Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Seurity Upgrade question

Former Member
0 Kudos

Hi All,

We are process of upgrade from ECC 5.0 to ECC 6.0. I need some information regarding the authorisation upgrade.

q1) If we haven't made any changes to authorisation check values in su24, then is it mandatory to perform upgrade using SU25.

q2) How can i find the roles affected by new authorisation objects introduced in ECC 6.0 version. Does the new authorisation objects introduced in ECC 6.0 version automatically get added to the roles when upgrade is done.

Is there any way to find these roles affescted due to addition new auth objects apart from using step 2c in SU25. If i run step 2c in su25, i am getting all the roles for which the authorisations has been manually changed (like standard new, Maintained new)

q3)What happens exactly when i run step 2a, step 2b in au25, does SAP automatically run load the default values in to the customer tables when upgrade is done?

I have gone thorugh the previous links regarding the upgrade, but need some clear picture regarding this.

Could any one help me with this?

Your answers are much appreciated.

Regards,

Sandhya

1 ACCEPTED SOLUTION

Former Member
0 Kudos

Hi Sandhya,

1) If we haven't made any changes to authorisation check values in su24, then is it mandatory to perform upgrade using SU25. - yes you have to because during upgrade there are many of the roles get affected due to new authorization objects introduced. You can have list of affected roles in SU25 -2C.

q2) How can i find the roles affected by new authorisation objects introduced in ECC 6.0 version. Does the new authorisation objects introduced in ECC 6.0 version automatically get added to the roles when upgrade is done.- New authorization objects automatically get added.

Is there any way to find these roles affescted due to addition new auth objects apart from using step 2c in SU25. If i run step 2c in su25, i am getting all the roles for which the authorisations has been manually changed (like standard new, Maintained new) - As per my knowledge , Su25 2c step is the only option to check affected roles.

q3)What happens exactly when i run step 2a, step 2b in au25, does SAP automatically run load the default values in to the customer tables when upgrade is done? - Step 2A , 2B just compares the two versions. If there are any new values introduced , SAP automatically loads the new customer tables

Thanks,

Sneha

3 REPLIES 3

Former Member
0 Kudos

Hi Sandhya,

1) If we haven't made any changes to authorisation check values in su24, then is it mandatory to perform upgrade using SU25. - yes you have to because during upgrade there are many of the roles get affected due to new authorization objects introduced. You can have list of affected roles in SU25 -2C.

q2) How can i find the roles affected by new authorisation objects introduced in ECC 6.0 version. Does the new authorisation objects introduced in ECC 6.0 version automatically get added to the roles when upgrade is done.- New authorization objects automatically get added.

Is there any way to find these roles affescted due to addition new auth objects apart from using step 2c in SU25. If i run step 2c in su25, i am getting all the roles for which the authorisations has been manually changed (like standard new, Maintained new) - As per my knowledge , Su25 2c step is the only option to check affected roles.

q3)What happens exactly when i run step 2a, step 2b in au25, does SAP automatically run load the default values in to the customer tables when upgrade is done? - Step 2A , 2B just compares the two versions. If there are any new values introduced , SAP automatically loads the new customer tables

Thanks,

Sneha

0 Kudos

Hi Sneha,

Thanks for quick reply. When we run step 2C in su 25, we get a report which ahve been affected by upgrade, but from these list of roles, how can we find the roles specifically which have been added with new auth objects from ECC6.0. IS there a way?

Regards,

Sandhya

0 Kudos

To find out the new authorization object , you have to check manually each and every authorization object in role . The authorization object with *Standard New , Standard Updated , Maintained New , Manually new , changed new * shows the affected authorization object. In our project we have done manually , according to my knowledge there is no other option. Let me know if you find anything else

Regards,

Sneha