<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lock access to ABAP system - Allow access to JAVA system in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312569#M1535678</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have SSO configured between them ( ABAP &amp;amp; JAVA ) you can achieve your goal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and allow GUI access for those 2-3+ users to perform admnistrative activities &lt;/P&gt;&lt;P&gt;but in this case remember the user will still be unlocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the user needs to view data from the backend system&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Sep 2010 20:10:31 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2010-09-15T20:10:31Z</dc:date>
    <item>
      <title>Lock access to ABAP system - Allow access to JAVA system</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312564#M1535673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear SAP colleagues,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do have 2 SAP SRM systems :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. DL1 is our SRM-ABAP system&lt;/P&gt;&lt;P&gt;2. DJ1 is our SRM-JAVA system&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A user is created in DL1 (ABAP) system.&lt;/P&gt;&lt;P&gt;The DJ1 UME links to DL1. In other terms, a user is created in ABAP system (DL1) and automatically replicated to JAVA system (DJ1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question :&lt;/P&gt;&lt;P&gt;We want to give access to our user only to DJ1 (SRM-JAVA) system.&lt;/P&gt;&lt;P&gt;User must not be able to connect on SRM-ABAP system (DL1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I lock the user in DL1 (ABAP), it is automatically locked on JAVA system (DJ1), which is normal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User has ABAP roles and JAVA roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a solution to give access to a user on JAVA system (DJ1) and lock the same user in DL1 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your suggestion, even if it is a strange request ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 12:31:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312564#M1535673</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-09-14T12:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Lock access to ABAP system - Allow access to JAVA system</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312565#M1535674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Think this way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;U1=user1&lt;/P&gt;&lt;P&gt;R1= role 1 in java stack&lt;/P&gt;&lt;P&gt;R2 = role 2 in ABAP stack&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How will the user get access to R2? if you remove the relationship between R2 and U1?&lt;/P&gt;&lt;P&gt;with your present installation model.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen UME/portal UME connected to ABAP database ( ABAP SRM ) only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have the Netweaver install pointing to UME only ( my knowledge is it will be java only stack )&lt;/P&gt;&lt;P&gt;in that case your  NW SRM ABAP side which will be independent , the user can be locked forever!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 20:08:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312565#M1535674</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-09-14T20:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Lock access to ABAP system - Allow access to JAVA system</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312566#M1535675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can disable password logon using parameter login/disable_password_logon and not to set up SSO. So normal users won't be able to log on. I am not sure if this parameter affects Java stack but it looks like DJ1 is a separate system. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you could use an user exit SUSR0001 which is called after dialog log on to ABAP stack. But be careful about it. Probably you don't want to lock out all users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another approach could be to put firewall in front of your ABAP stack and allow dialog logon only from limited range of IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW if you don't give authorization to run any transaction to users (S_TCODE) then you don't care if users can log on or not. They won't  be able to do anything. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 00:39:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312566#M1535675</guid>
      <dc:creator>mvoros</dc:creator>
      <dc:date>2010-09-15T00:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Lock access to ABAP system - Allow access to JAVA system</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312567#M1535676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DL1 (SRM-ABAP) is the UME source system of DJ1 (SRM-JAVA), through SAPJSF user.&lt;/P&gt;&lt;P&gt;I need to keep the connection between both systems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybye I was not precise enough in my problem description :&lt;/P&gt;&lt;P&gt;1. DL1 - SRM-ABAP system - contains all users.&lt;/P&gt;&lt;P&gt;    All users are created in DL1 and then automatically replicated to DJ1 (SRM-JAVA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. We do have 300 users. Among them, only 2-3 users must have access to ABAP system (DL1) for certains activities.&lt;/P&gt;&lt;P&gt;    Theses 2-3 users will be SAP Basis Administrator, SRM Admin, SRM Manager, SRM-Catalog Manager.&lt;/P&gt;&lt;P&gt;    They need to have access to DL1 to work on ABAP system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    But all other users (key users, assistants, ...) must not have access on ABAP system (DL1), but only&lt;/P&gt;&lt;P&gt;    on JAVA (portal) system (DJ1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal :&lt;/P&gt;&lt;P&gt;1. I do not want autorize all this users to have access on ABAP system (DL1) but only on JAVA system (DJ1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea or suggestion ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;CP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 08:16:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312567#M1535676</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-09-15T08:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Lock access to ABAP system - Allow access to JAVA system</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312568#M1535677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The easiest way would be to use network restrictions: e.g. block SAPGui between the client network and the server network, and / or deny access from all hosts except the Java instances. When the maintenance window is over, you just open the access again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without knowing your setup it is hard to recommend where you should do this (e.g. firewall, SAProuter, message server, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 08:31:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312568#M1535677</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-09-15T08:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Lock access to ABAP system - Allow access to JAVA system</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312569#M1535678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have SSO configured between them ( ABAP &amp;amp; JAVA ) you can achieve your goal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and allow GUI access for those 2-3+ users to perform admnistrative activities &lt;/P&gt;&lt;P&gt;but in this case remember the user will still be unlocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the user needs to view data from the backend system&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 20:10:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/lock-access-to-abap-system-allow-access-to-java-system/m-p/7312569#M1535678</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-09-15T20:10:31Z</dc:date>
    </item>
  </channel>
</rss>

