<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security upgrade testing in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237527#M1629776</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SU25 is the upgrade transaction for the PFCG. In step 2a you can copy the SAP data in the customer environment. With 2b you can compare overlapping default changes from your own with SAP. In step 2c roles,where the new default values would have an impact, are marked. The roles marked with red lights are not invalid and can be used with the old authorization set. If you do not process the step 2c it might be possible that you will run in trouble with new or changed authorization checks, that is why it is recommended to run step 2c and update all red roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;P&gt;Blanca&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Oct 2011 07:09:03 GMT</pubDate>
    <dc:creator>blanca_serrano</dc:creator>
    <dc:date>2011-10-05T07:09:03Z</dc:date>
    <item>
      <title>security upgrade testing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237526#M1629775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have upgraded our sytem from R/3 4.6 to ECC 6. Have executed the post security upgarde steps and found that most of the  roles/transactions got implacted. Now we are in security testing phase. It would be very helpful if you could be provide me inputs regrading  how to go about security upgarde testing, stargey to be followed for this testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 03:56:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237526#M1629775</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-10-05T03:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: security upgrade testing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237527#M1629776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SU25 is the upgrade transaction for the PFCG. In step 2a you can copy the SAP data in the customer environment. With 2b you can compare overlapping default changes from your own with SAP. In step 2c roles,where the new default values would have an impact, are marked. The roles marked with red lights are not invalid and can be used with the old authorization set. If you do not process the step 2c it might be possible that you will run in trouble with new or changed authorization checks, that is why it is recommended to run step 2c and update all red roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;P&gt;Blanca&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 07:09:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237527#M1629776</guid>
      <dc:creator>blanca_serrano</dc:creator>
      <dc:date>2011-10-05T07:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: security upgrade testing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237528#M1629777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After SU25 steps, you have to identify the list of tcodes which are changed and which are new.&lt;/P&gt;&lt;P&gt;According to that you should visit all the roles where the above ones are present and do the necessary changes of new authorization checks(use expertmode : Read old data and merge with new data)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This step is should be done with lot of assessment with the help of business discussions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 20:17:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237528#M1629777</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-10-05T20:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: security upgrade testing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237529#M1629778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do what Hari says and then ensure that your updated roles are tested in all the standard e2e business process testing as part of the general upgrade activities.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 11:05:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-upgrade-testing/m-p/8237529#M1629778</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-10-06T11:05:32Z</dc:date>
    </item>
  </channel>
</rss>

