Configure SLD service user roles

Hello to all,
we set up a system landscape directory.
Now I want to connect a new system to it.
The guide told me to set up to HTTP destinations.
SLD_DataSupplier with user SLD_DS_<SID>
SLD_Client with user SLD_CL_<SID>
Up to now we've used the user SLDDSUSER for both connections.
So now my question is, which roles need the two users?
I can't find any guide, where the assigned roles are mentioned.
I only have the SLDDSUSER with assigned role SAP_XI_APPL_SERV_USER on my SLD-System.
Is this the right role? I don't think so.
Please advice
Regards Christian

Hi Christian,
If you are trying to add ABAP/JAVA system into your SLD system please follow the below steps.
For ABAP system.goto RZ70 transaction and provide your SLD system information like hostname and sapgateway service ( sapgwXX here XX instance number).Aftre maintain the settings you can see your ABAP system in SLD technical system details.
For JAVA system you have to logon to Visual admin and goto SLD datasupplier service and there you need to maintain your SLD server details like host name and gateway service.
If your java instance release is 7.1 you need to maintain through NWA.
I hope it will help you.
Regards,
Kiran .V

Similar Messages

  • Directory Services User/Role Validation concurrent request impact

    we have the Java WF Mailer active and have users that receive WF notifications via email and the worklist. If we are are constantly running the Workflow Directory Services User/Role Validation concurrent request, what will this do to them?
    Thanks & Regards,
    sree

    There should not be any impact on the notifications.
    Please see (Questions On The "Workflow Directory Services User/Role Validation" Program [ID 369279.1]) for how frequent you should run this concurrent program.
    Thanks,
    Hussein

  • User Specific catalog UI configuration - Custom catalog user role

    Hi all,
    We need different user specific layout settings for each user. i have duplicated catalog user role for each user and maintained specific named search for that particular user in constraint. but when we want to configure specific layout for individual user. its not showing that catalog user in the catalog config UI for the layout configuration. please advice. if it shows that specific user then we would configure each specific user layout with individual look and feel ( like shopping lists, search fields, images, etc., ). thanks for your inputs.
    Your help would be highly appreciated!!!!!!!!!!!!!

    Hi Smartsoft General user,
    I guess you are on SRM-MDM Catalog 3.0
    We have the same business scenario as yours. Its working perfectly for us.
    1. Donot copy Catalog User role. SRM-MDM UI Config only accepts users assigned under std Catalog User role. You dont need mutiple copies of Catalog user role, anyways it wont work.
    2. Create multiple webservices for each Named search. Provide one User (like User1, User2...or your own created ones) and one Named Search as following parameters in each webservice.
              http://<your server:port>/SRM-MDM/SRM_MDM
    username     User<n>
    password     <password>
    server     <your server>
    repositoryType     M ( for Master ) S (for Slave)  - Make sure you are pointing to right repo if you have master/slave
    catalog     <provide Repository name- make sure you are giving right repository name, I provided it wrong first time>
    port     <your port>
    uilanguage     SY-LANGU
    datalanguage     SY-LANGU
    mask     < keep blank if you want dynamic search>                                                                               
    namedsearch     <Provide exact Named search name as you provided in Data Manager>
    HOOK_URL                                                                               
    returntarget     _parent
    If you are creating 5 different Named searches, create 5 different webservice definitions as above.
    3. Now for each Catalog user, you can perform separate search UI layout as you wish.
    Let me know if this helps or have any questions. If this worked for me, we will make it work for you.
    ~Pravin

  • XIUSER - Service users role/profile at R/3 system

    All,
    Currently, we have the following scenarios
    1) IDoc to XI to 3rd Party System
    2) 3rd Party System to XI to R/3 RFC
    3) R/3 RFC to XI to 3rd Party System
    These scenarios are working using service user XIUSER with SAP_ALL, SAP_NEW access at R/3.
    I would like to know the Roles needs to process the above scenarios.
    Thanks,
    Peter

    hi Peter,
    >>>>2) 3rd Party System to XI to R/3 RFC
    it depends what does your RFC do
    if you're posting MM transaction then you'll need MM roles if SD then SD, etc
    >>>>1) IDoc to XI to 3rd Party System
    SAP_XI_APPL_SERV_USER <-- user role on the XI
    http://help.sap.com/saphelp_nw04/helpdata/en/d4/d12940cbf2195de10000000a1550b0/content.htm
    Regards,
    michal

  • Contact Role should be assigned as 'Self Service User'

    Dear All,
    I have requirement while creating contacts for a particular customer, contact Role should be assigned as ‘Self Service User’ Role, so that they are created as user for iReceivables access. Which column in ra_contact_phones_int_all should be populated with what value ??? Is there any API to update the same .
    Any help on this is appreciated.
    TIA.

    Hi All,
    Anyone has an answer for my query ???

  • Problem in maintaining service user for CCM srm_cse

    Hello all,
    We are implementing SRM 4.0 (EBP 5.5) SSP scenario.
    To support shopping of EBP we are also implementing CCM 2.0 as an add on.
    Please note CCM and EBP are on same client and CAT & CSE are also on the same client.
    No XI is involved as the catalog will be only uploaded in CSV format.
    I am doing intial configurations for CAT and CSE.
    Now we know that we need to configure a service user in the service of srm_cse.
    I am adding the same in SRM client-> trans SICF -> default host -> sap -> bc -> bsp -> ccm -> srm_cse ->change service -> log on procedure- log on data reqd. -> Anonymous log on data - details of client, user, password, language.
    since my SRM and CCM are in same client I have put the same client no. and given the user with role "/CCM/CATALOG_SEARCH"
    But when I am saving this change in service I am getting an error messaeg that " Changes to Repository or cross-client Customizing are not permitted ".
    I am in a same client hence there is no question of cross client customizing .
    The other cause left is CHANGES TO REPOSITORY .
    Can anybody tell me where I should do config so that this "changes to repository" error message will be be corrected?
    Thanks for yr attention and apologies for lengthy matter.
    Kind Regards,
    Dinesh

    Hello Yann,
    Thanks a lot for your attention.
    But my question was regarding particular error I am getting while maintaining service user in the service "srm_cse" as given in my first message.
    Can you throw some light on that pl.?
    My client configration as per yr path is present.
    Regards,
    Dinesh

  • End user roles

    Hello!
    Has anyone configured the e-learning functionlity in SM40.  How do we configure the end user role type ? or how to distribute from a central HR system as mentioned in help.sap? Appreciate any input.
    Thanks.

    Hello Mike,
    To create and assign roles, please refer to the following documentation
    http://help.sap.
    com/saphelp_sm40/helpdata/en/9f/7898408f3db753e10000000a114b1d/frameset.
    htm
    Just to answer your question, after you have assigned the End User Roles
    to the user, the learning map is sent to the E-Mail address in the
    address data (txn SU3).
    FYI, e-Learning Management with the SAP Solution Manager
    https://websmp103.sap-ag.de/~sapidb/011000358700000325712005E.sim
    Hope the above information helps.
    Dolores

  • Assign user role to network group people

    Hi everyone,
    What user role should I assign to network people if they wan to be able to discovery(add) and manage their network devices by themselves. I have tried Advanced Operator and Operator two roles, but non of them came up with Discovery Wizard option. I really don't
    want to assign them to Operations Manager Administrators group because I'm pretty sure they will mess up SCOM within couple mins!!!!!

    Hi,
    We can create runas account for discovery with the network discovery wizard, the runas account type is community string only.
    Network devices that use SNMP v1 or v2 require a Run As account that specifies a community string, which acts like a password to provide read-only access to the device.
    Regards, Yan Li
    Hi Yan Li,
    After reading your post couple times, I'm confused now. I did have two run as account created for community string and snmpv3 authentication. When I ran Discovery Wizard for network devices, I can select either one of them to run without problem,
    and discover network devices. My account is under Operation Manager Administrators role, so I have full permissions to do anything I want.
    My question is that how to configure or create User Roles for network group people, so they can also run Discovery Wizard and manage their network devices without putting them into Operation Manager Administrators group. Ex: there is not Administration
    tab for them, they only see Network Monitoring folder under Monitoring. Because I don't want them to mess up those options under Administration.
    Is it just like the previous post said that only two options?  Thank you.
    1) grant them as a SCOM administrators right
    2) scom administrator help them to do network discovery

  • Service users

    I have gone through different threads that are available on this forum. In summary
    >>The service users are used for internal communication within XI components which are trigerred by Dialog users. The service user username, password, language are given in Exchange profile.
    Again there we have 2 different service users (  service users during design&configuration and service users in during runtime). As a developer whether at any time we are going to use these ?? If so what are the occations in which we will use service users (design & runtime users ) ??
    Thanks
    Kumar

    hi
    Ref this
    http://help.sap.com/saphelp_nw04/helpdata/en/9f/d12940cbf2195de10000000a1550b0/content.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/f9/e3162ec55f4df6922d161f3785012a/frameset.htm
    http://help.sap.com/saphelp_nw04s/helpdata/en/3d/3272396ace5534e10000000a11405a/content.htm
    http://help.sap.com/saphelp_nw04/helpdata/en/d4/d12940cbf2195de10000000a1550b0/frameset.htm
    Dialogue or Service User
    /people/alexander.bundschuh/blog/2007/01/16/principal-propagation-in-sap-xi
    http://help.sap.com/saphelp_nw04/helpdata/en/52/671126439b11d1896f0000e8322d00/frameset.htm
    Thanks

  • Do XI service users have to exist in the SLD with the same password?

    Hi All,
    Do XI service users have to exist in the SLD with the same password?
    We have a 3 system(development, QA and production) XI landscape with a single SLD. All systems are NW04s with support stack 9.
    We are required to change XI service user passwords. I have found OSS note 936093 for changing these passwords. What I am not sure of is if I can change XI service user passwords one system at a time. I am under the impression that XI service users must exist in the SLD with the same password as the XI system. If this is correct, I have to change service user passwords in all three systems at the same time which is not very feasible.
    Thanks,
    Hamid Lashgari

    Creation and Maintain Users
    For the transport of Integration Server content, it is a good idea to install CMS on an
    existing Integration Server. In this double-stack scenario, where an ABAP and J2EE
    stack is used, user management is different from a J2EE only installation.
    Note: For more information about using CMS on a J2EE only installation, see the
    CMS documentation.
    The following section describes the double-stack user management settings required
    when CMS is running on the Integration Server in the development environment. See
    Figure 2. The description we provide starts with ABAP user management and is followed
    by the maintenance in J2EE User Management Engine (UME). You proceed as follows:
    • Create the service user LSADMIN using transaction SU01.
    • Assign the ABAP roles SAP_XI_CMS_SERV_USER and
    SAP_SLD_ORGANIZER to the LSADMIN service user.
    • Create the ABAP role SAP_CMS_ADMINISTRATOR and assign this role to the
    ABAP dialog user(s) responsible for CMS administration.
    • In UME, create the role CMSDeveloper with the actions CMS.Display and
    CMS.Export.
    • In UME, create the role CMSAdministrator with the action CMS.Administrate.
    • In UME, assign the users representing “xirepuser” and “xidiruser” to the role
    CMSDeveloper.
    • In UME, assign the group SAP_CMS_ ADMINISTRATOR to the role
    CMSAdministrator.
    • Log on to CMS with the ABAP dialog user responsible for CMS administration.
    • Maintain the CMS service user (LSADMIN) for the domain.
    Task XI Dev
    With CMS XI Test XI Prod
    Create the service user LSADMIN in TA using transaction
    SU01. Yes Yes Yes
    Assign the ABAP roles SAP_XI_CMS_SERV_USER and
    SAP_SLD_ORGANIZER to the LSADMIN service user. Yes Yes Yes
    Create the ABAP role SAP_CMS_ADMINISTRATOR and
    assign this role to the ABAP dialog user(s) responsible for
    CMS administration.
    Yes No No
    In UME, create the role CMSDeveloper with the action
    CMS.Display and CMS.Export.
    Yes No No
    In UME, create the role CMSAdministrator with the action
    CMS.Administrate.
    Yes No No
    In UME, assign the group SAP_CMS_ ADMINISTRATOR to
    the role CMSAdministrator
    Yes No No
    Log on to CMS with the ABAP dialog user responsible for
    CMS administration.
    Yes No No
    Maintain the CMS service user (LSADMIN) for the domain. Yes No No
    Figure 4: Overview of User Management Tasks in Different Systems

  • Credentials of the configured SERVICE USER not correct

    Hi Gurus
    Is there any way to know the login credentials for a service user(configured in SU01 TCODE).
    Actually,I am gettinf 401 authentication error when I try to post my message through a web service in PROD env.
    In QA and DEV ,its running fine with same credentials of the SERVICE USERconfigured (in ID).
    My scenario is a synchronous SOAP to Proxy.
    Regards,
    Sriparna

    Hi Sriparna,
    Do u have same roles In Production whatever u have in DEV and QA.
    1)First u have to compare the userID Roles.
    2)Check the u r ID have this role SAP_XI_IR_SERV_USER,SAP_XI_DEVELOPER_ABAP,SAP_XI_DEVELOPER_J2EE,SAP_XI_IS_SERV_USER,SAP_XI_RWB_SERV_USER,SAP_XI_MONITOR_ABAP,SAP_XI_MONITOR_J2EE,SAP_XI_MESSAGE_MODIFY.
    Thanks
    Ravi

  • User Authorization Required for configuring SLD

    hi,
    i need to configure SLD and create JCo connections for my webdynpro application.
    i wanted some information regarding what user roles/groups should be assigned to a user in order to
    1)Configure the SLD
    2)Creating JCo Connections
    Thanks & Regards
    Priya Ghosh

    Hi,
    Generally it can done by Admin only.
    If you need then u can give as sytemadmin.
    Thanks,
    Lohi.
    Message was edited by:
            Lohitha M

  • BOE XI R2 - Configuring RAS with Service user, RAS Fails to start...

    Colleagues:
    Where would kbase article c2018785 be found?
    I am configuring my BOE XI R2 to use End-to-End SSO via IIS using this document from Business Objects:
    Link: [https://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/403cdf46-c63e-2b10-2997-978cb8ba59f0]
    In this document, you create a service user under which certain applications run, including the Report Application Server.
    There is a specific note on page 6 in the doc which states:
    The RAS server may fail to start under this new service account. If you experience this issue, follow the steps outlined in the following kbase:
    Link: [http://support.businessobjects.com/library/kbase/articles/c2018785.asp]
    Unfortunately, the link is out of date, and I have not found the article using the existing search tools.
    I did use the -trace argument to the command line to start up the RAS service, and the output is follows:
    Timestamp     ProcessID     ThreadID     Message
    [Thu May 07 13:21:39 2009]     4448     4228     (.ashwin32service.cpp:165): trace message: RAS starting
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2039): CDTSApp::InitInstance(): In CDTSParameters::RUN
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2055): CDTSApp::InitInstance(): Starting server. Process Id=4448
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2062): CDTSApp::InitInstance(): setServerParameters() done
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2130): CDTSApp::InitInstance(): initLicenseLimit() returns 1
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:3895): CDTSApp::loadServerOptions(): about to SaveToRegistryAsDefault
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:3897): CDTSApp::loadServerOptions(): done SaveToRegistryAsDefault hr=-2147024891
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:3916): CDTSApp::loadServerOptions(): error Access is denied.
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2134): CDTSApp::InitInstance(): loadServerOptions() returns 0
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2194): CDTSApp::InitInstance(): getDataEngineName() returns C:TrouxBusiness Objectscommon3.5 incrpe32.dll
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2197): CDTSApp::InitInstance(): openEngine() returns 0
    [Thu May 07 13:21:39 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:39.936 4448 4228 (.dtsdts.cpp:2292): CDTSApp::InitInstance(): preloadMSXML() done
    [Thu May 07 13:21:39 2009]     4448     4228     trace message: EnCOMSessionMgr::EnCOMSessionMgr begins...
    [Thu May 07 13:21:39 2009]     4448     4228     trace message: EnCOMSessionMgr::EnCOMSessionMgr trying to get Singleton SessionManager.
    [Thu May 07 13:21:39 2009]     4448     4228     trace message: CInfoSessionManager::Initialize start
    [Thu May 07 13:21:39 2009]     4448     4228     trace message: CInfoSessionManager::Initialize, start the cluster refresh thread
    [Thu May 07 13:21:40 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:40.217 4448 4228 (.dtsdts.cpp:2445): CDTSApp::InitInstance(): caught UNKNOWN EXCEPTION!!!
    [Thu May 07 13:21:40 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:40.217 4448 4228 (.dtsdts.cpp:2461): CDTSApp::InitInstance() returns 0
    [Thu May 07 13:21:40 2009]     4448     4228     (.dtsdts.cpp:1794): trace message:
    TraceLog 2009  5  7  8:21:40.217 4448 4228 (.dtsdts.cpp:1039): CAgentMapMT::ShutDown - outstanding agents:
    [Thu May 07 13:21:40 2009]     4448     4228     (.ashwin32service.cpp:329): trace message: RAS Exiting: return code = 0
    In the Windows event viewer, this error is echoed:
    Failed to load Report Application Server settings from the system registry.
    Detailed Message: Access is denied.
    It seems my service account needs a certain permission to be able to load and read the registry for this application, and I'm sure this permission is discussed in the missing kbase article. 
    Could you please let me know what permission is required for this user on the OS? This is Win2003 x64 SP2.
    Thanks, and have a good day

    Hi,
    if this a permissions problem then just start +regedit*, go to
    My Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Business Objects
    select it, press the right mouse button and choose Permissions. Press the advanced button and assign your service account with full control at this point of the registry. Do not forget to select the +Replace Permissions Entries on all child objects ... + option.
    You can also take a look at Notes 1199630 and 1201489 (this one is for CR 10 but it may be worth it to follow the instructions there) ( [https://service.sap.com/notes])
    Regards,
    Stratos

  • New Request/Service Offerings not displaying on Portal via Catalog Group/ User Role

    I have created some new service offerings and request offerings which I have published and are visible on the portal when logged in as an administrator.
    I have then added these new items into a catalog group which is tied to a pre-existing user role to target our IT department ( this user role is currently working fine and shows all the other IT related offerings)
    The new published items do are not showing up on the portal.
    AD sync completed with no errors.
    I have done the following to troubleshoot to no avail:
    -  created a new catalog group and user role to target the new SO RO's to
    - targeted directly to a test user rather than the AD group 
    Some other weird things that I  believe to be  related to this is that the contents of catalog groups appear empty on local console but when logging on to the SM server to launch console all catalog group items are visible.
    we are seeing a lot of  error and warning event logs 26319 & 3333
    Any suggestions?
    Thanks
    Pete

    did you try to restart the Microsoft Monitoring Agent?
    Antoine AL Ibry

  • User role for service requests from the SSP

    Does the End User role have enough permissions for users to create service requests from the SSP?  I know for incidents it is but I am not sure about service requests.  If you go through the Service Catalog Checklist, step 5 to create the User
    Role brings up a new role based on the Author role and not on the end user.

    here step by step procedure with user access.
    http://www.concurrency.com/blog/scsmportalpermisions/
    Cheers
    Antoine AL Ibry

Maybe you are looking for

  • HELP??  Can't update my ipod all of the sudden??

    I hooked my iPOD to my computer the other day to update some songs and walked away. Assuming all was well, I unhooked my iPOD and went through my music on the iPOD and suddenly, no songs AT ALL were there. Now, when I try to update my entire library

  • My optical drive went out. what external dvd drive will work?

    My optical drive is going out.  I went to Apple and they suggested I buy an external dvd drive instead of paying $150+ to replace the drive on my MacBook Pro. I bought the Samsung Ultra Portable Slim External DVD drive and it took about 15+minutes fo

  • They keep asking to see my card!

    it happened at Aeropostale...  After a sucessful payment I had to sign and she asked me for my card... So whats the point of apple pay?

  • How do i put a picture of the event on my .mpg4 file ? Please Help

    basically this is my problem. Just got a new sony camera and now i cant see a picture of the movie even. i would like to know which to select. when i go to open my movie folder i used to be able see the picture events of all my movies so i knew which

  • SINGLE USER LOGON

    Hello, In my scenerio we have SAPGUI,EP and ITS. I wan't to disable multiple logins from EP & ITS. I am able to do this is gui level but my requirement is to enable one user at a time , either in EP , ITS or GUI/ Is it possible? Can some one help