Showing posts with label user. Show all posts
Showing posts with label user. Show all posts

Thursday, 11 March 2021

user password reset for user re-use in hdbuserstore list

case studies:

  1. If the HDB user password is restarted by the user, with out updating the password in hdbuserstore list. then the following steps need to perform.
  2. If the user is locked, due to wrong password in hdbuserstore list.
  3. Generally hdbuserstore key allows 6 attempts of wrong password, after that user will locked.
  4. hdbuserstore list keys basically use for scripts.

steps:

alter user <user name> reset connect attempts.

alter user <user name> active user now


To change password:

alter user <user nsame> password <password>


Sunday, 22 November 2020

step by step process for SAP User audit(EULA)

1.Based on the SAP contract, each customer is obligated to perform system measurement of a systems.
2.measuring the system determines No. of SAP systems are in use and No. of user of SAP systems.
3.Before system measurement takes place SAP sent. so called measurement request to the customer. with some details how to perform such a measurement.

with the measurement request following attachments are available:
  1. measure plan: information about all installation and systems.
  2. special version of measurement plan: need to upload to measurement tool SLAW.
  3. self declaration plan: To add new product for the measurement plan.
  4. snote list. - provides the list of snote that need to implement before system measurement.
To perform system measurement need 2 t-codes:
  1. USMM : system measure for single system.
  2. SLAW ; consolidation all systems measurement.
start system measurement: need to perform on each system in the measurement plan.

1. enter the T-code: USMM.



select the type of the system. in case any client in the system of type production. select the checkbox for production.


in client tab:

Enable all the production clients in the production server.
Enable all the development clients in the dev server. similarly for QAS server also.
remaining clients can be uncheck for the system measurement.


in the price list tab: need to select the price list according to your SAP software contract.

in the system measurement request email. the info about the price list is available.


 Depending on the selected price list chosen, the system shows related default use which is used to classify the unclassified users.
  



User types: the user list available in the list here. can be used for user classification.
SAP recommends to uncheck the active check box for the user types which are not required.


To specify the customer specific user type can defined here by replacing the special module type with best description and can user in defining user type in su01 --> LIC data tab.



Address tab: if need to get conformation once audit data sent to SAP. Need to maintain sender and receipt mail id here.



All the information provided in the 5 tabs should be correct and accurate. to avoid cross questions from SAP.

User classification:

Please note that you can classify and reclassify user with in the logon client users.


Need to switch to valid users list.

with valid users option, users with validity will only will be listed.



select all unclassified or user which need to classify and go with the option classify selected Records:



Select the correct and required user type from the drop down and click on save.                        

select the user type in the drop down and SAVE.                                                                                      
Mass change option in USMM tcode.                                                                                                                


here we have 2 option,                                                                                                                
1. to classify all non classified user at once.                                                                 
2.Change user type from one type to another.                                                                  





to classify non classified user, follow the below process.                                                                              
1. Select the user type for the unclassified users.
2.Click on execute.                                              



To change already defined user type in to another perform the below navigation.                                            





System measurement logs: logs provide all relevant information by last system measurement.

To display the measurement results. Click on the logs.



the measurement logs are structured in different sections:
  • sender and recipients information provided in the address tab.
  • system data includes installation number and system type info.
  • Status of background job should be finished for all the entries.







Troubleshoot logs:

in case of any wrong assignments 


After pressing the logs option --> the below pop up will be shown in the screen with the inconsistency list.

here i am selecting professional users w. Inconsistent  Classification.
then followed by workbench users with inconsistent classification.





The system determines and display users that are made entries in certain database tables during 4 weeks period from the system measurement and which activity do not match the currently selected user classification. This user should be classified as either professional or limited professional.

To check what is the activity performed by the user to make him as professional or limited professional user --> Click on the Activity box as highlighted below --> change --> make the user changes --> save.








if you use license agreement tool to consolidate the result, download measurement results per system.
In the menu bar go to system measurement --> Export to LAW file.

 



 


alternative download for Email and sent result through email.





Consolidation: which consolidates measurement results to avoid multiple counting of same user.

Now we can go for Prod login as we are sending through the SAP Central Instance Installation production system.




  •  Run T-code SLAW:
  • Here we can upload the template(.xml file) given by SAP & upload all the req systems License report or here in you may just leave as it is if no new SAP system launched since last year & just make a reply mail by saying that other systems we are not using. If want to upload the .xml file then, as below Change view-> Maintain RFC Data





Then save the .xml file sent from SAPLabs to your desktop & as follows click on the open button to browse to the .xml template & click open & it will show what & all the systems are required to be measured as per SAPLabs & whatever systems License data you will not be sending to SAPLabs , you can just select the column & press the delete button as follows,
in case the system is not in use from last system measurement to now.
in case any new system added from the last system measurement. choose add button as shown below (4).



once after adding all the system data start consolidation and sent the final result to SAP.


Friday, 10 January 2020

issue : ASE user connection

issue:
ASE user connection
Use cases:

 1. If it is ASE installation  2. If App+DB are on same host or it is a Business Suite Installation. how to verify:
"1. Switch to syb<SID> and check the log in the file below: /sybase/<SID>/ASE16-0/install/<SID>.log 2. Error will be in below format: Number of connections exceeded" Solution:
"1. Switch to syb<SID> 2. login to isql: isql -Usapsa -S<SID> -X go 2. Change user connections: sp_configure ""number of user connections"",375 go "

Saturday, 14 September 2019

User administration in SAP BASIS

1.Good reference for user administration in ECC systems. 
2. Good reference for user administration in portal systems.




Security: improve your user Master Record Accuracy with Hidden Fields

By default,some user master record fields in Transaction SU01 are not displayed.for better accuracy enter custom data to better classify your master data.

This post especially useful for the SAP customers, who do not have SAP ERP HCM (Human Capital Management).

Note: By following the below steps,Maintaining the perner number,company code, department,personnel area etc. is also possible. You can gather all the information by tables USR02,USR21,ADCP,ADR6 ,V_USERNAME and USER_ADDR.



Here's How

Step 1: Login to respective system.

step 2: Execute T-code: SU01

step 3: click on Edit button.
           Here i'm using DDIC user, use your user name as per your requirement.

             

step 4: Default screen obtain with the above step.                                                                                                                                                                                                                               

Step5: click on the button as shown below.


step 6:Then the hidden fields are displayed. maintain the hidden fields and SAVE. for the better accuracy of user Master data.




Saturday, 31 August 2019

BI_security/ BW_security

                                                           A brief note on security:                                                              
  • ECC security is Transaction based security.       
  • HR security is position based security.
  • BW/BI is Query based security.                                                                                                                                    
  • Data in ECC system is permanent data. where as BW/BI is analytics data.
Ex1: bank transaction data for all the transaction will be stored bank server is an example for ECC system data.where as last 6 transaction data which, will get in mini statement is query based data from BW/BI server.

Ex2: Suppose their are 3 lakhs of employee working in an ERP based company.this data will be stored in ECC systems. where as query for top 10 salary getting employees query will be in BW/BI system.

  • Query in BW/BI server will re-arrange the data in ECC system.
  • Authorization maintenance for this queries is called BW/BI security.  

Note:
connection between ECC system to BW/BI system will be done through RFC connection. with the concept behind it ETL tool.

E - extract.
T- Translation.
L- Load.

ex: in ECC system                                                                             in BI/BW system

                emp name ----------------------------------------------------------------> first name

Difference between BW and BI systems:
----------------------------------------------------------|---------------------------------------------------------------
                  BW                                                                                           BI
------------------------------------------------------------------------------------------------------------------------                                                                                
  • last version of BW - 3.5                                                      last version of BI 7.X
  • ABAP based                                                                          Netweaver based
  • Customizing authorization objects                                     Analysis authorization
  • T-code: RSSM                                                                     T-code: RSECADMIN
  • one authorization objects have 10 fields                              No limit
--------------------------------------------------------------------------------------------------------------------------
Note:
for security admin only works on 2 T-codes: RSSM (if the system is BW system.)
                                                                        RSECADMIN (if the system is BI system.)

Key points to be consider for BI security:
  • source system: It's either SAP or NON SAP system.
  • Data source: whatever the data available in SAP BI system we call Data source (Info packages).
  • Info Area: the place where BI data is store in the BI system is called INFO AREA(folder name).
  • Info object catalog: who folds actual /all objects( Folders inside INFO AREA, for better segregation).
eg: Movies is folder name, inside telugu movies,tamil movies,Kanada movies are folders inside the folder Movies.

  • Info objects: Each field in the tables( combination of key figures and characteristics)
  • Info provider: Through info provider will load the data inti info objects.

Here we go for the practical steps 👀:

  1. login to BI system.by providing user id and password.
2. Access T-code RSECADMIN
3. The screen rsecadmin screen looks like below.                                                                                    
4.click on Autorizations and then Maint. As shown below.                                                                      

5.Enter the Authorization object name.So called as Role in ECC systems.                                     

6.click on create.                                                                                                                                         
7.provide the description details.                                                                                                           

8.click on insert special characters to obtain default authorization object.

8(2). Resultant screen for the step 8.                                                                                                         


9. click on the intervel option.as shown below.


10.Click on the add  button. To add the custom role as per the business requirement.
11.Then click on the help button. As shown below to add Info objects.

12. Add the required info object.

13. Add the intervals value.




14. Click on SAVE.


14. To add no. of info objects

15. Followed by operator value.

16. select the value as per the business requirement.                                                                                



17. click on SAVE.

18. Go with YES.
19. finally SAVE again, after defining the interval value.



20.From the previous steps creation of Authorization required is completed. Now assign to user.
21.Click on Assign.
22.Click on Change as shown below screenshot.

23. Enter the Authorization role in the Authorization selections & click on Insert.
      Cross check the result as shown in the screen shot as 2.

Hurrah!!! the authorization is added to the user in BI system.




Authorization maintenance for BW(3.5) system

Note: The authorization maintenance for BW system is almost similar to ECC system. But the below authorization object need to add manually.

step 1: 

SU01 ---> collection user details--> assign the T-code: RSSM
PFCFG --> create role.


step 2:

Name of the Authorization object is s_rs_comp



step 3:                                                                                                                                                       
Add the s_rs_comp1 to add user details.                                                                     




Step 4: save and generate profile similar like ECC system.