Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Generation of derived roles when transported

Former Member
0 Kudos

Hello Everyone,

We are on ECC6.0 and I've come across a scenario where I've created certain number of derived roles from a parent role and generated the parent and derived one's from the parent role in PFCG and created a transport request. But,

When I got them imported (SCC1) to a different client on the same box I can see that the authorization tab is still in yellow in all these derived roles,they do contain the same profile name in the authorization tab in PFCG as from the original client they were created in and I would like to know the reason why these roles under the auth.tab are in YELLOW and need a regeneration of profile? I remember doing it previously where I did not regenerate the profiles for the roles when they are imported/transported to a different client.

And the status text in SUPC says " no current profile".

Any ideas/inputs are much appreciated.

Regards,

Raj

9 REPLIES 9

Former Member
0 Kudos

Hello,

Could you please confirm this is happening only for Derived roles or for parent roles too

Thanks,

Prasant K Paichha

sdipanjan
Active Contributor
0 Kudos

Hi,

There may be more that one cases.

What are the roles you included into the Transport request? You should include all the Derive roles along with the parent roles ideally. Also, I hope you have checked the authorization data for the derived roles in the development before transport.

Other option could be the system change options for appending data in the target system.

Please provide more information and also try to search for SAP Notes if there any with this kind of issues.

Regards,

Dipanjan

Former Member
0 Kudos

Hi Dipanjan,

Yes,

I've included the derived and parent roles in the Transport.

I've checked the auth,data for the dervied roles before the transport.

@prashanth,

this happens only in the derived roles.

Thanks,

Raj

Former Member
0 Kudos

Hi Raj,

Can you post the entries which you have in table PRGN_CUST, if any?

Cheers,

Julius

Former Member
0 Kudos

Hi Julius,

Thanks for the reply but unfortunately I cannot find any entries for the PRGN_CUST table.

As a work around, we had to manually AGAIN regenerate the derived roles from the Parent (generate dervied) in the client these roles were imported to.

But it still remains a question why did this happen? Any other ideas?

Thansk All,

Raj

Former Member
0 Kudos

Take a look in PFCG at the name of the main profile for one of the derived roles.

In the target system / client, take a look in AGR_PROFS wether it already exists but is generated for a different role (AGR_NAME).

?

Cheers,

Julius

Former Member
0 Kudos

I've checked this too Julius. No luck

Former Member
0 Kudos

Hmmm...

Is there anything in the logs of STMS, ST22 or SM21?

If you can open the authorizations tab in display mode, what is the status of the authorizations? (new, old, etc) Any difference to the source system which might give us a clue?

Otherwise I have to pass.

Cheers,

Julius

Private_Member_119218
Active Participant
0 Kudos

I've encountered a similar issue, with the symptoms you describe, but I do not transport generated profiles across systems (PROFILE_TRANSPORT = NO).

Sometimes profiles wouldn't get regenerated based on the new authorizations data and "Authorizations" tab in user master would remain yellow. Regenerating roles with SUPC wouldn't work as the program would not id the role as needing its profile regenerated.

The only solution I found was to manually delete the current profile and generate a new one. My release is 701, sp3.