ChaRM - Role associations in target clients

Hi Guys
I have tried to assign the roles in target clients, but they don't exist.
This is the roles:
SAP_CHANGEMAN_DEVELOPER
SAP_CHANGEMAN_OPERATOR
SAP_CHANGEMAN_ADMIN
They are not in customer name space. What I can do?
There is a SAP note or I create them manually?

Hi,
depending on the release of your satellite system you should have the following roles/profiles:
Roles for the Change Management in satellite systems:
1)
Release >= 6.10
Role: SAP_CHANGEMAN_DEVELOPER
Release < 6.10
Profile: S_TMW_DEVELO
Authorizations for developers;
This profile contains CTS authorizations for developers: No authorization to create transport
requests, and no authorization to release transport requests but to create and release tasks
2)
Release >= 6.10
SAP_CHANGEMAN_OPERATOR
Release < 6.10
Profile: S_TMW_OPERA
Authorizations for operators;
This profile contains CTS authorizations for operators: All transport authorizations;
no configuration authorizations
3)
Release >= 6.10
SAP_CHANGEMAN_ADMIN
Release < 6.10
Profile: S_TMW_ADMIN
Authorizations for administrators;
This profile contains CTS authorizations for administrators:
All authorizations in the CTS (including configuration)
Taken from the Security Guide SAP Solution Manager 7.0 as of SP16.
What is your satellite system component and version?
I just checked in ECC 6.0, those roles are there.
Regards

Similar Messages

  • ChaRM:cCTS Configuration Import Targets Issue.

    Hi ChaRM Experts,
    Did any one configured cCTS for ChaRM in Solution Manager SP10 ?.
    I have configured cCTS in our solution manager and created clusters for DEV, QAS and PRD and assigned satellite systems then distributed plugins every thing is fine till here.
    Then defined transport routes between the clusters => CDV (consolidation)-> CQS (Delivery)-> CPD.
    Then i am trying to insert source client and target client for CQS in Import Targets Tab, Followed below steps.
    1) Call transaction STMS and choose Overview  -> Transport Routes from the menu
    2) Switch to edit mode
    3) Double click on a target cluster , e.g the quality CQS
    4) In the dialog box, select tab Import Targets
    5) Choose Insert Row -> Insert Row is invisible i am unable to specify source and targets clients
    Could some one please help how to make visible Insert Row icon ?.
    Regards
    gsr

    Hello,
    I can see in your screenshot that no cluster is assigned to the system for which you are trying to assign the import target.
    You should verify that the cluster is validated and then try again to assign the import target.
    I managed to assign them in SP10 without problems.
    Regards
    Renato

  • Does client copy erase all the data in the target client or?

    hi
    experts
    does clientcopy erase all the data in the target client or except user master records.
    regards
    rajendra.

    It depends upon the profile you use for the client copy.
    if you use SAP_ALL
    All data is deleted from target client and source client data is copied.
    and therefore you shall see the profiles and understand them .
    SAP_ALL    All Client-Specific Data w/o Change Documents    
    SAP_APPL   Customizing and Application Data w/o Change Docs 
    SAP_APPX   SAP_APPL w/o Authorization Profiles and Roles    
    SAP_CUST   Customizing                                      
    SAP_CUSV   Customizing and User Variants                    
    SAP_CUSX   Customizing w/o Authorization Profiles and Roles 
    SAP_PROF   Only Authorization Profiles and Roles            
    SAP_UCSV   Customizing, User Master Records and User Variants
    SAP_UCUS   Customizing and User Master Records              
    SAP_UONL   User Without Authorization Profiles and Roles    
    SAP_USER   User Master Records and Authorization Profiles   
    Hope it helps.
    Thanks
    Amit

  • Target client is productive and protected against client copy

    when copy 000 with tran code sccl its give error
    Message no. TA133
    Target client is productive and protected against client copy

    Hi Rahul,
    I mean:
    Execute SCC4.
    Push the "Edit" icon at the top (pencil).
    Double-click the target client.
    At the new screen, change the Client Role (you can select "Test").
    Change the combo "Protection Level" to Level 0.
    Save changes.
    After the Client Copy, you can revert all these changes to the original status.
    Regards,
    JC Llanes.

  • IMG - Target client is productive and protected against client copy

    I am doing post-installation for Solution Manager 4.0 and encounter the above error.
    From the IMG Solution Manager Basic Settings ... --> Create Client, I created client 020 and the role = customizing.  Protection Level 0 and allow change to  repository and cross-client customizing.  Then, I click on Copy Client, it gave me the above error.
    I could not find any information regarding the correct way to work around it.  I tried to log into client 020 with SAP*/PASS to do manual client copy, but could not login either.
    Anyone ran into this problem?  Please share your successful instructions.
    Thanks.

    Hi Teengh,
    you can only do the client-copy in the target client; in your case in client 020.
    Please have a look in TA scc4 whether the client 020 was really created. If it is existing, then you should be able to log on to the client 020 with sap*/pass (password in lower case). What was the error message after you could not login?
    Best regards,
    Kai

  • CHARM Roles in Satellite System

    Hi,
    Can anybody tell me  exactly on CHARM roles in Solman 7.0 EHP1.
    I am totally confused which roles i have to assign to Change Manager, IT operator, Tester, Developer & Requester.
    In Solman which roles I have to assign & in Satellite system R/3 which roles to assign.
    Currently I have assigned following Roles in Solman.
    Change Manager     
    ZO_BC_SOCM_CHANGE_MANAGER
    ZO_BC_CHANGEMAN_ADMIN
    ZO_BC_CHANGEMAN_OPERATOR
    ZO_BC_SOCM_CREATE
    ZO_BC_SOCM_DISPLAY
    ZO_BC_SOCM_PRODUCTION_MANAGER
    ZO_BC_TRUSTED-RFC
    IT Operator /Basis     
    ZO_BC_SOCM_IT_OPERATOR
    ZO_BC_TRANSPORT
    ZO_BC_SOCM_ADMIN
    ZO_BC_CM_SMAN_ADMINISTRATOR
    ZO_BC_TRUSTED-RFC
    Developer     
    ZO_BC_SOCM_DEVELOPER
    ZO_BC_CM_SMAN_DEVELOPER
    ZO_BC_TRUSTED-RFC
    Tester     
    ZO_BC_SOCM_TESTER
    ZO_BC_TRUSTED-RFC
    Can anybody tell whether above assignment is correct.
    In Satellite system which roles I need to assign.
    Regards
    PK
    Edited by: PK on Jun 1, 2010 9:58 AM
    Edited by: PK on Jun 1, 2010 9:59 AM

    Roles required for developer, tester and chagne manager in Solution manager in solution manager are as follow.
    Developer
    SAP_CM_DEVELOPER_COMP(composite role)
         SAP_CM_SMAN_DEVELOPER
         SAP_SOCM_DEVELOPER
    SAP_SOCM_REQUESTER
    tester
    SAP_S_RFCACL (for RFC)
    SAP_CM_TESTER_COMP(composite role)
         SAP_CM_SMAN_TESTER
         SAP_SOCM_TESTER
    change manager
    SAP_CM_ADMINISTRATOR_COMP (composite role)
         SAP_CM_SMAN_ADMINISTRATOR
         SAP_CPR_PROJECT_ADMINISTRATOR
         SAP_CPR_USER
         SAP_SOCM_ADMIN
    SAP_CM_CHANGE_MANAGER_COMP (composite role)
         SAP_CM_SMAN_CHANGE_MANAGER
         SAP_SOCM_CHANGE_MANAGER
    But you have to assign some object authorization to these standard roles.
    mainly you have to provide authorization for these objects S_TCODE, B_USERSTAT, S_OC_ROLE, CRM_ORD_OP etc.
    You can assign sap_all, sap_new to your user(developer, tester, change manager etc) and can set a trace from st01 on that perticaular user and then try to execute anything which you want. Then you can check for the objects in the trace and can authorize user for those object.
    Regards,

  • Error or termination in target client

    Hi All,
    We are able to move Transport Request from Development BW Client  to Quality BW Client smoothly.
    But when we move the same TR to Production client, we are getting the following error log. I would be very grateful if somebody could throw light on why it is happening, what could be its implications and what to do to avoid the same
    ===========================================================================================
    ETP162 EXECUTION OF REPORTS AFTER PUT
    1 ETP101 transport order     : "BWDK900063"
    1 ETP102 system              : "BWP"
    1 ETP108 tp path             : "tp"
    1 ETP109 version and release : "372.04.88" "701"
    1 ETP198
    2 EPU126XPost-import methods for change/transport request: "BWDK900063"
    4 EPU111    on the application server: "BWPRD2"
    2 EPU122XPost-import method "FINB_TR_AFTER_IMP_METHOD" started for "UCM001" "T", date and time: "20110113171454"
    2 EPU186 Post-processing taking place in client &2"800"&1"FINB_TR_AFTER_IMP_METHOD"
    A2 EFINB_TR 033 Import carried out using RFC destination "FINBTR@BWPCLNT800"
    A2AEFINB_TR 077 Error or termination in target client: "胇嗣嘎堵泵^颐趁?"800""FINBTR@BWP"
    A2AEFINB_TR 078 Target client: "800" user: "FINBTR@BWP" RFC dest.: "FINBTR@BWPCLNT800"
    A2EEFINB_TR 091 Last transport object: "UGMD001" (component "FINBASIS")"FIN 涓绘瞻鎊彤: 搴早渊绋隋篰翔蘜缅鄞""CL_UG_MD_
    TR_METHOD_IMPORT"
    2EEPU133 Errors occurred during post-handling "FINB_TR_AFTER_IMP_METHOD" for "UCM001" "T"
    3 EPU135 "FINB_TR_AFTER_IMP_METHOD" belongs to package "FINB_TRANSPORT_TOOL"
    2EEPU136 The errors affect the following components:
    2EEPU137    "FIN-FB" ("Financials Basis")
    3 EPU123 Post-import method "FINB_TR_AFTER_IMP_METHOD" completed for "UCM001" "T", date and time: "20110113171509"
    2 EPU127 Post-import methods of change/transport request "BWDK900063" completed
    2 EPU128      Start of subsequent processing ... "20110113171454"
    2 EPU129      End of subsequent processing... "20110113171509"
    2 EPU110XExecute reports for change/transport request: "BWDK900063"
    4 EPU111    on the application server: "BWPRD2"

    HI,
    pretty sure that this should be part of either the BW forum or the Basis forum.
    Ingo

  • TCURM in target client empty after Client Copy

    Hi Experts,
    Has anyone encountered situation whereby TCURM does not contain a record for the target client after Client Copy process is completed? Is this a feature or bug?
    Regards

    Hi ,  I  user the exclude tables option to exclude some tables.
    but I have another problem:  the client copy still failed.  I get these  informations:
    table/object   component                         error
    ANLU           FI-AA-AA                   Field missing locally
    C905            SD-MD-CM                Different Field Names
    IMPTT          PM-EQM-SF-MPC      Field missing locally
    how can i finish my client copy ?   can you give me the solution
    thanks very much

  • Setting Target Client in STMS- Import Queue

    After restoring Db,we has some issues in Transport Routes so deleted and added the child system to Transport Domain Controller.
    After adding the system, if we go to STMS->Import Overview-> QAS ( system queue name )-> here it asking to set the target client.
    My issue is..when i click on " Set Target Client", it is ready to import all the transports...
    Can i exclude importing all the transports and set the target client ?
    Thank you

    Hi NIA,
    As mentioned by Sunny, you just have to add the NEW QAS system in the Domain.
    Go to transport routes and then from "Configuration"-> "Adjust with Controller".
    This will adjust the system with the Domain Controller.
    Regards,
    Anuj

  • Target client is Productive and Protected againt client copy

    Dear Team,
    I have fresh install SAP R/3 4.7 with SQL .After installation  I make new Client 110.
    I login in 110 with sap* and password  pass.
    then via sccl i just for Client copy.this  messege is comming that is   "Target client is Productive and Protected againt client copy ".
    Where is the problm. Plz help .
    Thanks & Regards
    jagdish Kumar

    Maybe you have in production system in SCC4 the option
    Protection: Client copier and comparision tool - Level 0 activated
    Markus

  • VOFM - Formulas Problem : Can't transfer in to target Client.

    I just created a formulas in Tcode VOFM, and inserted some code , and actived it. ,
    GRPZE GRPNO AKTIV KAPPL
    ADAT 905 X
    But I can't transfer it into target client.
    The transfer log is ok .
    But the target client still don't have formula 905 .
    Is there any special step for the transfer of formulas ?
    Many many thanks .
    The following is my Request ! Is there any problem ?
    DR1K903890 ZZFZWANG
    DR1K903891 ZZFZWANG
    Program
    RV45C905
    DR1K903892 ZZFZWANG
    Table contents
    TFRM
    TFRMT

    Hi Eswar ;
      Done.  I have found the formula in the target client.
      I think the problem is simple .
      The request was released and posted 3 days ago from dev system ,and It just appeared in the target client. But I found the transfer log is ok in DEV system.
      Thanks you very very much, Eswar .
    Best Regards
    Fred

  • Strange behavior after granting a role associated to an access policy.

    Greetings.
    I am using OIM 11.1.1.3 and I am using also the DBUM Adapter 9.1.0.4.
    I Defined 3 roles in OIM after that I defined three access policies with the purpose of provision roles at a database.
    Every policy is associated to a role and a DBUM resource.
    At the end I have the following policies.
    Policy Name OIM Role Database Role
    1. Policy Role A - Role A - DBRoleA
    2. Policy Role B - Role B - DBRoleB
    3. Policy Role B - Role C - DBRoleC.
    When a role is granted to OIM User using the Administration Console the correct database role is provisioned at the specified database. But If I revoke a Role from the user and grant the same role again the specified role is not provisioned to the specified database.
    Example: An user have "Role A", "Role B" ,"Role C" at the database the user have DBRoleA, DBRoleB, DBRoleC.
    After revoking "Role A" from the user the database have the correct roles DBRoleB and DBRoleC.
    But if the "Role A" is granted again to the user the DBRoleA is not provisioned at the database.
    I enabled the dbum log file and it looks like the wrong role was chosen and the DBRoleB is the database role to be provisioned. Because we see at the log file when the "Role A" is granted to the user:
    [WLS_OIM1] [TRACE] [] [OIMCP.DBUM] [tid: [ACTIVE].ExecuteThread: '2' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: oiminternal] [ecid: 0000JDjSF5i9h^5prOt1iY1EgfQX0000lD,0] [SRC_CLASS: com.thortech.util.logging.Logger] [APP: oim#11.1.1.3.0] [dcid: 4506c477d760fc7e:26c2d53a:1336a1dbc64:-7ffd-0000000000000d45] [SRC_METHOD: debug] oracle.iam.connectors.dbum.integration.DBUMProvisionManager : getChildFormData : Form Value2011-11-04[2011-11-04T11:37:14.392-05:00] [WLS_OIM1] [TRACE] [] [OIMCP.DBUM] [tid: [ACTIVE].ExecuteThread: '2' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: oiminternal] [ecid: 0000JDjSF5i9h^5prOt1iY1EgfQX0000lD,0] [SRC_CLASS: com.thortech.util.logging.Logger] [APP: oim#11.1.1.3.0] [dcid: 4506c477d760fc7e:26c2d53a:1336a1dbc64:-7ffd-0000000000000d45] [SRC_METHOD: debug] oracle.iam.connectors.dbum.integration.DBUMProvisionManager : getChildFormData : Child form data map received:- {UD_DB_ORA_R_VERSION=0, UD_DB_ORA_R_KEY=3180, UD_DB_ORA_R_UPDATE=2011-11-04, UD_DB_ORA_R_CREATE=2011-11-04, Process Instance.Key=5916, UD_DB_ORA_R_UPDATEBY=6, UD_DB_ORA_R_ROLE=102~*DBRoleB*, Access Policies.Key=183, UD_DB_ORA_R_CREATEBY=6}
    The question is somebody has experienced the same issue?
    Is there another way to provisioning database roles after granting OIM Roles?
    Thanks!
    Ramiro Ortíz

    Finally we opened a Service Request to solve this issue, and it was a bug "OIM SENDING WRONG ENTITLEMENT NAME TO TARGET DURING ADD ENTITLEMENT OPERATION" and Oracle generated the patch 13499465 for DBUM Connector. Oracle had to provide us a new Readme to apply this patch because it wasn't well explained. So far the patch seems to work, we are making some tests now to be sure that the issue is solved. I just want to share that with the OIM community.
    Ramiro Ortiz

  • ABAP prog with Call Transaction  to SU01 will not add roles in a CUA client

    I am modifying a current ABAP program that works in a non-CUA client to hopefully execute in a CUA client.  This program performs a Call Transaction to tcode SU01 and adds roles to an existing user.  I used tcode SHDB to identify the new BDC commands needed for CUA when using tcode SU01.  When executing the program in the CUA client  it does not save the roles to the user.  There is no error message or abnormal termination.
    When I assign the role to the same user that's referenced in my program directly with tcode SU01 it works fine.  Its just when I run the ABAP program the role assigment is not retained.  I opened a Customer Message with SAP and they referenced OSS Note 93802 and said this was a consulting question.  My program is not abending as referenced in Note 93802, it just does not add the role.
    Has anyone been able to get this to work in a CUA client?

    Hi,
    it should be fairly simple to create a new ABAP using the BAPI's related to business object USER. Call BAPI_USER_CREATE1 to create the users, and BAPI_USER_LOCACTGROUPS_ASSIGN to assign roles in a CUA environment. It should go something like this:
    [read file with user data into internal table wt_users]
    [read file with role assignments into internal table wt_roles]
    Loop at wt_users into wa_user.
      [create LOGINDATA, ADDRESS and other structures for user in BAPI below, based on the data in wa_user]
      call 'BAPI_USER_CREATE1'
      exporting
        username                      = [the user name from input file]
      NAME_IN                       =
        logondata                     = [structure for logondata]
        password                      = [initial password value]
      DEFAULTS                      =
        address                       = [address structure created above]
        [etc.]
      if sy-subrc eq 0.
    Assign roles for the user
    clear wt_activitygroups. refresh wt_activitygroups.
    loop at wt_roles into wa_roles where username = wa_user-username.
        [build an internal table, wt_activitygroups, for system/role assignments for the user]
    endloop.
        call BAPI_USER_LOCACTGROUPS_ASSIGN
          exporting
            username                      = [the users name]
          tables
            activitygroups           = wt_activitygroups
            return                       = wt_return.
    Endloop.
    Ideally, you would have two input files: one with the user data (one record per user), and another one containing the data for the BAPI_USER_LOCACTGROUPS_ASSIGN (on the format USERNAME, SYSTEM, ROLENAME); one entry per line. You'd loop at the first table, containing the user data, then create the user, then loop at all entries in the system/role assignment file for the same username, building an internal table of role assignemnts; then call the second BAPI (provided there were any role assignments to assign for that user!)
    Hope this makes sense. It's not rocket science really; you can omit most of the parameters of BAPI_USER_CREATE1, and the second BAPI is even simpler. You could consider validating the input data by checking entries in table USRSYSACT, which contains all valid system/role assignments as seen from the CUA system (this table gets updated every time you do a "text compare" from within SU01.
    Regards,
    Trond

  • CHARM - avoid developer login to client 000 when import to QA system

    Hi Gurus.
    I've activated a new system to use CHARM for import. When testing the import to QA, the logon screen to QA 000 is displayed. 
    I already applied SAP Note 913232 which suggests that the TMSADM user (with profile S_TMW_OPERA) in QA 000 can be used as default user for import so that developer don't need to exist in QA 000, but it still didn't fix the issue.
    Are there other configurations that I need to do to fix this issue.
    We are currently using SOLMAN 7.0 SP25.
    Thanks,
    Tess

    Hi Tess,
    Check the  TMW and trusted RFC mapped to correct client of satellite system.
    SM_(system)CLNT(client)_TRUSTED
    SM_(system)CLNT(client)_TMW
    Rg,
    Karthik

  • ChaRM: Role Developer needs to test in QAS system

    Hi!
    We are about to implement and use Solman ChaRM approach.
    One interesting point is:
    the developer should have the possibility within the urgent correction to test the transport in QAS system.
    If everything is ok, then the transport should go to QAS system.
    Can some one tell how to cutomize this process?
    Thank you very much indeed!
    H. Thomasson

    hi christian,
    i am currently customizing charm security, i am trying to use sap_socm_admin role and copying it to customer namespace like
    zsap_socm_developer, zsap_socm_manager etc, and trying to enforce restrictions by adding or removing auth keys under the auth object b_userstat . My problem is when i do that these roles are missing other authorizations to perform small functions like displaying logs and things like that.
    so i wanted to know if there is any role ( single of composite ) that i can use to copy for all my users and i can simply restrict the clicking on actions ( authorize CR, set in development  ..etc) by removing or adding just the auth key, i mean only the auth key...i dont care if they have auth to projects or task list or what ever i just want to restrict by the actions they can perform.
    rgds

Maybe you are looking for