Showing posts with label SAP Enterprise Portal. Show all posts
Showing posts with label SAP Enterprise Portal. Show all posts

Checking Role Transports

Transaction WP3R can be used to check whether roles were correctly transported to target systems lying on the transport track. You can display and check the role and user data by calling the transaction in a target system. However, you cannot make any changes in this system using transaction WP3R.
Prerequisites

? To maintain the data copied from the portal to the SAP system you need role administration authorization (see Authorizations).

? You are on the Role Administration screen Follow-Up Processes for Portal Roles and have chosen the option Maintain Authorization Roles.
Procedure

To check the role transport, start transaction WP3R in a target system.


You cannot execute any operations that change the data if the system is not responsible for role maintenance in Customizing (table view WP3ROLESYS).

Checking Role Transports

Use

Transaction WP3R can be used to check whether roles were correctly transported to target systems lying on the transport track. You can display and check the role and user data by calling the transaction in a target system. However, you cannot make any changes in this system using transaction WP3R.

Prerequisites

· To maintain the data copied from the portal to the SAP system you need role administration authorization (see Authorizations).

· You are on the Role Administration screen Follow-Up Processes for Portal Roles and have chosen the option Maintain Authorization Roles.

Procedure

To check the role transport, start transaction WP3R in a target system.


You cannot execute any operations that change the data if the system is not responsible for role maintenance in Customizing (table view WP3ROLESYS).

End of Content Area

Transporting Roles to other Target Systems

Depending on the structure of your system landscape, you have to copy the authorization roles created and maintained in one system to the other systems and make them available there (see System Landscape). The system automatically copies the roles with customizing requests.

You have to enter a customizing request for all changes to authorization roles. This ensures that the roles as well as the administration data are distributed in the target system of the transport.

If a role transport is not required, you can deactivate the field for the automatic transport request on the initial screen for role distribution, for example if the role is created and used in the same system.

You can also trigger the transport manually by choosing Authorization role ® Transport. This is necessary for example if you temporarily deactivated the field for automatic transport requests for test purposes and later decide you want to copy your changes to the target systems after all.

Prerequisites

· To maintain the data copied from the portal to the SAP system you need role administration authorization (see Authorizations).

· You are on the Role Administration screen Follow-Up Processes for Portal Roles and have chosen the option Maintain Authorization Roles.

Procedure

To transport roles to another system:

...

1. Select one or more roles.

2. Choose Authorization role ® Transport.

The selected roles are transported.


You can also call the authorization role transport with transaction PFCG under Download/Upload. The administration data of the portal roles are not copied if you trigger the transport with this transaction.

You should therefore always start the transport from transaction WP3R.


Roles are always transported together with their profiles. The option to suppress the profile transport (table PRGN_CUST, entry PROFILE_TRANSPORT) is ignored.

End of Content Area

Deleting Authorization Roles

Use

When deleting an authorization role, the system offers to either remove only the connection between the authorization role and the portal role, or to delete the authorization role completely.

Prerequisites

· To maintain the data copied from the portal to the SAP system you need role administration authorization (see Authorizations).

· You are on the Role Administration screen Follow-Up Processes for Portal Roles and have chosen the option Maintain Authorization Roles.

Procedure

To delete an authorization role:

...

1. Place your cursor on an authorization role.

2. Choose Authorization role ® Delete or choose the This graphic is explained in the accompanying text icon next to the authorization role.

A dialog box appears, in which you state, whether you want to remove only the connection between the authorization role and the portal role, or to delete the authorization role completely.

3. If you want to remove the connection, choose Remove in the dialog box. If you want to delete the authorization role, choose Delete.


You should only delete authorization roles using this maintenance transaction. If you delete roles using other methods, the administration data needed for assigning portal roles is not deleted.


You cannot use the deletion function for more than one role simultaneously.

Generating Authorizations

Use

Maintaining the authorization data includes completing the proposed authorization values entered by the system for the SAP transactions and trace IDs contained in the portal role.

Prerequisites

· To maintain the data transferred from the portal to the SAP system you need role administration authorization (see Authorizations).

· You are on the Role Administration screen Follow-Up Processes for Portal Roles and have chosen the option Maintain Authorization Roles.

Procedure

To maintain the authorization data:

...

1. Click an existing authorization role and choose Authorization role ® Merge and maintain authorizations or choose the This graphic is explained in the accompanying text icon next to the authorization role.

The screen for maintaining the role authorizations is opened. The proposed values are derived from the transactions and services in the menu structure.

2. Check and complete the authorization data.

3. Generate the authorization profile by choosing Generate This graphic is explained in the accompanying text.

4. Return to the screen for Role Administration.


You can also call the screen for maintaining authorization data with transaction PFCG. However, the data needed to maintain the authorization roles does not appear here. You should therefore always start maintenance of the authorization roles from transaction WP3R.

Transferring Role Data in SAP Enterprise Portal

Use

SAP Enterprise Portal offers you a function for distributing the portal roles defined in the enterprise portal to connected SAP systems. Usually, you transfer the roles to a particular SAP system, which is responsible for creating and maintaining the authorization roles within the SAP system landscape. For more information, see System Landscape.

Procedure

...

1. In SAP Enterprise Portal choose System Administration ® Permissions ® SAP Authorizations.

2. To distribute the portal roles in the SAP system choose tab Transfer Portal Roles.

3. On the Transfer Portal Roles tab, choose the system to which you want to distribute the roles from the dropdown list. The alias names are displayed in the dropdown list. Select the alias names you maintained for the system in which the roles are distributed. Read also Creating Systems for Role Distribution.

The following graphic shows the search mechanism based on it:

This graphic is explained in the accompanying text

The portal first uses an RFC module to access table WP3ROLESYS, where the system responsibilities for role maintenance are entered (see step 1 in the graphic). The logical system names are returned to the portal and displayed in a list (see step 2). The portal finds the corresponding portal systems using the logical system names (see step 3). The corresponding aliases are found from the portal systems (see step 4). If no portal system is found for a logical system or no alias is maintained for a portal system, there is a waring and a corresponding status message.

4. Decide which roles you want to distribute. You have the following options:

¡ Option one: Select from transferred roles

¡ Option two: Transfer all transferred roles again

¡ Option three: Select from complete set of portal roles

¡ Option four: Transfer all portal roles

If you choose options one or three, a screen appears, on which you can select the roles that you want to transfer. Select the entries and choose Next. A screen appears, on which you can check your transfer settings.

If you choose options two or four, you go directly to the screen on which you can check your transfer settings.


If you select Include SAP Authorization Trace IDs, the system automatically generates trace IDs in the SAP system for the iViews contained in the portal role. For more information about trace IDs, see Roles and User Distribution to the SAP System.

5. Check all your settings for the role transfer. A name is proposed for the report that performs the distribution. You can overwrite this proposal.

6. Choose Finish. This starts the distribution of the roles.

In this process, the portal checks which of the iViews contained in the roles contain the alias names identified in step 3. All the iViews containing the relevant alias names are selected. The transaction names entered in the iViews are transferred to the SAP system together with the portal role names.


An iView that refers to a transaction in a SAP system always contains an alias name as property.

7. A new screen displays the log messages for the role transfer report. With Stop Transfer you can interrupt the transfer at this location.

With the Display Transfer Reports tab you can display the log files for each executed transfer report again.

¡ Decide if you want to display the log files for the role transfer or for user assignments.

¡ In the list, select a transfer report and choose Display Report.

Distribution Process with Predefined Settings

You can also save your settings under a given name. To do so, choose tab Predefined Transfer Settings and enter a name for your settings. The advantage of this is that you can reuse the settings instead of having to enter all the information again for the next transfer run.

If you use predefined settings, steps 2-6 are omitted. In this case you only perform step 1, go to tab Predefined Transfer Settings and start the transfer from there by selecting the name of the predefined setting and starting the transfer. You can then view the log files, as described in step seven.

End of Content Area

Assignment of Users to Roles

Integration

Portal users must have roles in R/3 to be able to view or work with R/3 content in the portal. For the content administrator to view or manipulate business objects based on R/3 transactions, or for any user to see iViews based on R/3 transactions, they must have roles defined in the back-end system.

With an R/3 system role, the user can use the Drag&Relate navigation mechanism to click on a field in the content area and execute it with parameters simply by dragging it onto any drag-enabled iView in the navigation panel of the portal.

Activities

To assign roles in the SAP R/3 system, there are three possibilities here:

· The user roles in the portal are migrated to the SAP R/3 system. For more information, see Role and User Distribution to the SAP System.

· The user roles are created or maintained directly in the SAP R/3 system.

· The user roles in R/3 are migrated to the portal. For more information, see Unification with SAP R/3 and BW.

Creating and Maintaining User Roles in the SAP R/3 System

To create a new role:

...

1. Choose transaction PFCG.

2. Enter a name and description for the new role and choose Create.

3. Choose the Menu tab and then Transaction.

4. Enter the transaction codes and choose Assign transactions.

5. Choose the Authorizations tab and then Change authorization data.

6. Maintain the authorizations needed for the role.

7. Choose the User tab and assign a user to the role.

8. Choose User compare and then Complete compare.


The role assigned to the portal user must contain at least the following authorizations in order to have access to the SAP R/3 system from the portal and in order to be able to execute Drag&Relate operations:

Authorization object S_RFC with the following field values:
ACTVT:
16
RFC_TYPE:
FUGR
RFC_NAME:
RFC1, RSAN, SDIF, SDIFRUNTIME, SDWZ, SKBW, SPR4, SPRT, SRFC, SSCV, SURL, SUSO, SUSW, SU_USER, SWOR, SYST, SYSU

Authorization object S_TCODE with the following field value:
TCD:
SPO1

For detailed information about the individual steps, see the SAP NetWeaver documentation underSecurity ® Identity Management ® Users and Roles (BC-SEC-USR).

End of Content Area

Role and User Distribution to the SAP System

SAP Enterprise Portal provides you with broad and easy-to-use functions for the creation and administration of roles and users (see Roles in the Enterprise Portal).

In order to be able to access connected SAP systems with the roles managed in the portal, you must transfer these role definitions and user assignments to the SAP systems. For this distribution process, a component in the portal is available, which allows you to distribute the portal roles and user assignments to the SAP system.

Data on the following services can be transferred from SAP Enterprise Portal to the SAP system:

· Transactions

· Non-transactional data (for example, TADIR services or RFC-enabled function modules) in the form of authorization trace IDs

On the SAP system side, transaction WP3R is available. This allows you to assign a corresponding role in the SAP system to users and their assigned portal roles. The corresponding role (authorization role) contains the authorizations that are required to perform certain services, for example, transactions, from within the portal.

Prerequisites

Up to Basis Release 6.20, you must import Enterprise Portal plug-in 6.0 into your SAP systems in order for the functions necessary for follow-up processing of the portal roles to be available in the ABAP-based SAP system.

With Basis Release 6.40, the functions of Enterprise Portal plug-in 6.0 are included in the corresponding PI_BASIS, which no longer needs to be imported separately. See also Note 723189.

For information about the necessary authorizations.

Constraints

· Release 4.0

The portal data can only be displayed. You can neither create authorization roles nor assign roles to users.

· Release 4.5

You cannot assign roles to users if the central user administration is used with global role assignment and a central system of Release 4.5.

· Release 6.20

Support for default authorization values for services is provided through support packages. You can find out the current status in SAP Note 640759.

· Enterprise Portal Plug-In <>

If you use an Enterprise Portal Plug-In <>