<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ST22 access in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387595#M1043367</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A security consultant need not have access to ST22 in Production. If a user would want to send you a authorization error that would be through SU53. In case you would like to have access to ST22 this is to be restricted and therefore should be through a Firefighter or Swat ID (which is monitored)&lt;/P&gt;&lt;P&gt;I would think that S_DEVELOP is okay in production with activity 03 (depending on a case by case basis)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ravi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Aug 2008 09:58:35 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-08-20T09:58:35Z</dc:date>
    <item>
      <title>ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387591#M1043363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear guru's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many RFC authorization issues will occur as ABAP dumps (ST22). I am security consultant, and everyday Basis team is sending me email for RFC authorization dumps(st22 screen shot).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked for St22, required is S_DEVLOP auth. object with activity=display. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you guys recommend that security consultant should have access to ST22 (display access) in production server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly advise.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 09:33:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387591#M1043363</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T09:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387592#M1043364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Imran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as access to ST22 TCode concern, a Basis guy should have the access to ST22 TCode. As I am a Basis person, I have the access to this TCode. As you are a Security person,  access to ST22 TCode is not your cup of tea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Satish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 09:38:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387592#M1043364</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T09:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387593#M1043365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Satish for your inputs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the problem is Basis people are sending any RFC authorization daily morning time during their health check. So i will not be getting upto date errors to resolve before end user come to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if authorization team should have ST22 access, i don't see any harm to give display access... &lt;/P&gt;&lt;P&gt;still looking for experts advise like you &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 09:50:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387593#M1043365</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T09:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387594#M1043366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; As far as access to ST22 TCode concern, a Basis guy should have the access to ST22 TCode. As I am a Basis person, I have the access to this TCode. As you are a Security person,  access to ST22 TCode is not your cup of tea.&lt;/P&gt;&lt;P&gt;Sorry to disagree with you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ST22 checks S_DEVELOP actvt '03' (display) without any values for the other fields - how could it when it does not yet know which program dumped? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is checked because once inside the dump, there is a possibility to step into the source code in debug mode which will then check further fields of S_DEVELOP (e.g. object type = DEBUG, etc). You don't have to have that authority nor give it to the security admin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If an RFC call fails and recorded in the dump analysis, it can be security relevant and the security admin should be able to look into the context of the call - and &lt;STRONG&gt;not&lt;/STRONG&gt; just add it to a role because "basis" says it's dumping...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand, perhaps you can google "ST22 basis sap_all only" and give us some random links?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 09:51:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387594#M1043366</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T09:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387595#M1043367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A security consultant need not have access to ST22 in Production. If a user would want to send you a authorization error that would be through SU53. In case you would like to have access to ST22 this is to be restricted and therefore should be through a Firefighter or Swat ID (which is monitored)&lt;/P&gt;&lt;P&gt;I would think that S_DEVELOP is okay in production with activity 03 (depending on a case by case basis)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ravi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 09:58:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387595#M1043367</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T09:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387596#M1043368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Imran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, as you said, there is no harm in having &lt;STRONG&gt;display&lt;/STRONG&gt; authorization for a security person for ST22 TCode in Production. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Satish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 10:03:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387596#M1043368</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T10:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387597#M1043369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; A security consultant need not have access to ST22 in Production. If a user would want to send you a authorization error that would be through SU53. &lt;/P&gt;&lt;P&gt;How is a remote RFC user in the background processing going to take a screenshot of SU53 and email it to you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; In case you would like to have access to ST22 this is to be restricted and therefore should be through a Firefighter or Swat ID (which is monitored). I would think that S_DEVELOP is okay in production with activity 03 (depending on a case by case basis).&lt;/P&gt;&lt;P&gt;I have S_DEVELOP display access in some production systems as well, but only with specific object types. It does not include DEBUG even in display mode. So I can start ST22 and read the dump, but not debug the source of the dump...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, most users can typically get much of this information from table SNAP anyway...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 10:03:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387597#M1043369</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T10:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: ST22 access</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387598#M1043370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 11:03:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/st22-access/m-p/4387598#M1043370</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-20T11:03:43Z</dc:date>
    </item>
  </channel>
</rss>

