Showing posts with label CTS. Show all posts
Showing posts with label CTS. Show all posts

Authorizations in the CTS

This section is intended for customers with longer experience of the SAP System. If you have just installed the system, use the role maintenance transaction to maintain authorizations.

If you want to set up your own authorizations, bear in mind that in addition to the CTS authorizations, users also require the following authorizations to work with the extended view of the Transport Organizer:

  • S_DATASET_AL (for accessing files)
  • S_C_FUNCT_AL (for calling external programs)
  • S_TCD_ALL (for calling transactions)

Since Release 4.0, the administration functions in the CTO have been safeguarded by a new authorization object called S_CTS_ADMI. The authorization object S_TRANSPRT introduced in 3.0 is now used exclusively to safeguard functions that directly change requests and tasks.

The authorizations are checked independently of the user name. User DDIC therefore does not automatically have administration rights. A user who wants to schedule the transport program (RDDIMPDP) needs administration authorization so that the program can run without errors.

The authorization object S_TRANSPRT consists of the fields Activity and Request type. The following values are used:

Activity

Description

01

Add or generate

02

Change

03

Display

05

Lock

06

Delete

23

Change/edit object list manually

43

Release

50

Change source client

60

Transport

65

Merge request

75

Release other user's requests

78

Edit transport proposal

90

Change owner

Request types

Description

CLCP

Client transports

CUST

Customizing requests

DLOC

Local change requests

DTRA

Transportable change requests

MOVE

Relocation transports

PATC

Support Packages

PIEC

Piece list

TASK

Task (repair or correction)

TRAN

Transports of copies

The authorization object S_CTS_ADMI, with safeguards administration functions, only has the field CTS_ADMFCT, whose values describe the various administration activities. Use the following values to assign the user authorization for particular administration functions.

Administration function

Description

TABL

Maintain the control tables of the Transport Organizer (for example, configure the transport routes)

  • Schedule the transport dispatcher RDDIMPDP
  • Call certain administration tools (Transaction SE03)
  • Extended maintenance authorization when changing the object directory entries with the tool Change Object Directory Entries of Objects (Transaction SE03).

INIT

Initialize the Transport Organizer, for example, after a system copy

SYSC

Setting the System Change Option

PROJ

Manage projects in the Change and Transport System

INBX

Edit the TMS worklist

QTEA

Approve transports into the production system

IMPA

Import all requests in an import queue

IMPS

Import individual requests into the target system

TADM

Special transport functions in TMS

TDEL

Delete transport requests from the import queue

TADD

Forward transport requests to an import queue

TQAS

Activate or delete inactive transport requests

IMPT

Import requests into the target system using the Transport Management System (obsolete)

EPS1

Generate EPS objects

EPS2

Change EPS objects

Transport Operator

Technical name: SAP_BC_TRANSPORT_OPERATOR

Tasks

The Transport Operator is responsible for routine tasks such as imports, approving software changes, transports, tracking imports, and so on.

Activities in the Change and Transport System

The tasks of the Transport Operator include:

  • Importing transport requests into systems in the transport domain
  • Approving transports that are part of the transport workflow or quality assurance procedure
  • Using the Alert Monitor to monitor the transport domain
  • Using the import tracking functions to check transports
  • Analyzing and editing the contents of transport requests.

The Transport Operator role has display authorization in the Transport Organizer and Transport Organizer tools.

Integration

Transport requests are created by the Customizing Project Administrator and the Development Project Leader. These users create tasks for the Customizing Project Members, ABAP Developers and Documentation Developers working on the project. In turn, these users record their changes in transport objects in tasks and then release the tasks. After the Customizing Project Administrator or the Development Project Leader has released it, the request is imported into other systems by the Transport Operator or Transport Administrator.

The Transport Operator supports the Transport Administrator in his or her routine tasks in the Change and Transport System (making transports, approving changes, monitoring, and so on). However, fundamental changes to the SAP Systems, such as reconfiguring the landscape, importing SAP software, creating transports, deletions, and so on, remain the responsibility of the Transport Administrator.

The Transport Administrator needs display authorization for the ABAP Workbench to be able to analyze transport objects. This authorization is in the role ABAP Developer: Display Authorization.

Transport Administrator

Technical name: SAP_BC_TRANSPORT_ADMINISTRATOR

Tasks

A user with the role Transport Administrator is a superuser of the Change and Transport System. The tasks of this user include:

  • Configuration of the system landscape with the Transport Management System
  • Import of new SAP software
  • Routine transport tasks such as imports, approving changes, and so on.

The Transport Administrator role has all authorizations in the Change and Transport System.

Activities in the Change and Transport System

The main daily task of the Transport Administrator is importing transport requests into the systems of his or her transport domain. This includes actually importing the requests, approving transports that are part of the transport workflow or quality assurance procedures, using the Alert Monitor to monitor the transport domain, and tracking imports. The Transport Administrator has full authorization to analyze and edit transport requests in the Transport Organizer and the Transport Organizer tools.

The administrator also configures the system landscape for the Change and Transport System, including the transport domain and the transport routes. He or she sets the system and client change options.

The Transport Administrator imports new SAP software, such as Support Packages and add-ons, upgrades the system, and adjusts any modifications. Language transports are another area for which this administrator is responsible.

Note

The Transport Administrator has the Transactions STMS, SA38 and RZ20 in the LaunchPad, without which certain less frequent functions cannot be accessed. If you change the single role Transport Administrator into a composite role, and want to make the LaunchPad less complicated, you can delete these transactions from the composite role menu. This does not change the authorization to execute these transactions.

Integration

Transport requests are created by the Customizing Project Administrator and the Development Project Leader. These users create tasks for the Customizing Project Members, ABAP Developers and Documentation Developers working on the project. In turn, these users record their changes in transport objects in tasks and then release the tasks. After the Customizing Project Administrator or the Development Project Leader has released it, the request is imported into other systems by the Transport Operator or Transport Administrator.

The Transport Administrator is supported in his or her routine tasks in the Change and Transport System by the Transport Operator (making transports, approving changes, monitoring, and so on). However, fundamental changes to the SAP Systems, such as reconfiguring the landscape, importing SAP software, creating transports, deletions, and so on, remain the responsibility of the Transport Administrator.

One typical task of the Transport Administrator is to use the client copy function. All transactions and authorizations for this function are in the role Client Copy.

The Transport Administrator needs display authorization for the ABAP Workbench to be able to analyze transport objects. This authorization is in the role ABAP Developer: Display Authorization.

Authorization Concept in the CTS

All functions in the CTS are safeguarded by detailed authorization checks.

With the help of authorizations, you can specify whether a user may perform administration functions and which request types this user can edit.

SAP provides roles for the different CTS user types. Each role has the appropriate authorizations for the different CTS activities. In most cases it is sufficient to set user authorizations by assigning roles. You can use the role maintenance transaction (PFCG) to change the authorizations of roles for your own requirements, or to create new roles.

Sap basis Change and Transport System

The Change and Transport System (CTS) is a tool that helps you to organize development projects in the ABAP Workbench and in Customizing, and then transport the changes between the SAP Systems in your system landscape.

This documentation gives you an overview of how you can use the CTS to organize your changes, as well as basic information on setting up your system and client landscape, and choosing a transport strategy. Read and follow this documentation when planning your development project.