<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interpreting RSECADMIN Trace (BI Analysis Authorizations) in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694785#M1293836</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Benjamin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I asked the same question [here|&lt;A class="jive_macro jive_macro_message" href="https://community.sap.com/" __jive_macro_name="message" modifiedtitle="true" __default_attr="6432926"&gt;&lt;/A&gt;;&lt;/P&gt;&lt;P&gt;Apparently nobody knows what these figures are representing &lt;SPAN __jive_emoticon_name="sad"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If do find the answer though, please share it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lodewijk Borsboom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Jul 2009 09:24:30 GMT</pubDate>
    <dc:creator>l_borsboom</dc:creator>
    <dc:date>2009-07-03T09:24:30Z</dc:date>
    <item>
      <title>Interpreting RSECADMIN Trace (BI Analysis Authorizations)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694783#M1293834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recently, one of the users ran a query and encountered an authorization issue.  I logged his ID into RSECADMIN and after he re-ran the query with authorization issues, I took a look at the trace logs and found a section with errors:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Following Set Is Checked&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;Characteristic  Contents  &lt;/P&gt;&lt;P&gt;0CS_GROUP  Node 3 12 0 1185 7 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Comparison with Following Authorized Set&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Characteristic  Contents  &lt;/P&gt;&lt;P&gt;0CS_GROUP  Node 1 Node 2 Node 3 Node 4 Node 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My interpretation is that this user has authorizations for Node 1 - 5, but what I do not understand is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0CS_GROUP  Node 3 12 0 1185 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know it is checking for the characteristic 0CS_GROUP but what does the "Node 3 12 0 1185 7" represent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help in interpreting this is greatly appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jun 2009 16:56:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694783#M1293834</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-05T16:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting RSECADMIN Trace (BI Analysis Authorizations)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694784#M1293835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Confusing: Up to know I had know the &lt;STRONG&gt;report&lt;/STRONG&gt; RSECADMIN which deals with the secure storage, but this questions is about &lt;STRONG&gt;transaction&lt;/STRONG&gt; RSECADMIN, which manages the analysis authorizaions in BI...  I've added a note about the component into the heading of this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jul 2009 14:14:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694784#M1293835</guid>
      <dc:creator>Frank_Buchholz</dc:creator>
      <dc:date>2009-07-02T14:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting RSECADMIN Trace (BI Analysis Authorizations)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694785#M1293836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Benjamin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I asked the same question [here|&lt;A class="jive_macro jive_macro_message" href="https://community.sap.com/" __jive_macro_name="message" modifiedtitle="true" __default_attr="6432926"&gt;&lt;/A&gt;;&lt;/P&gt;&lt;P&gt;Apparently nobody knows what these figures are representing &lt;SPAN __jive_emoticon_name="sad"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If do find the answer though, please share it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lodewijk Borsboom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jul 2009 09:24:30 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694785#M1293836</guid>
      <dc:creator>l_borsboom</dc:creator>
      <dc:date>2009-07-03T09:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting RSECADMIN Trace (BI Analysis Authorizations)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694786#M1293837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Frank:  Thanks for adjusting the title.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lodewijk:  It seems there is no sense in those node numbers.  When I first ran RSECADMIN trace, I was figuring it would be just as straightforward as SU53 - at least that would tell you EXACTLY what you are missing.  However, RSECADMIN trace is cryptic sometimes and it's very difficult with no official documentation.  Not even the experts here seem to know.  About the only thing that helps is when they tell you 'EYE007' (authorization error) and the node/characteristic that the error is happening on.  Then you can sort of look through the user's roles and compare against the variable selection criteria.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyhow, I would love to find out what those Node numbers mean as well.  I asked a fellow BI Security consultant doing this for a couple of years and he was unable to tell me as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jul 2009 15:01:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694786#M1293837</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-03T15:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting RSECADMIN Trace (BI Analysis Authorizations)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694787#M1293838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These node numbers does not have any meaning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you can go through SAP Note 1234567 - The authorization log RSECADMIN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There you can check the paragraph &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Under the heading&lt;/P&gt;&lt;P&gt;  The Following Hierarchy Authorizations Were Found",&lt;/P&gt;&lt;P&gt; there is a list of the hierarchy authorizations of the user.&lt;/P&gt;&lt;P&gt;The fields TCTAUTH and TCTIOBJNM again specify the authorization and&lt;/P&gt;&lt;P&gt;characteristic names. The fields HIESID and HIEID have no significance in&lt;/P&gt;&lt;P&gt;this context. The fields TCTHIENM und TCTHIEVERS and TCTHIEDATE are three&lt;/P&gt;&lt;P&gt;specifications that generally and precisely define each hierarchy of a&lt;/P&gt;&lt;P&gt;characteristic in a BI system: Hierarchy name, version and date (valid-to).&lt;/P&gt;&lt;P&gt;The fields TCTNIOBJNM and TCTNODE precisely define the authorized node.&lt;/P&gt;&lt;P&gt;TCTNODE is simply the technical node name.&lt;/P&gt;&lt;P&gt;TCTNIOBJNM specifies the node type.&lt;/P&gt;&lt;P&gt;a) If TCTNIOBJNM = 0HIER_NODE, then a text node with the name&lt;/P&gt;&lt;P&gt;&amp;lt;TCTNODE&amp;gt; is authorized.&lt;/P&gt;&lt;P&gt;b) If TCTNIOBJNM is blank, a hierarchy leaf with the given name is&lt;/P&gt;&lt;P&gt;authorized.&lt;/P&gt;&lt;P&gt;c) If TCTNIOBJNM has the same name as the hierarchy-defining&lt;/P&gt;&lt;P&gt;characteristic, a chargeable node is authorized.&lt;/P&gt;&lt;P&gt;CAUTION The node type is relevant for the authorization. For example: A&lt;/P&gt;&lt;P&gt;hierarchy authorization for a text node cannot directly authorize a&lt;/P&gt;&lt;P&gt;chargeable node with the same name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Imran&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Imran  Mulani on Jul 5, 2009 9:10 AM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Imran  Mulani on Jul 5, 2009 9:11 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jul 2009 07:10:27 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694787#M1293838</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-05T07:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting RSECADMIN Trace (BI Analysis Authorizations)</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694788#M1293839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Imran:  Thank you very much for leading me to SAP Note 1234567.  This is some helpful information in there!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 13:49:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/interpreting-rsecadmin-trace-bi-analysis-authorizations/m-p/5694788#M1293839</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-06T13:49:51Z</dc:date>
    </item>
  </channel>
</rss>

