CUA - Adding Child systems after implementation

Hello all, just have a quick question:
We have about 10 systems all with 8-10 clients in each of them and are in desperate need of the CUA.  I wanted to just do a couple of systems at first so that everyone could get used to the CUA and then add the rest of the systems at a later time.  Is there anything wrong with this?  Or does the whole distribution model have to be setup BEFORE setting up the CUA?
Thanks

i know your question is answered but i wanted to add my comment anyway - i was not around the last few days ... so: endure it now !
there's no restriction as to when to add other clients/systems to your distribution model. you can go step by step here if you like.
i have an adivce anyway: normally i do it systemwise (not client-wise) because in that way i find it more transparent what ports (WE20/21) and rfc-destinations (SM59) i have created (because i maintain them with the same names/numbers in all the systems in one landscape - just in case there is a system-copy to a new sandbox or somesuch ... then my settings will already be there).
but that's just a personel preference.

Similar Messages

  • CUA client doesn't know any profile/role anymore after adding child system

    Hi,
    I did set up a CUA client on our Solman system. The client is client 500 which has been copied over from 000 via the SAP_CUST profile.
    In this client 500 I did create some users with the SAP_ALL profile, so no problem here.
    After adding a child system to the CUA, it seems that if I want to create a new user in the CUA client 500 it doesn't know any role/profile anymore which is standard available in this client.
    In PFCG I can find a lot of standard roles, but when adding one via SU01 I do get the error that it doesn't exist. The same goes for the profile SAP_ALL.
    Just to be clear, adding profiles or roles from child systems is not a problem, just adding roles or profiles for the CUA client itself doesn't seems to work anymore.
    I had this problem on a 7.0 solman system and now also on a 7.01.
    Did anyone had the same problem?
    Thanks,
    Gregory

    Hello Georges,
    I have exactly the same issue.
    I have created a new CUA. I have copie 001 client to 333 client, using SAP_ALL profile.
    Now, from CUA client (333), I cannot add any roles or profiles to my user.
    I have created an RFC D1CCLNT333, but it does not resolved the problem.
    Did you do anything else to fix your issue ?
    Thanks
    Best regards
    CP2009

  • How to create automatically users&roles in CUA and child systems

    Hi,
    i have a CUA on a 2 chlid R/3 systems (test and training) and 2 portal systems (test and training).
    i need to create a web application to create automatically users test and users training in CUA and see them in the R/3 chlid systems and at the same time to create autmatically a roles in CUA and R/3 chlid systems for those users (we sppose that the role is already stored in a table).
    are there any standard BAPI or Funcion modules that can do this job?
    is the role created automatically in CUA can be seen automaticall in the portal child system?
    any help?
    Thanks&Best regards

    Thank you all. I got the solution.
    Regards
    Rajesh

  • Files newly added in system after having opened firefox are not visible for attachments

    if firefox is alrady running & new file is being added to the system,the same is not visible for attaching the file in gmail. what must be the issue?

    if firefox is alrady running & new file is being added to the system,the same is not visible for attaching the file in gmail. what must be the issue?

  • CUA on PRD without child systems

    Hi,
    We are planing to implement CUA on PRD without child systems. And also DEV as the parent for all non-productive systems. Anybody provide pros/cons making PRD as parent without child systems? Is it recommended?
    Thanks
    Craft

    Hi,
    CUA without child system is of no use. One of the use that I can explain it to you is say:-
    For example:- If you want to assign 10 similar roles to 100 similar user in DEV,Quality or Prod
    1.If CUA is present:-
    You can assign all roles to all user in DEV,Quality or Prod via CUA which will save your time
    2.If CUA is not present:-
    You have to assign all roles to all user first in DEV and then Quality and then in Production which will be more time consuming. You have to log in to individual system and then assign.
    Even maintainance of user becomes easy if you have CUA system. Even removal of roles becames easier
    CUA system without a child system will not be called as CUA system. It will be normal system.

  • CUA user master table updates from child system

    Hi Experts,
    In my system although there are roles assigned to users in child system they are not showing up in CUA for few user.
    Is there any program in CUA which i can use to  update the user master tables for only a limited set of users from child systems.
    Regards,
    Sandeep

    Hi Sandeep,
    Just want to check below queries....if this solves your problem..
    Is these are the new systems assigned to CUA or moved from other CUA as you said that role assignment is available in child system but not in CUA ? Another  thing that  I want you to check the User Group  assigned to user in child system and in CUA.If user gorups assigned to users are different in CUA and child system or particular group is missing in any one of the system then idoc will not move. Also check the Output device type along with address data...Any mismatch of these will stop the idoc.
    After that run the SCUG for all users, in CUA as suggested by akshay, this you can run for all 10 child system from CUA, no need to go in every child system.....

  • CUA - how can I disable child system user record RENAME?

    I have setup CUA.  How can I disable SU01/RENAME from the child system?  If a user is Renamed directly in the child system, the new record is unlocked and can be edited in the child system.  These new records are now out of sync with CUA master data.
    I dont see an option for 'rename' in SCUM.
    Is this how CUA is supposed to work, or can the rename function be disabled?
    Thanks.

    Ben,
    We have installed CUA on solution manager 4.0, the back end (child) system is R3 4.7.
    My CUA SCUM shows seperate tabs for Address and Logon data.
    On the Address tab Ive set everything to global, its a long list.
    On the Logon tab all fields, except for inital password, are set to 'global', inital password is set to 'everywhere', to allow changes directly in the child system.
    Just about everything seems to be working, except this RENAME problem.  The users are greyed out in the child system, the create button doesnt even exist anymore in SU01 in the child system.  Syncing between the CUA and Child systems is working as I expect.
    Any suggestions?
    Thanks for the quick response.

  • CUA Implementation - Resetting of passowrds not affected in Child Systems

    Hi all,
    I have implemented CUA in SOLMAN.
    We are having 6 child systems, when i try to change the passowrd in SU01(in SOLMAN) and select all the systems, its getting affected only to SOLMAN and one more system.
    Rest 4 of the systems are not getting affected....In SCUL it didnt pop up any errors...i m unable to find the reason..
    Could you please guide me to find the error..
    Thanks,
    Subbu

    Hi Tom,
    In WE02 i see some information in Outbound IDocs and everything is GREEN...But in Inbound IDocs i didnt see any information..'
    But whne i change the password in central system, its not getting affected...
    In SCUL transaction, everything is GREEN...didnt receive any errors...
    IN SCUM transaction i tried keeping initial Password parameter as Global, Local and Evrywhr but it didnt solve my problem...
    Any idea what is wrong??
    Thanks,
    Subbu

  • CUA- Deleting user IDs from Child systems

    Is there a possibility of configuring CUA in such a way that user IDs can be created and access can be updated from CUA but deleting user IDs should be taking place only in the child system (Not in all the child systems)?

    Generally good advice to keep the uniqueness of UIDs over time, also after Elvis has left the building
    What you could consider is a CUA RFC user which is not authorized to delete UID's and schedule a purge job for those IDOCs which deleted only them.
    However these sorts of "workaround" solutions are not the best advise, to be honest. What happens it someone temporarily assigns SAP_ALL because there is a big problem and authorizations should be excluded as the cause to get it working again?
    Also, every time a new child system is added to the CUA you will be flooded.
    My advice: Rather change your procedure (as discribed by Jurgen).
    What would be interesting to test is whether you are authorized to move a user (change the authorization relevevant group which they currently have) to a group which the CUA user is no long able to subsequently administrate? But theen you will still be hunting down IDOCs from time to time, most likely.
    If your shop is big enough to have these systems you have described, then you might want to consider an IdM system to replace your CUA at some time.
    If you wish, I will move this thread to the IdM forum.
    Cheers,
    Julius
    ps: Please do not cross-post.

  • Integrate GRC 10.1 with CUA and how to import roles from CUA & Child systems into GRC for provisioning

    Hello,
    I am trying to integrate CUA into our GRC 10.1 system through the below steps and so far I have completed the below steps following SAP Notes 1680108 and 1616121:
    1. Connected CUABOX to GRCBOX like a plug-in system.
    2. Updated CUA Global System and CUA Model Distribution in Maintain CUA settings under User Provisioning.
    3. Next I am trying to import the roles from CUA(CUABOX) into GRC(GRCBOX) to be able to provision roles in CUA Child Systems(ECCBOX).
    After reading few discussions in SCN, I have figured that we have to download a template in Role Import and populate it accordingly to upload the CUA child system roles into GRC system for provisioning in CUA Child Systems.
    Unfortunately, this template has multiple fields and I am unable to determine the fields that should be populated as CUA Global System and CUA Child System to import into GRC. Also, when we upload CUA Child System Roles template what selections should be made in Role Import window.
    Any help in this regard is very helpful.
    Thank you,
    Pawan

    Hi Alessandro,
    I have "Create user if does not exist" setting checked for both change action and assign role action and also have CUA enabled. Here is the list of steps that I am performing:
    1. Create an access request for new account, T-CUA_CHILD and select a role from a child system ECC Z_ECC_ROLE_IN_CHILD_SYSTEM.
    2. Approvals provided to assign the ECC role.
    3. I see the following in GRFNMW_DBGMONITOR_WD.
               Auto provisioning activity at end of request at Path GRAC_DEFAULT_PATH and Stage              GRAC_SECURITY
                   New User:T-CUA_CHILD created in System(s): ECC (created without role assignments)
                   T-CUA_CHILD User does not exist in target system CUA
    GRC created an account without role assignment in ECC but also throwed me an error that the user does not exist in CUA.
    However, if I select roles from both CUA and ECC it creates the account in both systems with the selected role assignments.
    So I am wondering if there is way to provide CUA access to users by default for new account requests types. I have tried setting up default roles for CUA but it does not assign the roles by default until I select the CUA system.
    Thank you for your help!
    Pawan

  • Users created in CUA does not distribute to child systems

    Hi
    I searched this forum and after pulling my hair for 2 days I am asking this question. I created a user in CUA and gave him child system access with the necessary roles.
    I was under the impression that the user will get replicated / distributed automaticlaly to the child systems which i selected at the time of user creation in CUA
    But it does not happen. I login the child system and search for the user. It says User does not exist. I saw SCUL in CUA and the log shows a grey icon next to the username and when I place my cursor on the icon, the tect comes " Distribution unconfirmed"
    What am I missing? Everything looks ok to me
    Why is the user or users not geting replicated or distributed to the child systems with the necessary roles / profiles?

    >
    Jackofalltrades wrote:
    > 2. Also the communication user from Client to CUA is getting locked very frequently. When I do a text comparison from CUA, it always pops the username and password login screen and then I have to enter it and the text comparison happens. I don't know what that happens
    >
    > Any ideas for point 1 and 2 ?
    Hi,
    that is an indication, that the RFC-connection is not defined properly. As soon it does not work, you will get the login screen (on the login screen the default client (503) is filled automatically, but that has nothing to do with the problem you have).
    First check the password of the RFC-user you use. Simply change this user to type 'dialog' and try to log on with the password you know. If that works, reenter this password in SM59. Perform the authorization test in SM59 afterwards. Mind possible upper/lowercase problems with the password depending on the releases your systems are.
    You can also try to perform a remote login through sm59 to make sure, tath you can log on with that RFC-user (as long he is of type dailog this will work). If the rfc-user gets locked frequently, then something is wrong with the rfc configuration. In most cases the entered password is simply wrong.
    Check this first!
    b.rgds, Bernhard

  • CUA Roles residing in Child system are not showing in Central System

    I just hooked up CUA today and have linked 8 child systems to the central system.  The 8 child system users and roles have already been established in the child systems.  Do I need to run program susr_zbv_get_receiver_profiles in each of the child systems to get the roles in the child systems to show up in the Central System for each user?  I tried this in one child system and it worked.
    Or is there something else I need to do without going into each child system?
    I tried this program susr_zbv_get_receiver_profiles in the Central system but it did not work.

    are you looking for roles or profiles? profiles will not show up in the central system. If you run SCUL do you see anything? when you first added the child system did you use an SAP user that had the proper permissions? In both the child and the parent? There are two roles that the user must belong to to add the child to the parent they are SAP_BC_USR_CUA_SETUP_CENTRAL and SAP_BC_USR_CUA_CENTRAL.
    If you have any question about the permissions of these user at the time you added the child to the parent I'd delete the child and re-add with either the above roles or a user with SAP_ALL in BOTH the child and the parent systems

  • CUA and SU10: unexpected deletion in all child systems

    Hi,
    I am facing with a problem with SU10 and CUA.
    I have updated a lot of users with SU10 in CUA. For 20 users in a child system, I first add a new role, everything is fine. Then I perform a remove of a old role (I know that the end date will be changed), everything is fine except for one user. All roles were removed from all systems where the user is defined ! However, when I look in each child systems, it is not the case, the roles are well present except in the child sytem for which I do the remove.
    This problem occurs twice, for different users. It is a real problem because we have to adapt a lot of users.
    I have reinstalled the 'missing' roles with SCUG and with the change document for users but it can be a workaround because I have discovered this by chance. I can imagine check all users after each run of SU10.
    Hope someone can help me.
    Regards

    Hi Olivier,
    that sounds like you are facing the problem corrected with sap note #1117530......
    The removal shows up only at the next change of a user, the actual deletion of role assignements because of the copy might have happend already some time ago.....
    b.rgds, Bernhard

  • User roles un-assigned in CUA but acces in child system is ok

    hi
    i am have a really weird issue. a user who has access in roles in child clients, suddenly his roles disappeared from CUA. it did not effect access in child systems. any suggestions how to investigate this.
    thanks

    Did you click the Naughty Button in SCUL? Check OSS Note 1074552...
    Could also be a cause of failing idocs.
    Regards,
    Trond
    PS: The above note is for cases where users loose their visible role assignments in CUA, although roles remain assigned in the child system(s), not for cases where role assignments from CUA never trickles through to the child systems. The mentioned OSS note is a direct result of a case worked on by yours truly in 2007. I include below a warning I posted on sapfans about the issue:
    Word of warning: RSUSR_CUA_CLEANUP_USZBVSYS is faulty!!!
    The program RSUSR_CUA_CLEANUP_USZBVSYS is available as a standard SAP program from at least version 6.20. It can be run from SE38/SA38 or launched from a pushbutton (far right) on the "results" screen of transaction SCUL.
    The program is intended to delete "obsolete" entries from table USZBVSYS, which contains log entries for assigned child systems in a CUA environment. The program is run in the main CUA system, and supposedly deletes entries for systems where users no longer have access.
    There is a serious problem with the program, as acknowledged and confirmed by SAP in an OSS note I opened a few days ago. Under certain circumstances (more than 500 entries for any child system in the CUA landscape), the program wipes clean the whole table, instead of just the obsolete entries.
    The consequences are dire. Table USZBVSYS is used for several fundamental CUA functions, such as remote password reset from the CUA master system. After the wipe, executing SU01 and attempting to reset a users password in a child system will no longer work. The assigned child systems are no longer visible in the reset password pop-up (nor anywhere else in SU01, including the Roles tab). You'll have to edit the user via SU01, and click on the annoying pop-up showing "new system assigned to user" for each system where the user has access...
    The only way to fix the issue is to re-run SCUG for all systems in the CUA landscape. We had to do this across 6 CUA's, each containing 30+ child systems/clients and 10000+ users, which was very time-consuming and annoying. Also, there seems to be cases where roles have been wiped out from users on the CUA master systems, possibly due to consequences of the empty USZBVSYS table.
    SAP has conceeded the program is faulty, and have proposed a new version (note 1074551). Without applying this correction, the program should NOT be run.
    Note that users can still log in to and work in the child systems, it's just the "visibility" from the CUA master system which is missing. Tables USLA04/USL04 are still intact.
    Just wanted to warn the community; we've spent some considerable time discussing with SAP and rectifying the mess created by RSUSR_CUA_CLEANUP_USZBVSYS...
    Edited by: Trond Stroemme on Aug 5, 2008 3:03 PM

  • CUA history for child systems

    Hi all
    I have seen quite a few forum entries about change history and tables to see the mapping of roles to users, such as:
    Table AGR_USERS (actual assignments)
    Table USLA04 (actual assignments in a CUA central system)
    SUIM report RSSCD100_PFCG for viewing change documents of roles.
    - but does anyone know of any reports / tables that show the change history of a user/what roles they have had assigned, for child system in a CUA set up?
    SUIM and RSSCD100_PFCG only show the local client... we have lost our child systems user <-> roles mappings after a refresh and we want to see history of what roles where assigned to what user, but running these reports in the CUA system only shows local users, and running it in the child is no good as it's just been refreshed and is a copy of the CUA system now anyway!
    Any help much appreciated... we have users in the child system shouting as the don't have the correct authorisations...
    Thanks
    Ross

    Seems nobody knows....    Closing....

Maybe you are looking for

  • JSF 2.0 and @ManagedBean

    I just started to build a new JSF 2.0 application using the latest RI available for download. My first intention was to try the new annotation features like marking a POJO class as managed bean using @ManagedBean and @SessionScoped. When I deployed m

  • The manufacturer of my SD card is?

    I've got a Nokia phone that came with a memory card, but there's no brand name on it. The only thing written on it is "2GB micro SD card" and there are alphanumeric figures at the back. I'm having issues with the card & would like to contact the manu

  • How Do I Get My Music On The Radio.

    Hey there, looking for everyones oppinions When your projects are final and ready, what are the nessary steps onto getting your music played on radio. A&R? other method? Opon acceptance, do most radio stations pay you a figure per play? What is the r

  • Implementing a custom OracleResultSetCache...

    Hi all, I am trying to implement my own result set cache. I've written a class: public class DBCache implements oracle.jdbc.OracleResultSetCache { For some reason, when I try to use DBCache, Oracle throws a ClassCastException. Is the custom cache sup

  • I have the old ipod touch, can i upgrade to the new one and just pay the difference?

    I have the ipod touch 2 and i bought it used a couple of months ago from Apple. I want to tak it in to apple and return it and get the new Ipod Touch and just have to pay the difference, is this possible?