cancel
Showing results for 
Search instead for 
Did you mean: 

Systems Don't appears in Password Self Service GRC 10

Amparo_Gómez
Explorer
0 Kudos

Hi Experts!

I need their divine help:

I'm seting the Password Self Service in GRC. My System Satellital is a CUA, here I'm configuring the service, I executed all the steps defined in this guide:

But when I test the service GRAC_UIBB_END_USERLOGIN, I can loggin me, I can define a question and an answer secret, but I Can't select a system for the reset, because in the windows not shown any system. When I seach a systems, appear the error message:

"No records found for the search criteria selected"

I put this value in the field of system: *GRD* because I configured the systema GRD100 for test the service.

What do I need activate for fix this issue?

Thanks!!!!

Accepted Solutions (1)

Accepted Solutions (1)

alessandr0
Active Contributor
0 Kudos

HI Amparo,

it seems that the connector has not been activated for PSS. Goto SPRO >IMG > GRC > AC > Maintain Connector Settings and activate the PSS flag for the connector you would like to see in PSS.

Let us know if it works.

Best regards,

Alessandro

Amparo_Gómez
Explorer
0 Kudos

Hi Alessandro,

Thanks for response, I reviewed the Flag and is activated in my system:

I don't know what other thing could be.

Colleen
Advisor
Advisor
0 Kudos

on a very strange off chance, ensure that your SCUM setting in CUA has the password field as everywhere (I haven't configure PSS for CUA so not sure if the function module goes to the CUA system or straight to the satellite)

The other one - does the user actually have an account for that satellite system? They will only appear on the system list if they have access

Finally, have you checked and tested your connector to make sure it's all set up correctly (including logical system to rfc mapping)?

Amparo_Gómez
Explorer
0 Kudos

Hi Colleeen,

Thanks for your response! I reviewed in the SCUM and the password field is EveryWhere. The user test, exists in the satellite system, but I'm not sure that have the complete authorizations and I don't grant the SAP_ALL

For the test and check the connector, We created a communication user with the roles:

  • SAP_GRAC_ACCESS_REQUESTER
  • SAP_GRAC_END_USER

We set this user in the Logon Data tab for the service GRAC_UIBB_END_USERLOGIN in the SICF. But the user RFC configurated in SM59, for the conections between CUA and Children systems is other.  Could be this topic, the real problem?

Thanks!!!

Colleen
Advisor
Advisor
0 Kudos

Hi Amparo

I noticed from your screen shot you search for S* but your connectors are G*. Can you try searching * only?

I'm a bit confused by which RFC connections you mean?

Regards

Colleen

alessandr0
Active Contributor
0 Kudos

Hi Amparo,

additionally what Colleen has mentioned also make sure you have the appropriate authorization for the connectors. Therefore make sure authorization object GRAC_SYS is authorized properly.

Regards,

Alessandro

Amparo_Gómez
Explorer
0 Kudos

Thanks Alessandro!

I Reviewed the authorizations for the user and has the object GRAC_SYS.

Thank you!

We're reviewing the point specify by Colleen. I'll commented if the problem is solved

Amparo_Gómez
Explorer
0 Kudos

the RFC connections between the CUA and children systems. We have a user type System: RFCGRD, this user exists in all de children systems connected to the CUA.

The user RFCGRD have SAP_ALL. But this user isn't configured in the SICF, We used other called RFCPSS without SAP_ALL, only has the roles

SAP_GRAC_ACCESS_REQUESTER

SAP_GRAC_END_USER

We'll test put the user RFCGRD in the ten servicies for de PSS.

Amparo_Gómez
Explorer
0 Kudos

Hi Colleen,

I'm sorry, I paste an incorrect screen, I put G* and I test with "*" in the field, but the result it's the same "No records found for the search criteria entered"

Colleen
Advisor
Advisor
0 Kudos

HI Amparo

I would go through the following checks:

  1. Connector setup
    1. SM59 - test connection works
    2. Integration framework - connector is setup and mapped through for the scenarios (assume so or it wouldn't be in the list)
    3. Logical System - the RFC connection GRDCLNT100 is the same name in BD54 and SM59 so it matches
  2. Run Sync jobs and check logs (SLG1, SM21 and ST22) to make sure no errors
  3. Confirm the user for password does actually exist in the GRDCLNT100 system (shouldn't matter for the search system step but maybe check user type, validity date and lock status as well)
  4. Does your IMG have CUA configuration setup?
  5. Check the SICF services to make sure they have the system user and this user has the authorisations to perform the change
  6. Run a system trace as your attempt it again
    1. Check the logs - ST22, SLG1 and SM21 to see if any errors (might be RFC connection for the system use, etc)
    2. Analyse trace file if it doesn't

I haven't done PSS with CUA. However, with the requirement that SCUM setting be set to everyone - it makes me think the GRC system will call the API in the satellite/child system and not go via the CUA. This makes me wonder if the SICF user needs access in satellite/child. I assume that will depend on your RFC connection definition in GRC and use of trusted systems.

Regards

Colleen

former_member204479
Active Participant
0 Kudos

Hi Amparo,

Can you also ensure the following:

1. Full User sync has been performed successfully

2. In SPRO, which system do you have maintained in the User Authentication Data Source? Ensure the user you are logging with is available in this system. in PSS first level of authentication takes place from the Authentication Source.

Let us know.

Thanks

Sammukh

Answers (1)

Answers (1)

Amparo_Gómez
Explorer
0 Kudos

Hi Guys!!

Thanks for your responses, all the tips was valuables for us. We could fixed the problem executed the Sync jobs. The system configurated appears!!!