<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security upgrade question in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588352#M1082120</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; p/s besides, we've encountered another issue while running PFCG_TIME_DEPENDECY, I will post it out in a separate message.&lt;/P&gt;&lt;P&gt;Just a guess from me now: You are using composite roles which have the same single roles in them a multiple of times but with different validity dates? If so, the answer is PRGN_COMPRESS_TIMES.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(just a guess in the dark)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Sep 2008 06:13:42 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-09-24T06:13:42Z</dc:date>
    <item>
      <title>Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588346#M1082114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello there, we have just gone through some new installations and upgrades (support pack level.. etc.). We've encountered few problems after this, could anyone of you kindly advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After running the program PFCG_TIME_DEPENDENCY in SA38, we received the following warning messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Authorisation profile for role SAP_XXXXX does not exist", and&lt;/P&gt;&lt;P&gt;"Role SAP_XXXXX does not contain a profile or authorisations"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I further select the message, it navigates me to another message that says "Messages for SU22 and the Profile Generator".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked these roles (all are SAP standard roles) in PFCG, and those that do not contain authorisation profile is because the organizational level is not maintained.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my question is, do I need to separately go though all these hundreds of roles one by one to maintain the organizational level for them, or is there way to mass-maintain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or.. does this have anything to do with SAP_ALL profile regenerate, will that help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for answering!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2008 20:05:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588346#M1082114</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-23T20:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588347#M1082115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The profiles for the standard delivered SAP roles are not generated - this is the reason for the error message. You can, in your selection criteria - just select Z* roles to run the "user compare" program.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: JC on Sep 23, 2008 4:07 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2008 20:07:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588347#M1082115</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-23T20:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588348#M1082116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Theoz,&lt;/P&gt;&lt;P&gt;There is no need to modify any of the SAP* roles. Those are just delivered as a help for the administrators to create there own versions of the roles. They are commonly delivered without a profile o not generated. Just ignore them and only take care of your customize roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Jose.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2008 20:24:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588348#M1082116</guid>
      <dc:creator>jabella</dc:creator>
      <dc:date>2008-09-23T20:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588349#M1082117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will probably have PFCG_TIME_DEPENDENCY scheduled as a job already with a variant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run it from SA38 via that variant (e.g. all roles "not equal to" SAP* naming convention, etc) if you want to do it manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS: It might still be interesting to compare the SAP* role menu between the old and the new. Generally, the access changes with SU22 (SAP does this, and you perform the SU25 steps =&amp;gt; SU24), but the menu could change as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Sep 2008 20:39:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588349#M1082117</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-23T20:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588350#M1082118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey guys, thanks for the quick response.&lt;/P&gt;&lt;P&gt;If I don't generate those standard roles without authoristions or a profile.. will this affect those users who are assigned to SAP_ALL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p/s besides, we've encountered another issue while running PFCG_TIME_DEPENDECY, I will post it out in a separate message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 05:22:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588350#M1082118</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-24T05:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588351#M1082119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; If I don't generate those standard roles without authoristions or a profile.. will this affect those users who are assigned to SAP_ALL?&lt;/P&gt;&lt;P&gt;No. You (re)generate SAP_ALL via other means (SU21, RSUSR406, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 06:11:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588351#M1082119</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-24T06:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588352#M1082120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; p/s besides, we've encountered another issue while running PFCG_TIME_DEPENDECY, I will post it out in a separate message.&lt;/P&gt;&lt;P&gt;Just a guess from me now: You are using composite roles which have the same single roles in them a multiple of times but with different validity dates? If so, the answer is PRGN_COMPRESS_TIMES.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(just a guess in the dark)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 06:13:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588352#M1082120</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-24T06:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588353#M1082121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julius, I've now created a new meesage called "Another security upgrade question". Can you check my problem details and see if that's the same issue as you described?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate it, thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 06:59:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588353#M1082121</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-24T06:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security upgrade question</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588354#M1082122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, that sounds like a different topic - not related to roles assigned a multiple of times to the same user ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2008 07:05:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-question/m-p/4588354#M1082122</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-24T07:05:11Z</dc:date>
    </item>
  </channel>
</rss>

