<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XI Security in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641101#M608006</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alice,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Developer roles in Dev:&lt;/P&gt;&lt;P&gt;SAP_XI_DEVELOPER&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Developer roles in Qty:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;SAP_XI_SUPPORT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Administrator roles in Dev:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR&lt;/P&gt;&lt;P&gt;SAP_XI_ADMINISTRATOR&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;SAP_XI_SUPPORT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Administrator roles in Qty:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR&lt;/P&gt;&lt;P&gt;SAP_XI_ADMINISTRATOR&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Administraor roles in Prod will be very restricetd and should be used with same as Qty but its advisable to keep the user locked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A small note here. When you try to copy standard Java roles they will not work due to permissions problem. SAP Recommonds to use customized ABAP roles and Standard JAVA roles without changing them. But if you want to copy JAVA roles into customized roles, then please let me know. I will explain the procedure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farooq.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Aug 2007 14:16:32 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2007-08-23T14:16:32Z</dc:date>
    <item>
      <title>XI Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641099#M608004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Iam relatively new to XI security. I'd like to know what roles are essential for developers and administrators in &amp;lt;b&amp;gt;production&amp;lt;/b&amp;gt;? we already developed some roles in dev box but developers seem to have lot of authorizations which should be restricted in production. How do i decide which roles are necessary ? Are there any transactions( XI specific) or roles that developers should  not be given access.&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 02:53:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641099#M608004</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-08-23T02:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: XI Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641100#M608005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alice,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can not answer your question, but i think you will be able to help me.. &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am searching for dev-roles for the XI. I have created the basis rolses based on folwowing SAP-standard roles:&lt;/P&gt;&lt;P&gt;SAP_XI_ADMINISTRATOR_ABAP&lt;/P&gt;&lt;P&gt;SAP_XI_ADMINISTRATOR_J2EE&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR_ABAP&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR_J2EE&lt;/P&gt;&lt;P&gt;SAP_XI_CONTENT_ORGANIZER_ABAP&lt;/P&gt;&lt;P&gt;SAP_XI_CONTENT_ORGANIZER_J2EE&lt;/P&gt;&lt;P&gt;SAP_XI_DEVELOPER_ABAP&lt;/P&gt;&lt;P&gt;SAP_XI_DEVELOPER_J2EE&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY_USER_ABAP&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY_USER_J2EE&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR_ABAP&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR_J2EE&lt;/P&gt;&lt;P&gt;SAP_XI_SUPPORT_ABAP&lt;/P&gt;&lt;P&gt;SAP_XI_SUPPORT_J2EE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any other roles which are necessary or do you have a hint for me, which role should get more / lessauthorization? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THX for your answer in Advance.&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 06:43:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641100#M608005</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-08-23T06:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: XI Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641101#M608006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alice,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Developer roles in Dev:&lt;/P&gt;&lt;P&gt;SAP_XI_DEVELOPER&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Developer roles in Qty:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;SAP_XI_SUPPORT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Administrator roles in Dev:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR&lt;/P&gt;&lt;P&gt;SAP_XI_ADMINISTRATOR&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;SAP_XI_SUPPORT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Administrator roles in Qty:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP_XI_CONFIGURATOR&lt;/P&gt;&lt;P&gt;SAP_XI_ADMINISTRATOR&lt;/P&gt;&lt;P&gt;SAP_XI_DISPLAY&lt;/P&gt;&lt;P&gt;SAP_XI_MONITOR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Administraor roles in Prod will be very restricetd and should be used with same as Qty but its advisable to keep the user locked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A small note here. When you try to copy standard Java roles they will not work due to permissions problem. SAP Recommonds to use customized ABAP roles and Standard JAVA roles without changing them. But if you want to copy JAVA roles into customized roles, then please let me know. I will explain the procedure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farooq.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 14:16:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641101#M608006</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-08-23T14:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: XI Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641102#M608007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a bunch, Farooq. That really helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We already have customized ABAP roles and we're using SAP standard JAVA roles. I would definetely like to know how to copy JAVA roles into customized roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Markus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Farooq mentioned, you can copy the ABAP roles into customized roles and use SAP std JAVA roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; A small tip, you might want to take away SU01 &amp;amp; PFCG authorizations from these roles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 17:17:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641102#M608007</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-08-23T17:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: XI Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641103#M608008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alice, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Java roles work with influence of permissions in Application Server which we call actions in UME. As you are aware in PI user master record will be in ABAP stack. So the roles in ABAP stack will be having only RFC connections to JAVA stack for the specific JAVA based role. So you need to edit the permission on Java App Server. For that you need to log on to server through visual admin and then go to services and you will find the standard groups assigned to actions. But I don&amp;#146;t remember that under which service you will find them &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under that service you will find some 200 actions. And you have to add the name of the custom created JAVA roles on ABAP to all those actions where you find the standard roles. And its a very very lengthy procedure. So SAP advice to go for customized ABAP roles and Standard JAVA roles. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answer clears your query. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farooq.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 17:47:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641103#M608008</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-08-23T17:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: XI Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641104#M608009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate your insight &amp;amp; prompt response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a document for this &amp;#133;copying SAP Java roles to custom roles.  If so, please email it to suudsv@yahoo.co.in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have another question..what is the difference between a UME role and J2EE security role? Can you give a example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 19:18:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641104#M608009</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-08-23T19:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: XI Security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641105#M608010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have any document on this. I found it myself after 2 weeks of research. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farooq.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 19:41:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/xi-security/m-p/2641105#M608010</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-08-23T19:41:15Z</dc:date>
    </item>
  </channel>
</rss>

