02-11-2010 4:08 PM
Hello Everyone,
We are on ECC6.0 and I've come across a scenario where I've created certain number of derived roles from a parent role and generated the parent and derived one's from the parent role in PFCG and created a transport request. But,
When I got them imported (SCC1) to a different client on the same box I can see that the authorization tab is still in yellow in all these derived roles,they do contain the same profile name in the authorization tab in PFCG as from the original client they were created in and I would like to know the reason why these roles under the auth.tab are in YELLOW and need a regeneration of profile? I remember doing it previously where I did not regenerate the profiles for the roles when they are imported/transported to a different client.
And the status text in SUPC says " no current profile".
Any ideas/inputs are much appreciated.
Regards,
Raj
02-11-2010 4:41 PM
Hello,
Could you please confirm this is happening only for Derived roles or for parent roles too
Thanks,
Prasant K Paichha
02-11-2010 4:42 PM
Hi,
There may be more that one cases.
What are the roles you included into the Transport request? You should include all the Derive roles along with the parent roles ideally. Also, I hope you have checked the authorization data for the derived roles in the development before transport.
Other option could be the system change options for appending data in the target system.
Please provide more information and also try to search for SAP Notes if there any with this kind of issues.
Regards,
Dipanjan
02-11-2010 5:00 PM
Hi Dipanjan,
Yes,
I've included the derived and parent roles in the Transport.
I've checked the auth,data for the dervied roles before the transport.
@prashanth,
this happens only in the derived roles.
Thanks,
Raj
02-11-2010 7:49 PM
Hi Raj,
Can you post the entries which you have in table PRGN_CUST, if any?
Cheers,
Julius
02-12-2010 3:10 PM
Hi Julius,
Thanks for the reply but unfortunately I cannot find any entries for the PRGN_CUST table.
As a work around, we had to manually AGAIN regenerate the derived roles from the Parent (generate dervied) in the client these roles were imported to.
But it still remains a question why did this happen? Any other ideas?
Thansk All,
Raj
02-12-2010 4:16 PM
Take a look in PFCG at the name of the main profile for one of the derived roles.
In the target system / client, take a look in AGR_PROFS wether it already exists but is generated for a different role (AGR_NAME).
?
Cheers,
Julius
02-12-2010 4:27 PM
02-12-2010 5:51 PM
Hmmm...
Is there anything in the logs of STMS, ST22 or SM21?
If you can open the authorizations tab in display mode, what is the status of the authorizations? (new, old, etc) Any difference to the source system which might give us a clue?
Otherwise I have to pass.
Cheers,
Julius
02-12-2010 7:01 AM
I've encountered a similar issue, with the symptoms you describe, but I do not transport generated profiles across systems (PROFILE_TRANSPORT = NO).
Sometimes profiles wouldn't get regenerated based on the new authorizations data and "Authorizations" tab in user master would remain yellow. Regenerating roles with SUPC wouldn't work as the program would not id the role as needing its profile regenerated.
The only solution I found was to manually delete the current profile and generate a new one. My release is 701, sp3.