cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Cluster - Windows permissions

Former Member
0 Kudos

Hi all!

I have a SAP ECC 6.0 installation in MSCS with SQL.

The problem is that I can't access the profile files using the network resource (sapmnt). I received a Windows error that I dont have permissions. Because of this when I start SAP it doesn´t load the profile.

When I try to open it using the local disk I dont have any problem. All of this with the adm are on it.

Any clue?

Wadih

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

First, check the share permissions, but from the MSCS Cluster Admin MMC. Do not use manage my computer. This is the first level of permission the O/S validates when you try to access a file in a share.

Then check the folder level permissions, this is the second level of check the O/S does. Do this via explorer, check for inheritance and folder level permissions (including sub-folders), make sure they are set to expected settings.

Lastly, check the individual files, see if the file security are what you are looking for.

Other than that, you shouldn't have any issues accessing the files. If you continue to have issues, try accessing the files by referencing the physical server where all the resources are on, instead of using the SAP virtual name. If the virtual name is the one w/ the access problems, check the kerberos and DNS checkboxes in the network name resource and cycle the resource.

Former Member
0 Kudos

Hi Kevin,

I already checked all that you told me and the same error. The only thing I didn't found is that of kerberos and DNS.

Is kind of wierd because I acan access the files from al11 but I can't from Windows using sapmnt.

If I try to import the profiles files from rz10 I'm receiving this error:

Instance profile
SPRODUCCION\sapmnt\PRD\SYS\profile\PRD_DVEBMGS02_sproducci

Could not be read. The import is therefore not possible.

Start profile
SPRODUCCION\sapmnt\PRD\SYS\profile\START_DVEBMGS02_sproduc

Could not be read. The import is therefore not possible.

Instance profile
SPRODUCCION\sapmnt\PRD\SYS\profile\PRD_DVEBMGS02_sproducci

Could not be read by file; Therefore could not be checked.

(Server = sproduccion1_PRD_02 )

Thanks,

Wadih

Former Member
0 Kudos

AL11 works but RZ10 doesn't, now that really confuses me. Because both transaction are accessing the files using the credential running the SAPPRD_02 NT service.

have you tried logging into the server as the user running the NT service and try accessing the share?

Former Member
0 Kudos

Hi Kevin,

I found the kerberos and DNS but nothing happened. Same error.

Wadih

Former Member
0 Kudos

I know, is a very weird error.

With a user named clustermanager, the one I believe you are telling me, I can access without any problem the files, also from sapmnt

I'm out of ideas, I don't know what else I can do.

Wadih

Former Member
0 Kudos

Is that a local user or a domain user?

Former Member
0 Kudos

A domain admin user.

Othe thing I believe is kind of weird is that the prdadm user can open some files of the profile directory like old versions of instance profile. All the files that has any kind of extension it can be opened by prdadm. But is that file doesn't has an extension, is where the problem occurs. All from Windows and sapmnt resource, because if you acces the file from the shared disk, prdadm can open all kind of files.

Former Member
0 Kudos

Did you try logging into the server where SAP is running with the domain user, then try to open the files using explorer?

Former Member
0 Kudos

Yes and I can.

Like I told you befores, the clustermanager user is a domain admin user and I dont have any problem with that user.

I believe the problem is with the user prdadm and not with the files. But I don't know why prdadm can open some files of the same directory and other don't. I have checked teh security settings of the 2 files and are the same, the only difference I have detected is that one has extension and the other one don't.

Former Member
0 Kudos

Sorry, I meant logging in as prdadm. Let's forget about the cluster for now and just talk about SAP. When I say domain user, I mean the user running the SAP service.

Have you checked to see if there are open handles on the file? Try using notepad, does it work?

Former Member
0 Kudos

Accessing from the shared disk without any problem, from sapmnt I cant.

Also I did the following test. I created a file named test the one I couldn't open. Afte rthat I rename it with test.1 and I was able to open it with any problem.

Former Member
0 Kudos

wow ... sorry man, never seen this before. Why would renaming a file lock it from access, man ... that sounds buggy. Maybe try posting this on msdn.com?

http://forums.msdn.microsoft.com/en-us/Forums

Former Member
0 Kudos

Thanks I would do that.

If later you have any more idea please tell me and I'll test it.

Thanks for your help,

Wadih

Former Member
0 Kudos

One question Kevin:

When I do a check profile from rz10, where I can find the file with that information because from SAP GUI I cannot see the full information.

Thanks!

Wadih

Former Member
0 Kudos

RZ10 when you import the profiles it reads it from the profile directory. This is set by your SID and drive where the instance is configured to run.

It then takes the start profile to determine where the instance profile is.

When RZ10 does a check, it checks the instance, default, and start profiles.

Former Member
0 Kudos

We solved the problem. One windows component was causing all the problems, the name of the component is: Internet Explorer Enhanced Security Configuration

You have to uninstall it and after that everything worked right.

Former Member
0 Kudos

Wow ... never ever seen that before, I've always thought that only controlled IE and not explorer...

Answers (0)