09-16-2009 7:27 AM
I encounter a problem when transporting a role from Dev to Acceptance system.I added manually GRC auth-obj in the existing role in D system and transported to A system.When I check the role in PFCG in the A system ,Auth-obj is missing.But, when I try through SUIM ,The transported role is relfecting for the GRC auth,obj.But in pfcg it is missing.FYI,Transport is successful.
Thanks ,
Naveen
09-16-2009 7:59 AM
If you see the object in SUIM but not in PFCG it may wel be the object itself sn't transported properly and the corresponding object class is missing. PFCG needs the object class to group objects and will not display objects without a known object class.
09-16-2009 7:41 AM
You can do the followings currently as per my opinion:
1. Check the Object entries in AGR_1251 table rather than SUIM.
2. If the Objects are not present there, pleas check the value of auth/object_disabling_active (whether it is Y) and then in auth_switch_objects, whether all those Object set is disabled.
3. If none of the point 2 is encountered, then check the profile status of the role in A system.
4. check the table TOBJ for those Objects or in SU21.
5. Regenerate SAP_ALL (should be last option) and then look into the role for those objects.
Regards,
Dipanjan
09-16-2009 7:41 AM
HI Naveen,
Does your Acceptance System (A) has GRC installed, check whether the Authorization object exists in A system, in transaction code SU21.
SUIM might be searching from AGR_1251 table, however if the object is not present in the system profile generator is not available.
Cheers !!
Zaheer
09-16-2009 7:44 AM
> Total Questions: 12 (12 unresolved)
My first guess (nothing else is possible here again) is that you have a ranged manual S_TCODE authorization or wildcard somewhere in this role or another.
Cheers,
Julius
09-16-2009 8:09 AM
you are correct.We maintained S_Tcode manually for this role.All other objects are all also maintained manually.
Because of that auth.obj is not reflecting?
09-17-2009 4:06 PM
Have you done what Zaheer recommended? Does the auth object exist in the target system?
If it doesn't then the role will transport but there will be no entries for the auth object.
09-17-2009 4:13 PM
You should still pick it up in the transport log though. There is an after import event which does something and will give a return message if the object is obsolete.
Perhaps naveen is transporting GRC roles into a system where GRC is not installed?
Cheers,
Julius
09-17-2009 4:18 PM
That's possible.
The problem with the logging could be that the transport will go through OK and the transport status indicator in STMS will look OK. I hate to admit that I have been there, done it & have the badge on this one
09-18-2009 2:48 AM
Well that's what i asked naveen, but never replied about this...
@naveen : can you check whether you have the grc installed on the target system....
Cheers !!
Zaheer
09-18-2009 9:15 AM
I think it is reasonable to expect that basis monitoring should have picked this up and contacted Naveen by now.
Perhaps they don't talk to Naveen anymore since the issue...
09-18-2009 9:39 AM
Hi All,
Sorry for the delay!
we found out that object class missing in A system.That's is the reason it's not reflecting in PFCG.
Zaheer:GRC is present in the A system.
Thank you all for all your valuable suggestion.
MODERATOR:I came across the SAP ALL question in one of my interview. I'm not really going to edit the SAPALL or advise any to do so.
Regards,
Naveen
09-16-2009 7:59 AM
If you see the object in SUIM but not in PFCG it may wel be the object itself sn't transported properly and the corresponding object class is missing. PFCG needs the object class to group objects and will not display objects without a known object class.