Hi Anand, thank you so much for the info. How can I create a particular application server?
Re: Remove Auto Log Off for a specific user
Re: Remove Auto Log Off for a specific user
You dont need to create any application server here. Application server must be there already.
If you are having only CI there then solution/workaround mentioned by me is not applicable.
Kind Regards
Anand
Re: Remove Auto Log Off for a specific user
I checked in SM51 and we only have 1 application server. Does this mean there's no way for us to test the work around that you mentioned?
THank you so much
Re: Remove Auto Log Off for a specific user
As effect of this parameter is instance wide I think we cant implement it in a only 1 application server scenario.
Anand
Re: Remove Auto Log Off for a specific user
You cannot use security policies to control dispatcher processes for session management.
They only control the assignment of password management rules to users (over and above the user type).
Cheers,
Julius
Re: Remove Auto Log Off for a specific user
What is the user type of this 1 user?
Missing Organization Levels in PFCG !!
Hello ,
background : we already had Ecc for a while and now got BI 7.3 .
trying to create BI roles , checking PFCG i dont find ANY fields in Organization Levels. How do i get from Ecc or define my organization strucutre here in BW ?
You help is much appreciated.
Regards
Raja
Problems in NW 7.02 in STRUST Importing Verisign Cert Response
I generated a new Client certificate and sent it to Verisign via our enterprise group and I have received a Verisign certificate. When I attempt to "Import Certificate Response", I get the following error (Long text):
Issuer certificate missing in database:CN=Symantec Class 3 Secure Server CA - G4, OU=Syma
Message no. TRUST057
Diagnosis
The following issuer certificate is missing from the database or is marked as inactive: CN=Symantec Class 3 Secure Server CA - G4, OU=Syma
Procedure
Store the issuer certificate in the database (menu function Certificate -> Export -> Database) and make sure that the certificate is not marked as inactive (menu function Certificate -> Database).
How can I import the intermediate/primary certificates to resolve this problem?
Re: Documentation Link in AIS does not work - who wants/can help?
Hello,
No I was unable to solve this case.
Anyway nice reading from you.
all the best Erwin
Re: Problems in NW 7.02 in STRUST Importing Verisign Cert Response
With sapgenpse you can do it by specifying all the certificates with -r. I haven't used STRUST to do the same but I think you should be able to import the intermediate and root certificate into the PSE before trying to import the certificate response.
Re: Documentation Link in AIS does not work - who wants/can help?
I guess that is just an inherent problem with hardcoding / hard-configuring links -> you need to maintain them if your expectation that SAP will maintain them fails.
Try a new 7.40 (Ehp 7) system to see what the links are. The SUIM based reports have also changed somewhat, so there are also new variant transactions (old AIS roles wont work - but it is easy to find the new ones which pass the new parameters).
Cheers,
Julius
Re: Problems in NW 7.02 in STRUST Importing Verisign Cert Response
Thank you for the response. I'm open to trying it.
Could you give me more details about what command/subcommand to use with sapgenpse?
Re: Problems in NW 7.02 in STRUST Importing Verisign Cert Response
The UI is also a bit tricky between the left context pain, the top right work area and the bottom right "clipboard" area for imports / exports.
This has tricked me several times before, although I could see the data in the bottom right pain. You still have to save it after uploading it.
Cheers,
Julius
Re: Problems in NW 7.02 in STRUST Importing Verisign Cert Response
To import the certificate response you use the command import_own_cert, see the documentation for details. Specify -c signedcert -r intermediate -r root.
Re: Documentation Link in AIS does not work - who wants/can help?
Hello,
Thank you very much.
I am 100% sure you are right.
all the best Erwin
Re: Documentation Link in AIS does not work - who wants/can help?
Little tip: Find the report in the old parameter transaction. Us eth Se38 where-used-list to search for the new transaction. Start it and in the selection screen us the help -> application help to get the URL.
Takes about 15 mins to relace them :-)
Also see SAP notes 1897781 and 1930238 which changed the screens and parameter transactions and APIs. This means that the application helps changed and you should change the transaction codes as well as the screens won't work anymore.
Cheers,
Julius
Re: SU24 - Changing SU24 after many years.
Hi,
SU24 is client - independent. Once you do changes in SU24 it will not affect the roles unless and until you use expert mode generation in PFCG transaction.SU24 is being used to display the authorization checks(whether authorization check is there or not) for the Transaction Codes. So roles will remain unaffected.
>Moderator: This reply is partly incorrect. Regarding the merge scenario in PFCG.>
Re: Roles in child system
Hi Colleen,
Thanks a lot. Just tried. It works Sorry, I misinterpreted the initial solution.
Regards,
Subha
Re: Problems in NW 7.02 in STRUST Importing Verisign Cert Response
bash-3.2$ export SECUDIR=/usr/sap/<SID>/<Instance>/sec
bash-3.2$ sapgenpse import_own_cert -p <PSENAME> -c /tmp/cert.crt -r /tmp/inter.crt -r /tmp/root.crt
import_own_cert: Installation of certificate failed
ERROR in ssf_install_CA_response: (1280/0x0500) Incomplete FCPath, need certificate of CA : "CN=Symantec Class 3 Secure Server CA - G4, OU=Symantec Trust Network, O=Symantec Corporation, C=US"
ERROR in ssf_install_certs_into_pse: (1280/0x0500) Incomplete FCPath, need certificate of CA : "CN=Symantec Class 3 Secure Server CA - G4, OU=Symantec Trust Network, O=Symantec Corporation, C=US"
Based on your advice, I think I tried it correctly.
Here is where I downloaded Verisign's Root and Intermediate certs:
Re: Getting dump after implementing the Note 1640523
Hi,
Were you able to resolve the issue?
Im getting the same problem after implementing that note
Regards,