When importing the transport(s),
-
The 'overwrite existing objects' flag should be selected since many of these are existing objects.
-
Allow sufficient time for each transport to complete before loading the next one to prevent syntax errors.
-
Any custom changes (including userexits configured in the Paymetric IMG's) should be evaluated and may need to be replicated in the new later versions of these userexits. There may be new PUE's (Paymetric userexits) that were not in your previous version - please review the documentation for details.
-
-
If upgrading from a previous/older version of XiSecure SAP IK, it is advised you recreate any custom userexits that are configured in the /PMENC/BIMG. They should be recreated based on the new sample default userexits that are provided.
-
As always, please test thoroughly before moving to PRD. If you would like to obtain consulting assistance with this install, please contact Support or your Relationship Manager.
Known Issues or Limitations
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
-
XiSecure-XiIntercept SAP S/4HANA Integration Guide
-
XiSecure_SAP_S4HANA1909.zip
Document and transport are available for download from the Merchant Portal Resources page.
XiSecure S/4HANA for SAP 1610

New Features
-
All XiSecure token functionality is now compatible with S/4HANA version 1909.
Problems Addressed
N/A
Compatibility
-
SAP S/4HANA 1909
-
SAP SP Stack: Initial Shipment Stack
Paymetric SAP components
-
PAS - 2.9.0 minimum
-
PCMA - 4.4.0 minimum
Install and Configuration Notes
For New Installs:
This is a full release of XiSecure Integration Kit (IK) for S4 HANA; no prior transports are required.
There are no release-specific installation notes. Refer to the XiSecure-Intercept SAP S4HANA Integration Guide for install, setup and integration details.
For Upgrades:
-
For ALL upgrades, even if XiSecure IMG modifications are not required for the upgrade, you must execute the XiSecure IMG transaction code (/n/PMENC/BIMG) to initiate the objects from the upgrade.
-
When importing the transport(s),
-
The 'overwrite existing objects' flag should be selected since many of these are existing objects.
-
Allow sufficient time for each transport to complete before loading the next one to prevent syntax errors.
-
Any custom changes (including userexits configured in the Paymetric IMG's) should be evaluated and may need to be replicated in the new later versions of these userexits. There may be new PUE's (Paymetric userexits) that were not in your previous version - please review the documentation for details.
-
-
If upgrading from a previous/older version of XiSecure SAP IK, it is advised you recreate any custom userexits that are configured in the /PMENC/BIMG. They should be recreated based on the new sample default userexits that are provided.
-
As always, please test thoroughly before moving to PRD. If you would like to obtain consulting assistance with this install, please contact Support or your Relationship Manager.
Known Issues or Limitations
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
-
XiSecure-XiIntercept SAP S/4HANA Integration Guide
-
XiSecure_SAP_S4HANA1909.zip
Document and transport are available for download from the Merchant Portal Resources page.

New Features
-
Initial release for S4 HANA. The conversion programs are not included in this first release; they will be added in a subsequently planned release.
Problems Addressed
N/A
Compatibility
-
SAP: S4CORE, 100, 0002, SAPK-10002INS4CORE
Product Versions
-
S4HANA ON PREMISE, 1511, 02 (05/2016) FPS
-
NW FOR S4HANA ONPREMIE,1511, 03 (04/2016)
Paymetric SAP Components
Release 4.1.0 was tested with the above versions. Later SAP S4 related releases, components and/or support packs are not guaranteed to work. XiSecure SAP IK for S4 will not work with versions prior to the ones provided above nor with S4 Simple Finance (S4FIN).
-
PAS - 2.7.3
-
PCMA S4 - 4.0.0
Install and Configuration Notes
For New Installs:
This is a full release of S4 HANA; no prior transports.
There are no release-specific installation notes. Refer to the XiSecure Platform SAP S4 Integration Guide for install, setup and integration details.
For Upgrades:
- N/A
Known Issues or Limitations
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
-
XiSecure Platform SAP S4 Integration Guide
-
XiSecure_SAP_S4.zip
Document and transport are available for download from the Merchant Portal Resources page.
XiSecure SAP ECC

New Features
-
Intercept SAP and Open AR CVV and workflow improvements.
Problems Addressed
N/A
Release Notes

New Features
-
Intercept SAP and Open AR CVV and workflow improvements.
Problems Addressed
N/A
Release Notes

New Features
Expanded Token Format Support through Credential Management Platform (CMP). This release supports integrating through Intercept SAP to the Credential Management Platform (CMP) (TMS). It facilitates Direct Debit OmniToken functionality from SAP.
You use a separate token format for credit card numbers. Credit card numbers should ideally use an XiSecure token type given the multiple format options available that are easily distinguishable as a token.
TMS supports the following token types:
-
XiSecure
-
Vantiv OmniToken
-
WPG token types
Problems Addressed
N/A
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ECC 6.0, ABAP 702 Support Pack 0016
-
Paymetric SAP components
-
PAS - 2.10.0 minimum
-
PCMA - 2.7.0 minimum
-
Install and Configuration Notes
For New Installs:
Install the full transport and perform the setup and integration tasks as defined in the following integration guide(s):
-
XiSecure Platform SAP ECC Integration Guide - Instructions on importing the transport and setup for XiSecure-only
-
SAP ECC TMS Integration Guide - Instructions on importing transport and setting up tokenization through TMS
For Upgrades:
To upgrade XiSecure SAP IK, import the new, full transport and see the following bullet points for additional considerations:
-
For ALL upgrades, even if XiSecure IMG modifications are not required for the upgrade, you must execute the XiSecure IMG transaction code (/n/PMPAY/BIMG) to initiate the objects from the upgrade.
-
CONSULT WITH PAYMETRIC SUPPORT OR YOUR PAYMETRIC INTEGRATION CONSULTANT BEFORE PERFORMING AN UPGRADE. An upgrade beyond XiSecure IK 2.2.0 is not possible without a conversion project to the latest XiIntercept SAP using SSO (Single Sign-On).
-
XiSecure 2.4 0 introduced Intercept SAP SSO and is NOT backwards compatible with existing Intercept SAP integrations so a conversion will be required.
-
Intercept SAP SSO requires the SSO permission be set on the XiSecure certificate.
-
Consulting services are available upon request for all upgrades. If you are upgrading from a version that is multiple versions prior to the latest release, We recommend you seek consulting services.
Objects Modified
This section identifies any objects that were modified that should be taken into account when upgrading if you have existing customizations that need to be brought into the new objects.
N/A
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide (for XiSecure-only integrations)
-
SAP ECC TMS Integration Guide (for TMS integrations)
-
SAP ECC-Getting Started Direct Debit Integration
-
SAP ECC-Getting Started TMS Integration
-
XiSecure ECC.zip (transport files)
-
PAS Setup Guide
-
PAS_Windows_Installer.zip

New Features
Expanded Token Format Support through Credential Management Platform (CMP). This release supports integrating through Intercept SAP to the Credential Management Platform (CMP) (TMS). It facilitates Direct Debit OmniToken functionality from SAP. You use a separate token format for credit card numbers. Credit card numbers should ideally use an XiSecure token type given the multiple format options available that are easily distinguishable as a token.
TMS supports the following token types:
-
XiSecure
-
Vantiv OmniToken
-
WPG token types
Problems Addressed
N/A
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ECC 6.0, ABAP 702 Support Pack 0016
-
Paymetric SAP components
-
PAS - 2.10.0 minimum
-
PCMA - 2.7.0 minimum
-
Install and Configuration Notes
For New Installs:
Install the full transport and perform the setup and integration tasks as defined in the following integration guide(s):
-
XiSecure Platform SAP ECC Integration Guide - Instructions on importing the transport and setup for XiSecure-only
-
SAP ECC TMS Integration Guide - Instructions on importing transport and setting up tokenization through TMS
For Upgrades:
To upgrade XiSecure SAP IK, import the new, full transport and see the following bullet points for additional considerations:
-
For ALL upgrades, even if XiSecure IMG modifications are not required for the upgrade, you must execute the XiSecure IMG transaction code (/n/PMPAY/BIMG) to initiate the objects from the upgrade.
-
CONSULT WITH PAYMETRIC SUPPORT OR YOUR PAYMETRIC INTEGRATION CONSULTANT BEFORE PERFORMING AN UPGRADE. An upgrade beyond XiSecure IK 2.2.0 is not possible without a conversion project to the latest XiIntercept SAP using SSO (Single Sign-On).
-
XiSecure 2.4 0 introduced Intercept SAP SSO and is NOT backwards compatible with existing Intercept SAP integrations so a conversion will be required.
-
Intercept SAP SSO requires the SSO permission be set on the XiSecure certificate.
-
Consulting services are available upon request for all upgrades. If you are upgrading from a version that is multiple versions prior to the latest release, We recommend you seek consulting services.
Objects Modified
This section identifies any objects that were modified that should be taken into account when upgrading if you have existing customizations that need to be brought into the new objects.
N/A
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide (for XiSecure-only integrations)
-
SAP ECC TMS Integration Guide (for TMS integrations)
-
SAP ECC-Getting Started Direct Debit Integration
-
SAP ECC-Getting Started TMS Integration
-
XiSecure ECC.zip (transport files)
-
PAS Setup Guide
-
PAS_Windows_Installer.zip

New Features
Support for XiIntercept P2PE Integrations
The XiIntercept P2PE solution allows users to connect a P2PE pinpad device to their machine, launch our SecureEntry application from within SAP, and return a token back to the Credit Card Number field.
This functionality is implemented via conversion exit or search help. Search help is available by default as part of XiIntercept. The Conversion exit (CONVERSION_EXIT_YP2PE_INPUT/OUTPUT) will need to be configured in the CCNUM domain Conversion Routine. Both CANNOT be implemented at the same time.
XiSecure IMG Changes
Changes to the XiSecure IMG include two new P2PE PUE’s and new P2PE Card Type field mappings.
PUE: P2PE Processing is used by both the conversion exit and the search help. This does the send and receive to the P2PE device and tokenization.
PUE: P2PE Populate Values is used by the conversion exit. Currently Open AR (Single and Multi), Direct AR, VA01, VA02, XD01, XD02 are coded within the /PMENC/PEX_P2PE_POP_VALUES user exit. You can make a Z version of it to change/add more screens as needed.
Card Type Mappings: This is used to map the P2PE card type values to the appropriate SAP card type values. Following are the values for P2PE solution:
VISA = 0
MC = 1
AMEX = 2
DISC= 3
JCB = 4
DINERS = 5
MAESTRO = 6
DANKORT = 7
SOLO = 8
SWITCH=9
XiIntercept Configured Values - In the XiSecure IMG (/PMENC/BIMG), click Maintain under Intercept Options. There is a new P2PE value in the Method dropdown.
-
Select P2PE as the Method.
-
Enter a Trigger (T…) value which is entered in the field to indicate what method to launch.
-
Select the radio button in the Primary column if you want this to be the primary input method that is launched when search help is triggered.
-
Leave URL, System ID, RFC Destination, SSO MID, and Template ID blank when configuring P2PE Method.
Problems Addressed
N/A
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ECC 6.0, ABAP 702 Support Pack 0016. For XiIntercept for SAP SSO, minimum version SAP GUI 7.1
-
-
PAS - 2.9.0 minimum
-
PCMA - 2.4.2 minimum
-
Install and Configuration Notes
For New Installs:
Install the full transport and perform the setup and integration tasks as defined in the following integration guide(s):
-
XiSecure Platform SAP ECC Integration Guide - Instructions on importing the transport and setup for XiSecure-only
-
Paymetric PCI Pal Integration Guide - Instructions on PCI Pal setup.
This is a full release and only requires the XiSecure full transport be imported.
For Upgrades:
To upgrade XiSecure SAP IK, import the new, full transport and see the following bullet points for additional considerations:
-
For ALL upgrades, even if XiSecure IMG modifications are not required for the upgrade, you must execute the XiSecure IMG transaction code (/n/PMPAY/BIMG) to initiate the objects from the upgrade.
-
CONSULT WITH PAYMETRIC SUPPORT OR YOUR PAYMETRIC INTEGRATION CONSULTANT BEFORE PERFORMING AN UPGRADE. An upgrade beyond XiSecure IK 2.2.0 is not possible without a conversion project to the latest XiIntercept SAP using SSO (Single Sign-On).
-
XiSecure 2.4 0 introduced Intercept SAP SSO and is NOT backwards compatible with existing Intercept SAP integrations so a conversion will be required.
-
Intercept SAP SSO requires the SSO permission be set on the XiSecure certificate.
-
Refer to the XiSecure SAP Integration Guide, "Integration XiIntercept SAP" section for detailed instructions on integration and how to request the SSO permission be added to the certificate.
-
Consulting services are available upon request for all upgrades. If you are upgrading from a version that is multiple versions prior to the latest release, We recommend you seek consulting services.
Objects Modified
This section identifies any objects that were modified that should be taken into account when upgrading if you have existing customizations that need to be brought into the new objects.
N/A
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide
-
XiSecure ECC.zip (transport files)
-
PAS Setup Guide
-
PAS_Windows_Installer.zip (contains PAS Setup Guide in zip)
-
PAS_RHEL_Install_Pkg.zip (RHEL package contains PAS Setup Guide in zip)
-
PCI Pal Integration Guide

New Features
XiSecure IMG DI Options Menu Node Name Changed to Intercept. The menu node formerly titled "DI Options" has been changed to "Intercept Options" to clarify the settings are associated with the XiIntercept solution.
PCI Pal Now Supported
Added support for PCI Pal payment card acceptance through XiIntercept for SAP. Within SAP under Intercept Options, you configure the PCI Pal method with the appropriate values.
The merchant works directly with PCI Pal to determine the telephony interoperability requirements to establish the PCI Pal account and telephony setup. Paymetric must enable PCI Pal in Merchant Portal and then obtain the necessary PCI Pal merchant authentication values that are configured in XiIntercept SAP Admin Interface.
Refer to the Paymetric PCI Pal Integration Guide for more details.
Ability to Configure Securelink and XiIntercept SAP
You can now configure a separate method and trigger for Securelink functionality within the IMG. Under the Intercept Options menu node, click to maintain the values and insert a new one selecting the Secure Link Method, and configure the values appropriately. See the XiSecure Platform SAP Integration Guide, "Securelink" section for more details.
-
Card Check Routine Updates for MC and Visa.
-
For MasterCard, updated BIN ranges in the card check routine, /PMENC/P_CHK_MC.
-
For Visa, modified the card check routine, /PMENC/P_CHK_VISA, to accommodate 19-character card numbers.
Problems Addressed
Resubmit Encryption Failure - The Resubmit Encryption Failure program now reads the Communication Method IMG setting to ensure it works properly for all methods
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ECC 6.0, ABAP 702 Support Pack 0016. For XiIntercept for SAP SSO, minimum version SAP GUI 7.1
-
-
PAS - 2.8.1 minimum
-
PCMA - 2.4.0 minimum
-
Install and Configuration Notes
For New Installs:
Install the full transport and perform the setup and integration tasks as defined in the following integration guide(s):
-
XiSecure Platform SAP ECC Integration Guide - Instructions on importing the transport and setup for XiSecure-only
-
Paymetric PCI Pal Integration Guide - Instructions on PCI Pal setup.
This is a full release and only requires the XiSecure full transport be imported.
For Upgrades:
To upgrade XiSecure SAP IK, import the new, full transport and see the following bullet points for additional considerations:
-
For ALL upgrades, even if XiSecure IMG modifications are not required for the upgrade, you must execute the XiSecure IMG transaction code (/n/PMPAY/BIMG) to initiate the objects from the upgrade.
-
CONSULT WITH PAYMETRIC SUPPORT OR YOUR PAYMETRIC INTEGRATION CONSULTANT BEFORE PERFORMING AN UPGRADE. An upgrade beyond XiSecure IK 2.2.0 is not possible without a conversion project to the latest XiIntercept SAP using SSO (Single Sign-On).
-
XiSecure 2.4 0 introduced Intercept SAP SSO and is NOT backwards compatible with existing Intercept SAP integrations so a conversion will be required.
-
Intercept SAP SSO requires the SSO permission be set on the XiSecure certificate.
-
Refer to the XiSecure SAP Integration Guide, "Integration XiIntercept SAP" section for detailed instructions on integration and how to request the SSO permission be added to the certificate.
-
Consulting services are available upon request for all upgrades. If you are upgrading from a version that is multiple versions prior to the latest release, We recommend you seek consulting services.
Objects Modified
This section identifies any objects that were modified that should be taken into account when upgrading if you have existing customizations that need to be brought into the new objects.
-
/PMENC/P_CHK_MC
-
/PMENC/P_CHK_VISA
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide
-
XiSecure ECC.zip (transport files)
-
PAS Setup Guide
-
PAS_Windows_Installer.zip (contains PAS Setup Guide in zip)
-
PAS_RHEL_Install_Pkg.zip (RHEL package contains PAS Setup Guide in zip)
-
PCI Pal Integration Guide

New Features
N/A
Problems Addressed
XiIntercept (a.k.a. DI) for SAP throwing ABAP short dump due to RFC failure
A ping is now performed on the RFC before invoking the DI Session and again before the retrieval of the DI information. If the RFC is down, an information dialog box now displays indicating there is an RFC failure allowing the user to save the order and all the information that has been entered.
XiIntercept Pop-up Errors in Open AR
When using XiIntercept in Open AR, the card search pop-up window was incorrectly displaying if the User launched XiIntercept browser and then closed the browser window before turning to SAP and triggering the token input by pressing F4 key the second time. In this scenario, the message "No values found" should display in the SAP Message Bar at the bottom of the screen. This has been corrected.
Erroneous error message when displaying DI for SAP configuration
When the User attempts to leave the DI Configured Values – Display screen by pressing the Green ‘Back’ arrow, an error message displays instructing the User to correct the RFC. The User is stuck in the screen until they select another method of leaving it. The error message is incorrect since it is not possible to change the RFC in a QA environment. Now when the system is locked (as in QA and PRD), just an Information message displays regarding the wrong RFCs. If it is a DEV system, it will remain as is, a hard error.
Multiple Primary Methods allowed for XiIntercept for SAP configuration causing short dump
Corrected a problem in which XiIntercept configuration in /PMENC/BIMG was allowing multiple Primary Methods to be selected resulting in a short dump; now only one Primary Method can be selected.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ECC 6.0, Unicode only. For XiIntercept for SAP SSO, minimum version SAP GUI 7.1
-
PAS - All versions back to minimum supported. For intercept SAP SSO, minimum version 2.8.0
-
PCMA - 1.8.0 minimum version
Install and Configuration Notes
This release requires the full transport version 3.0.0 already be installed.
Refer to the Read_Me.txt file provided with the transports BEFORE you perform any installation activities. This is especially important for upgrades.
Summary of User Exists/Wrappers Modified
N/A
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide
-
XiSecure ECC.zip (transport files)
-
PAS Setup Guide
-
PAS_Windows_Installer.zip (contains PAS Setup Guide in zip)
-
PAS_RHEL_Install_Pkg.zip (RHEL package contains PAS Setup Guide in zip)
-
PCI Pal Integration Guide

New Features
Added support for Paymetric SAP NetWeaver Solution (PSNS)
A new drop-down has been added that provides the option of selecting PAS or PI (PSNS) Communication Method in XiSecure IMG for ECC. PI should be selected for PSNS.
When selecting a communication method for:
-
PAS:
-
ECC - XiSecure IMG Displays Primary and Secondary for the RFC Destination.
-
CRM - XiSecure IMG Displays Authorization, Primary and Secondary for the RFC Destination
-
-
PI (Paymetric SAP NetWeaver Solution, a.k.a. PSNS):
-
PCMA Execution settings, ECC - XiSecure IMG displays only PI RFC destination for input.
-
In XiSecure IMG for ECC:
-
DI Maintenance screen, the RFC destination is no longer visible for input.
-
Flex Token Maintenance screen, the RFC destination is no longer visible for input.
-
-
In XiSecure for ECC, four new programs have been added related to token/raw data conversion as follows:
-
Convert Raw Cards to Tokens: Identifies and tokenizes any raw card numbers found in the CCNUM domain. It is a copy of the 'Credit Card Conversion' but without decrypt capabilities.
-
Convert Failure Tokens to Tokens: This program is only applicable if you have chosen ‘Option A – Application Failure Token generated’ for the Processing Option IMG node. If the remote call to XiSecure fails for any reason, the value to be tokenized is stored in the table /PMENC/PFAIL and other SAP tables containing CCNUM values where the CCNUM domain is used. This program locates the raw values, resubmits to XiSecure for tokenization and then replaces the failure token with the standard token format you have implemented in ALL tables within SAP.
-
Credit Card Conversion in Parallel: Is used to convert large quantities of tokens from one format to another format (i.e. EMS to FlexToken). This program is a two-step process. The first step converts all data from one token format to another and then stores it in the /PMENC/CONV_HEAD and /PMENC/CONV_CARD tables. Run the Review/Remove Conversion in Parallel Information report before actually performing the update so you can view the updates that will be made. The second step updates everything in the CCNUM domain based on the data stored in the *CONV* tables. Requires a Number Range to be create for /PMENC/CON.
-
Review/Remove Conversion in Parallel Information: Used to view the data that will be updated when running the Credit Card Conversion in Parallel program.
-
PUE: Filter Records for Parallel Conversion: A Paymetric User Exist (PUE) that can be used to filter data in the Parallel program. Previously, converting large quantities of data was time consuming. This PUE in gives clients the ability to filter their data in the parallel program and shorten conversion times.
Modifications to DI for SAP Parameters to support both PAS and PSNS
From the XiSecure IMG, access DI Options à Maintain. The following changes have been added to DI for SAP
-
For PAS, the configuration is unchanged.
-
For PI (PSNS), the configuration does not include the RFC.
Modifications to Flex Token Parameters to support both PAS and PSNS
From the XiSecure IMG, access Flex Tokens à Maintain. The following changes have been added to Flex Token Parameters:
-
For PAS, the configuration is unchanged.
-
For PI (PSNS), the configuration does not include the RFC.
Problems Addressed
N/A
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ECC 6.0, Unicode only. For XiIntercept for SAP SSO, minimum version SAP GUI 7.1
-
SAP NetWeaver PI: Minimum version SAP PI version 7.11, SP013. SP013 is required for password security. SAP PI version 7.3, EHP1 required for encrypting message content at the database level.
-
PAS - All versions back to minimum supported. For intercept SAP SSO, minimum version 2.7.0
-
PSNS 1.0.0 or higher
-
PCMA - 1.8.0 minimum version
Install and Configuration Notes
This release requires the full transport version 3.0.0 already be installed.
Refer to the Read_Me.txt file provided with the transports BEFORE you perform any installation activities. This is especially important for upgrades.
Summary of User Exists/Wrappers Modified
-
/PMPAY/PEX_POSTSETL
-
/PMPAY/PEX_PRESETL
-
/PMPAY/P_AUTH_WRAP
-
/PMPAY/P_SET_WRAP
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide
-
CRM XiSecure v3.0.0.C0006.zip (transport file)
For connectivity, you will choose one of the following installers:
-
Paymetric SAP NetWeaver Solution (PSNS)
-
PSNS Setup Guide
-
PSNS_Package_<ver#>.tpz (PSNS import file)
-
-
Paymetric Adapter for SAP (PAS)
-
PAS Setup Guide
-
PAS_Windows_<ver#>-install.zip -OR-
-
PAS_Linux_<ver #>.zip (RHEL package)
-

New Features
N/A
Problems Addressed
Make DI SAP work in non-unicode system. Changes made in version 2.4.3 would not work in non-unicode systems; this has been corrected.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ERP 4.6c, Support Pack 48 and higher
-
SAP ERP 4.7. Support Pack 22 and higher
-
SAP ECC 5.0 Support Pack 7 and higher
-
SAP ECC 6.0
-
** For DI for SAP SSO, Minimum version SAP GUI 7.1
DI for SAP is not supported in NWBC nor SAP GUI for HTML. -
PAS - All versions back to minimum supported. For DI SAP SSO, minimum version 2.7.0
-
PCMA - All versions back to minimum supported. For DI SAP SSO, minimum version 1.7.0
Install and Configuration Notes
This is a full transport release. No prior transport versions are required to install.
Refer to the IMPORTANT_FOR_UPGRADES_Read_Me_XiSecure.docx file (also provided with the transports). This is especially important for upgrades.
New Installation Notes
There are no installation notes specific to this release, follow the instructions in the XiSecure Platform SAP Integration Guide.
If you are implementing DI for SAP Single Sign-On (DI-SAP SSO)
And implementing retrieval of tokens from the Customer Master in addition to the XiIntercept for SAP GUI, you must make a Z version of PMENC/PEX_XiIntercept_PARAM Paymetric User Exit (PUE) and uncomment code that is specified in the XiSecure Platform SAP Integration Guide.
Upgrade Notes
As always, you should make note of the Objects modified in this release and check if you have customized Z versions. You will need to create a Z version of the appropriate Object and incorporate your customizations.
If you are implementing DI for SAP Single Sign-On (DI-SAP SSO) and implementing retrieval of tokens from the Customer Master (in addition to the DI for SAP GUI), you must make a Z version of PMENC/PEX_DI_PARAM Paymetric User Exit (PUE) and uncomment code that is specified in the XiSecure Platform SAP Integration Guide.
If you are upgrading from DI SAP version 1 to version 2...
-
Remove any existing Conversion Exit in the CCNUM domain. DI for SAP version 2 only uses F4 Search Help integration.
-
In the XiSecure IMG (/PMPAY/BIMG) under the DI Options section, remove all existing configured values.
-
Import the new transport and follow the configuration and setup steps in the XiSecure Platform SAP Integration Guide, under "Configure and Integrate DI for SAP" section.
Configuration Notes
There are no configuration notes specific to this release. Refer to the XiSecure Platform SAP Integration Guide.
Summary of Objects Modified
User Exit Samples Modified in this Release:
-
/PMENC/LPEXTTOP
-
/PMENC/PEX_DI_PARAM
General Objects Modified in this Release:
-
Program: /PMENC/LDIF02
-
Program: PMENC/LDITOP
-
Function Module: /PMENC/PSH_CCNUM_F4
-
Search Help Definition: /PMENC/PSH_CCNUM_DI
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide (includes PAS configuration details as well)
-
XiSecure v2.5.0.G0035(46c full).zip transport file
-
XiSecure v2.5.0.G0035(ERP and unicode full).zip transport file - For both ECC and 4.7 systems
-
PAS Windows Installer
-
PAS Red Hat Enterprise Linux (RHEL) Install package
For upgrades, there is no need to upgrade PAS if you are on one of the minimum supported versions.

New Features
N/A
Problems Addressed
Make DI SAP work in non-unicode system. Changes made in version 2.4.3 would not work in non-unicode systems; this has been corrected.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ERP 4.6c, Support Pack 48 and higher
-
SAP ERP 4.7. Support Pack 22 and higher
-
SAP ECC 5.0 Support Pack 7 and higher
-
SAP ECC 6.0
-
** For DI for SAP SSO, Minimum version SAP GUI 7.1
DI for SAP is not supported in NWBC nor SAP GUI for HTML. -
PAS - All versions back to minimum supported. For DI SAP SSO, minimum version 2.7.0
-
PCMA - All versions back to minimum supported. For DI SAP SSO, minimum version 1.7.0
Install and Configuration Notes
This is a full transport release. No prior transport versions are required to install.
Refer to the IMPORTANT_FOR_UPGRADES_Read_Me_XiSecure.docx file (also provided with the transports). This is especially important for upgrades.
New Installation Notes
There are no installation notes specific to this release, follow the instructions in the XiSecure Platform SAP Integration Guide.
If you are implementing DI for SAP Single Sign-On (DI-SAP SSO)
And implementing retrieval of tokens from the Customer Master in addition to the XiIntercept for SAP GUI, you must make a Z version of PMENC/PEX_XiIntercept_PARAM Paymetric User Exit (PUE) and uncomment code that is specified in the XiSecure Platform SAP Integration Guide.
Upgrade Notes
As always, you should make note of the Objects modified in this release and check if you have customized Z versions. You will need to create a Z version of the appropriate Object and incorporate your customizations.
If you are implementing DI for SAP Single Sign-On (DI-SAP SSO) and implementing retrieval of tokens from the Customer Master (in addition to the DI for SAP GUI), you must make a Z version of PMENC/PEX_DI_PARAM Paymetric User Exit (PUE) and uncomment code that is specified in the XiSecure Platform SAP Integration Guide.
If you are upgrading from DI SAP version 1 to version 2...
-
Remove any existing Conversion Exit in the CCNUM domain. DI for SAP version 2 only uses F4 Search Help integration.
-
In the XiSecure IMG (/PMPAY/BIMG) under the DI Options section, remove all existing configured values.
-
Import the new transport and follow the configuration and setup steps in the XiSecure Platform SAP Integration Guide, under "Configure and Integrate DI for SAP" section.
Configuration Notes
There are no configuration notes specific to this release. Refer to the XiSecure Platform SAP Integration Guide.
Summary of Objects Modified
User Exit Samples Modified in this Release:
-
/PMENC/LPEXTTOP
-
/PMENC/PEX_DI_PARAM
General Objects Modified in this Release:
-
Program: /PMENC/LDIF02
-
Program: PMENC/LDITOP
-
Function Module: /PMENC/PSH_CCNUM_F4
-
Search Help Definition: /PMENC/PSH_CCNUM_DI
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide (includes PAS configuration details as well)
-
XiSecure v2.5.0.G0035(46c full).zip transport file
-
XiSecure v2.5.0.G0035(ERP and unicode full).zip transport file - For both ECC and 4.7 systems
-
PAS Windows Installer
-
PAS Red Hat Enterprise Linux (RHEL) Install package
For upgrades, there is no need to upgrade PAS if you are on one of the minimum supported versions.

New Features
N/A
Problems Addressed
Token value not cleared when cancelling order
If a user launched the XiIntercept SAP GUI browser session from the SAP Create or Change Sales Order screen and generated a token, but then canceled the order BEFORE pressing F4 in the SAP screen to enter the token, the token was not cleared from memory. If the user then created or changed a new or different Sales Order and attempted to launch the XiIntercept SAP GUI again to obtain a token, the token from the canceled order was still in memory and automatically entered in the payment card field.
Now the token is always cleared if an order is canceled or a new one is created regardless of whether the user presses the F4 key after obtaining a token from the XiIntercept SAP GUI.
No message displayed for insufficient user permissions
If users do not have the appropriate remote function call permissions to obtain or view tokens, a message now displays as follows: “No security privileges. <object name>” where object name is the specific object to which they need permissions.
For example, if they do not have access to S_RFC then the message would read “No security privileges. S_RFC” when attempting to obtain or view tokens. Users can provide the message to their SAP Administrator to request access.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ERP 4.6c, Support Pack 48 and higher
-
SAP ERP 4.7. Support Pack 22 and higher
-
SAP ECC 5.0 Support Pack 7 and higher
-
SAP ECC 6.0
-
** For DI for SAP SSO, Minimum version SAP GUI 7.1
DI for SAP is not supported in NWBC nor SAP GUI for HTML. -
PAS - All versions back to minimum supported. For DI SAP SSO, minimum version 2.7.0
-
PCMA - All versions back to minimum supported. For DI SAP SSO, minimum version 1.7.0
Install and Configuration Notes
This patch release only requires the full transport 2.4.0 be installed. It does not require a 2.4.1 transport.
Refer to the Read_Me.txt file provided with the transports BEFORE you perform any installation activities. This is especially important for upgrades.
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide (includes PAS configuration details as well)
-
XiSecure v2.4.2.G0032(46c patch).zip transport file
-
XiSecure v2.4.3.G0032(ERP unicode patch).zip transport file - For both ECC and 4.7 systems
-
PAS Install and Configuration Guide
-
PAS Windows Installer
-
PAS Red Hat Enterprise Linux (RHEL) Install package
For upgrades, there is no need to upgrade PAS if you are on one of the minimum supported versions.

New Features
DI for SAP Single Sign-On Support
XiIntercept for SAP now contains a Single Sign-On Merchant ID (SSO MID) assigned by Paymetric so users are no longer required to log into the XiIntercept GUI separately when launching from SAP. After the token is generated, it is placed in the payment card field simply by pressing the F4 Key. Modified Object: PUE - /PMENC/PEX_XiIntercept_PARAM.
This version allows the user to have multiple XiIntercept SAP GUI browser sessions and SAP GUI sessions open at one time. There is a Session ID that ties the browser session with the SAP GUI session.
This feature requires minimum PCMA 1.7.0 and PAS 2.7.1. Also, be sure to review the Install and Configuration notes below.
DI for SAP Add Payer Partner/Customer to Customer Master LOV
When launching the Customer Master list-of-values (LOV) from the payment card field using XiIntercept for SAP, Payer Partner/Customer is now available for instances in which Sold-To Party differs from Payer Partner.
Problems Addressed
Date Error in Credit Card Field when using PCMA Direct AR
When Direct AR was converted to use CCNUM domain, XiIntercept for SAP expiration date retrieved from Customer Master was returning format error.
Date Format Problem - MM.YYYY
Date format problem occuring when performing customer transfer method. It was returning DD.YYYY rather than MM.YYYY.
DI for SAP Problem When Transporting Configured URLs
When configuring XiIntercept for SAP, Clients could not easily distinguish the XiIntercept SA URL (QA or Production) which cause problems when performing transports from one system to the next. A A System ID field was added to the XiIntercept for SAP configuration so Clients can now associate the URL with the appropriate SAP system.
DI for SAP - Customer Master Token Value List Problem
In VA01, when user created OR type invoice. Instead following SAP workflow by entering Sold-to Pary and hit ENTER key, user decided to go directly to credit card number field and query for the List-of-values; The current logic will offer either all customers' cards for if user access VA01 for the first time (since login) or will use previous stored customer parameter ID (VAG) for the list-of-values.
Encryption Status Indicator in XiSecure IMG (BIMG) Incorrect
Encryption configuration parameters incorrectly had a Red Indicator Status when XiIntercept or FlexTokens was configured.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ERP 4.6c, Support Pack 48 and higher
-
SAP ERP 4.7 Support Pack 22 and higher
-
SAP ECC 5.0 Support Pack 7 and higher
-
SAP ECC 6.0
-
** For DI for SAP SSO, Minimum version SAP GUI 7.1
DI for SAP is not supported in NWBC nor SAP GUI for HTML. -
PAS - All versions back to minimum supported. For DI SAP SSO, minimum version 2.7.0
-
PCMA - All versions back to minimum supported. For DI SAP SSO, minimum version 1.7.0
Install and Integration Notes
Known Problems
There are no known issues for this release.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide (includes PAS configuration details as well)
-
PAS Install and Configuration Guide

The CRM transport for this release does NOT support XiIntercept for SAP, only entering raw card numbers and then tokenizing directly to XiSecure. There is a now a separate package for XiSecure SAP CRM Integration Kit that supports XiIntercept for SAP starting with version 2.4.0.
New Features
XiSecure FlexToken Support Added
XiSecure OnDemand has FlexToken technology that allows you to preserve the format of the data being represented which supports the use of existing programs and validations against tokens. Depending upon the format selected, it also provides the ability to obtain BIN ranges from the token as well.
A set of commonly used FlexTokens have been created and tested. The format type library is in the Onboarding Request Form on the XiSecure tab in the column heading comment for FlexToken. If a custom format is selected, your Implementation Consultant or Relationship Manager will discuss the additional implementation time required for creation and testing of the new format.
The PCMA IMG has a new Encryption type, FLX, with corresponding PUE's and configuration to accommodate FlexTokens. Refer to the Review PCMA IMG Settings topic in the PCMA Install and Configuration Guide for additional information. Refer to the Convert to the FlexToken format topic in the XiSecure SAP Integration Guide for additional information on configuring the XiSecure component for this functionality.
Flex tokens allow customers to format their tokens to meet business needs. The XiSecure IMG has a new section to accommodate FlexTokens including:
-
PUE: FlexToken Parameters
-
FlexToken Conversion Program
-
An additional card check routine
-
A new conversion routine for the CCNUM domain
-
A checkbox to use the FlexToken format has been added to the Background program - Resubmit Encryption Failures.
For more information on converting to FlexTokens, refer to the "Converting to FlexTokens" topic in the XiSecure Implementation Guide.
FlexTokens are NOT available for CRM.
Problems Addressed
Error When Installing CRM 7.0 EHP1
To support the XiSecure transport compatibility with CRM, a new search help /PMENC/FC_RFCDEST has been created. It is included in the structure /PMENC/BLOBDOC to prevent an error message when attempting to upgrade a CRM system.
DI for SAP - All cards being returned from Customer Master
If you have implemented XiIntercept for SAP using the Customer Master there was a problem occurring when changing an order via the VA02 - Change Sales Order screen in which all tokens from the Customer Master were being returned in the selection list instead of just the ones for the selected Customer. This has been corrected.
DI for SAP - Customer Master defaults corrected - IMPORTANT - PLEASE READ
A problem was discovered in XiIntercept-SAP when the Customer Master option is being utilized and will manifest if your Payer Partner and Sold-to-Party values differ in SAP.
This XiSecure Release should be implemented as soon as possible if you fall under this condition using XiIntercept-SAP or there is a risk of retrieving and utilizing the wrong token.
A solution to use Customer Payer Partner has been implemented so that the correct token will be retrieved from the Customer Master. The transport must be imported into SAP and a block of commented code in the XiIntercept-SAP PUE must be uncommented to achieve the fix (block of code is not relevant for CRM).
The block of code is implemented in PUE: /PMENC/PEX_XiIntercept_PARAM. To implement in ECC or an older SAP version, copy the PUE to a Z version and uncomment the block of code under the following comment to the end of the Function Module.
Ability to clear an RFC added
In the execution settings, the ability to clear an implemented RFC in the XiSecure IMG is now available by using the Trash can button. Since XiSecure RFC Destinations have "traffic lights", a Trash can button will appear in place of a "green light" when an RFC destination is configured. The Trash can button is only available if an RFC destination has been configured.
DI-SAP Enter key functionality fixed in CCNUM domain
The User Exit YYZDI has been changed to allow the XiIntercept-SAP Enter key in CCNUM to function properly. Previously, the Enter key for the CCNUM field did not return data or start the browser screen as expected.
Card Check validation routine corrected
The two import parameters were updated in the card check validation routine in CRM in function module /PMENC/P_ND_CHK_CARD_TOKEN.
DI Web Browser Timeout Increased
As requested by numerous customers, the XiIntercept Web Browser timeout has increased from 40 to 80 seconds. The browser timeout can be increased or decreased in the PUE: XiIntercept Parameters.
Card Conversion Program updated
Program /PMEN/CONVERT_CCNUM has been changed to divide clean up tasks into smaller segments. A short dump was occurring due to a limitation in SAP to only process up to 1000 entries.
Known Issues
N/A. There are no known issues for this release.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
-
SAP ERP 4.6c, Support Pack 48 and higher
-
SAP ERP 4.7 Support Pack 22 and higher
-
SAP ECC 5.0 Support Pack 7 and higher
-
SAP ECC 6.0
-
** For DI for SAP SSO, Minimum version SAP GUI 7.1
DI for SAP is not supported in NWBC nor SAP GUI for HTML. -
PAS - Minimum version 2.5.0
Install and Configuration Notes
This is a full transport; there are no setup or configuration instructions specific to this release. Refer to the standard product documentation set.
There are no configuration notes specific to this release. Refer to the XiSecure SAP Integration Guide.
Support Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide (version 2.2.0)
-
PAS Install and Configuration Guide (version 2.5.0)

New Features
Authority Check enhancements as follows:
-
Added before all transactions calls.
-
Added before remote enabled function modules.
Detailed Release Notes
XiSecure SAP CRM

New Features
-
N/A
Problems Addressed
-
Simulate Encryption Program was causing a short dump.
-
CSOUR (CardDataSource) was not being sent to PAS from CRM during Authorization.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
SAP:
-
SAP BBPCRM 700, Support Package SAPKU70013
-
SAP BBPCRM 701, Support Package SAPKU70110
-
SAP BBPCRM 702, Support Package SAPKU70206
-
SAP BBPCRM 703, Support Package SAPKU71201
-
** For XiIntercept for SAP SSO, Minimum version SAP GUI 7.1
-
***Unicode only
SAP NetWeaver PI:
Minimum version SAP PI version 7.11, SP013
PAS:
-
All versions back to minimum are supported.
-
** For B2B Intercept SAP SSO, minimum version 2.7.0
PSNS: 1.0.0 minimum
PCMA: 1.9.0 minimum
Install and Configuration Notes
This release only requires the full transport 3.0.0 be installed.
Refer to the Read_Me.txt file provided with the transports BEFORE you perform any installation activities. This is especially important for upgrades.
Summary of Objects Modified
This section identifies any objects that were modified that should be taken into account when upgrading if you have existing customizations that need to be brought into the new objects.
User exits/wrappers modified in this release:
N/A
General objects modified in this release:
N/A
Known problems
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
-
XiSecure Platform SAP Integration Guide
-
XiSecure ECC.zip (transport files)
-
PAS Setup Guide
-
PAS_Windows_Installer.zip (contains PAS Setup Guide in zip)
-
PAS_RHEL_Install_Pkg.zip (RHEL package contains PAS Setup Guide in zip)
All of these documents and transports/installers are available for download from the Resources page in Merchant Portal.

New Features
Added support for Paymetric SAP NetWeaver Solution (PSNS) communication method.
There is a new IMG setting for Communication Method for which you will select either Paymetric Adapter for SAP (PAS) or PSNS.
PSNS only requires a single RFC Destination for all operations.
The same RFC Destination will also be used for auth, settle, void, & reconciliation when configuring the PCMA Execution Settings with PSNS.
For Clients using PAS, if they upgrade to this version, they must go back into the XiSecure IMG (/PMENC/BIMG) and select PAS as the Communication Method and set the RFC Destinations.
Problems Addressed
-
Corrected problem with XiIntercept not launching from the Business Partner screen in SAP GUI.
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
SAP:
-
SAP BBPCRM 700, Support Package SAPKU70013
-
SAP BBPCRM 701, Support Package SAPKU70110
-
SAP BBPCRM 702, Support Package SAPKU70206
-
SAP BBPCRM 703, Support Package SAPKU71201
-
** For XiIntercept for SAP SSO, Minimum version SAP GUI 7.1
-
***Unicode only
SAP NetWeaver PI:
Minimum version SAP PI version 7.11, SP013.
PAS:
-
All versions back to minimum are supported.
-
** For B2B Intercept SAP SSO, minimum version 2.7.0
PSNS: 1.0.0 or above
PCMA: 1.8.0 minimum
Install and Configuration Notes
This release only requires the full transport 3.0.0 be installed.
Refer to the Read_Me.txt file provided with the transports BEFORE you perform any installation activities. This is especially important for upgrades.
Summary of Objects Modified
This section identifies any objects that were modified that should be taken into account when upgrading if you have existing customizations that need to be brought into the new objects.
User exits/wrappers modified in this release:
-
/PMENC/P_AUTH_WRAP
General objects modified in this release:
N/A
Known problems
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
This release is supported by the following:
-
XiSecure Platform SAP Integration Guide
-
CRM XiSecure v3.0.0.C0012.zip (transport file)
For connectivity, you will choose one of the following installers:
-
Paymetric SAP NetWeaver Solution (PSNS)
-
PSNS Setup Guide
-
PSNS_Package_<ver#>.tpz (PSNS import file)
-
-
Paymetric Adapter for SAP (PAS)
-
PAS Setup Guide
-
PAS_Windows_<ver#>-install.zip -OR-
-
PAS_Linux_<ver #>.zip (RHEL package)
-
All of these documents and transports/installers are available for download from the Resources page in Merchant Portal.

New Features
-
Popup a new session of DI SA if Payer Partner changes after F4 is pressed.
Problems Addressed
-
N/A
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
SAP:
-
SAP BBPCRM 700, Support Package SAPKU70013
-
SAP BBPCRM 701, Support Package SAPKU70110
-
SAP BBPCRM 702, Support Package SAPKU70206
-
SAP BBPCRM 703, Support Package SAPKU71201
-
** For XiIntercept for SAP SSO, Minimum version SAP GUI 7.1
PAS:
-
All versions back to minimum are supported.
-
** For XIIntercept SAP SSO, minimum version 2.7.0.
PCMA:
-
All versions back to minimum supported.
-
**For XiIntercept SAP SSO, Minimum version 1.7.0
Install and Integration Notes
This enhancement release only requires the full transport 2.4.0 be installed.
Refer to the Read_Me.txt file provided with the transports BEFORE you perform any installation activities. This is especially important for upgrades.
Summary of Objects Modified
User exits/wrappers modified in this release:
-
/PMENC/PEX_XiIntercept_PARAM
-
/PMENC/LPEXTTOP
General objects modified in this release:
-
Program: /PMENC/LDIF02
-
Function Module: /PMENC/PSH_CCNUM_F4
Known Problems
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
-
XiSecure-XiIntercept SAP Integration Guide (includes PAS configuration details as well)
-
CRM XiSecure v2.4.1.C0004.zip transport file
-
PAS Windows Installer
-
PAS Red Hat Enterprise Linux (RHEL) Install package

New Features
-
DI for SAP Support Added. XiIntercept for SAP now supported in CRM.
Note that for upgrades, there is no need to create a new RFC Destination and Program ID; use the existing XiSecure/tokenization one when configuring XiIntercept for SAP.For new installs and upgrades, note that the configuration for the Authorization RFC for CRM is in the XiSecure Transport. There is no PCMA transport for CRM.
Problems Addressed
-
N/A
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
SAP:
-
SAP GUI 7.1
-
SAP BBPCRM 700, Support Package SAPKU70013
-
SAP BBPCRM 701, Support Package SAPKU70013
-
** For XiIntercept for SAP SSO, Minimum version SAP GUI 7.1
PAS:
-
All versions back to minimum are supported.
-
** For XIIntercept SAP SSO, minimum version 2.7.0
PCMA:
-
All versions back to minimum supported.
-
**For XiIntercept SAP SSO, Minimum version 1.7.0
Install and Integration Notes
This enhancement release only requires the full transport 2.4.0 be installed.
Refer to the Read_Me.txt file provided with the transports BEFORE you perform any installation activities. This is especially important for upgrades.
Known Problems
There are no known issues for this release.
Supporting Integration Documents and Transports/Installers
-
XiSecure-XiIntercept SAP Integration Guide (includes PAS configuration details as well)
-
XiSecure v2.4.0.C0002.zip transport file
-
PAS Windows Installer
-
PAS Red Hat Enterprise Linux (RHEL) Install package

New Features
XiSecure FlexToken support added
XiSecure OnDemand has FlexToken technology that allows you to preserve the format of the data being represented which supports the use of existing programs and validations against tokens. Depending upon the format selected, it also provides the ability to obtain BIN ranges from the token as well.
A set of commonly used FlexTokens have been created and tested. The format type library is in the Paymetric Onboarding Request Form on the XiSecure tab in the column heading comment for FlexToken. If a custom format is selected, your Paymetric Implementation Consultant or Relationship Manager will discuss the additional implementation time required for creation and testing of the new format.
The PCMA IMG has a new Encryption type, FLX, with corresponding PUE's and configuration to accommodate FlexTokens. Refer to the Review PCMA IMG Settings topic in the PCMA Install and Configuration Guide for additional information. Refer to the Convert to the FlexToken format topic in the XiSecure SAP Integration Guide for additional information on configuring the XiSecure component for this functionality.
Flex tokens allow customers to format their tokens to meet business needs. The XiSecure IMG has a new section to accommodate FlexTokens including:
-
PUE: FlexToken Parameters
-
FlexToken Conversion Program
-
An additional card check routine
-
A new conversion routine for the CCNUM domain
-
A checkbox to use the FlexToken format has been added to the Background program - Resubmit Encryption Failures.
For more information on converting to FlexTokens, refer to the Converting to FlexTokens topic in the XiSecure Implementation Guide.
Problems Addressed
Error when installing CRM 7.0 EHP1
To support the XiSecure transport compatibility with CRM, a new search help /PMENC/FC_RFCDEST has been created. It is included in the structure /PMENC/BLOBDOC to prevent an error message when attempting to upgrade a CRM system.
DI for SAP - All cards being returned from Customer Master
If you have implemented XiIntercept for SAP using the Customer Master there was a problem occurring when changing an order via the VA02 - Change Sales Order screen in which all tokens from the Customer Master were being returned in the selection list instead of just the ones for the selected Customer. This has been corrected.
DI for SAP - Customer Master defaults corrected - IMPORTANT - PLEASE READ
A problem was discovered in XiIntercept-SAP when the Customer Master option is being utilized and will manifest if your Payer Partner and Sold-to-Party values differ in SAP.
This XiSecure Release should be implemented as soon as possible if you fall under this condition using XiIntercept-SAP or there is a risk of retrieving and utilizing the wrong token.
A solution to use Customer Payer Partner has been implemented so that the correct token will be retrieved from the Customer Master. The transport must be imported into SAP and a block of commented code in the XiIntercept-SAP PUE must be uncommented to achieve the fix (block of code is not relevant for CRM).
The block of code is implemented in PUE: /PMENC/PEX_XiIntercept_PARAM. To implement in ECC or an older SAP version, copy the PUE to a Z version and uncomment the block of code under the following comment to the end of the Function Module.
Ability to clear an RFC added
In the execution settings, the ability to clear an implemented RFC in the XiSecure IMG is now available by using the Trash can button. Since XiSecure RFC Destinations have "traffic lights", a Trash can button will appear in place of a "green light" when an RFC destination is configured. The Trash can button is only available if an RFC destination has been configured.
DI-SAP Enter key functionality fixed in CCNUM domain
The User Exit YYZDI has been changed to allow the XiIntercept-SAP Enter key in CCNUM to function properly. Previously, the Enter key for the CCNUM field did not return data or start the browser screen as expected.
Card Check validation routine corrected
The two import parameters were updated in the card check validation routine in CRM in function module /PMENC/P_ND_CHK_CARD_TOKEN.
DI Web Browser Timeout Increased
As requested by numerous customers, the XiIntercept Web Browser timeout has increased from 40 to 80 seconds. The browser timeout can be increased or decreased in the PUE: XiIntercept Parameters.
Card Conversion Program updated
Program /PMEN/CONVERT_CCNUM has been changed to divide clean up tasks into smaller segments. A short dump was occurring due to a limitation in SAP to only process up to 1000 entries.
Known Issues
N/A
Compatibility
The basic compatibility for this release is listed below. See the XiSecure Platform SAP Integration Guide for more detailed requirements.
SAP:
-
SAP ERP 4.6c, Support Pack 48 and higher
-
SAP ERP 4.7. Support Pack 22 and higher
-
SAP ECC 5.0 Support Pack 7 and higher
-
SAP ECC 6.0
-
SAP GUI 7.1 is a minimum requirement with XiIntercept for SAP
PAS:
-
Minimum version 2.5.0
Install and Configuration Notes
This is a full transport; there are no setup or configuration instructions specific to this release. Refer to the standard product documentation set.
There are no configuration notes specific to this release. Refer to the XiSecure SAP Integration Guide.
Supporting Documents
-
XiSecure SAP Integration Guide (version 220)
-
PAS Install and Configuration Guide (version 250)

New Features
Authority Check enhancements as follows:
-
Added before all transaction calls
-
Added before remote enabled function modules