on 08-02-2012 9:03 PM
Hello,
we have the problem, that the Firefighter User do not only see the Firefighter ID's he is Firefighter. He see all assigned Firefighters to all Firefighter ID's in the NWBC Rule Setup => Superuser Maintance => Firefighters
We have choosen the following Authorisations Objects.
have you any idear how I can disable this?
Hi Kristin.
There was an OSS note release a few days ago.
1730649 - Firefighter owner can assign ANY Firefighter ID to Firefighter User
Also see
1663949 for detailed information on EAM Authorization objects.
This contains a PDF for the EAM Authoirisation Guide.
The Key is the GRAC_FFOWN authoirisation which needs to be limited to the logged on user.
If you need help please contact enquiries@integrc.com
Terry
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Kevin,
In SP08 we have made changes related to authorization. Please refer to
Note:1658244 for the details regarding the changes done.
There is one Auth Object GRAC_FFOWN that is being used for Firefighter
Owner. For a firefighter to view the FFIDs in the logonpad, display
authorization is required in this object apart from GRAC_USER &
GRAC_RCODE( that is already there). The object GRAC_OWNER object is
used for all AC owners.
Kindly check that you have assigned all the auth objects as per this note and the security guide.
Best Regards,
Nandita
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Kristin:
My first question would be why are your Firefighters logged into the NWBC portion of the GRC AC10 system.
Firefight is executed from the normal ABAP/GUI side.
Thanks.
Kevin Tucholke
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Kristin:
Kristin:
The firefight user will see the IDs he can access by executing the GRAC_EAM transaction, and only those he has been approved for.
The reason codes can be seen by executeing the logon session and then using the dropdown list (specific for the system of course).
I don't think that there is a permission to limit on User ID assinged to Firefight except for FF Controller and FF Owner.
Maybe someone else has other info, but have not seen that before.
Thanks.
Kevin
Hi Kristin ,
As mentioned by Kevin the Firefighters can see the reason codes and FFid assigned to them directly via the tcode GRAC_SPM or GRAC_EAM , via this tcode the firefighter can see FFids assigned only to his user .
The firefighters I believe should not have access to the Setup tab in NWBC. You can remove this access by changing the menu option in the role assigned to Firefighter.
thanks
Ranjiv
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.