Failed to activate authorization check for user SAPSYS
Hi Experts
I am trying to run the sdcc, it was throwing time_out error. i have increased the work process runtime. now
i am getting a error Failed to activate authorization check for user SAPSYS.
Please help me to solve this issue.
Regards
Venkat
Hi, Mr. Joe Bo.
Thanx for your reply. We are using ECC6 (HP Unix with Oracle)
Basis Patch - 15, Kernel 159
I have seen the the note but it's showing ccms method defination settings, but for my case we are yet to go live we have not made any settings from sap they are planning to run a session for the go live. When i am running sdcc i am getting a error in the system log "Failed to activate authorization check for user SAPSYS"
Thanks & Regards
Venkatesan J
Similar Messages
-
How add Authorization check for user with assigened role for t.code-MIR4
Hi All,
Regarding authorization how to check authorizations check for user whith assigned roles for the t.code MIR4 using ABAP.
In Detail:2) All users are allowed to go to MIR4(invoice number), But ONLY for users with role: MM_RELEASE_INVOICE can proceed to do the posting.
suggest me...
Thanks,
srii..Hi Sri ,
first u need to find out in which user rules u are using this object , after that if u want to restrict users then remove create/change values from that object values .
make use of Tcode SUIM to find out all roles which are using this Object.
or
ask ur basis guy to remove authorizations to create/change....
regards
Prabhu -
Set Up Authorization Check for G/L Accounts into PO creation
Dear friends !
How could I activate check to the access to certain accounts into PO creation ?
I know that is possible to activate this into Purchasing customizing under path
SPRO > Materials management > Purchasing > Purchase order > Set Up Authorization Check for G/L Accounts
But could I use it to give access only to certain GL Accounts by user ? Is this the purpose of this customizing ?
If yes what´s the object should I use to link with user account !?
best regards,
AleHi ,
After you setup the configuration in transaction OMRP, please setup up
the authorisation group in the account code (FS02, the field is on the
"Control", technical name is BEGRU).
When a account assigned purchase order is created, the system checks for
object F_BKPF_BES with values from the BEGRU and activity 01. -
Authorization check for surveys
Hello Friends,
Does anybody know if there is Authorization check for surveys?
I want to restrict access to surveys, depend on user and status of surveys (answered or not).
Thanks for any help.
LalasDear Lalas,
Unfortunately the survey runtime itself doesn't check any authorization.
But for my personal point of view, you might be able to look into the
following to fulfil your requirement:
1.add java script into the survey xml file
Or
2.define your own function module with additional authorization check,
and assign it to survey attributes in transaction CRM_SURVEY_SUITE,
as PBO or PAI function module.
(relevant steps necessary to activate the customer defined
authorization obj.)
Hope these could do help!
Regards, Gerhard -
Authorization check For T code
Hi everyone,
Can anybody guide to set a authorization check for a particular Tcode.
I have ztable where users are assigned particular numbers.
I want the users who are assigned some numbers should be able to use this particular t code
Thanks in advancehi
chk this out
AUTHORITY-CHECK
Basic form
AUTHORITY-CHECK OBJECT object
ID name1 FIELD f1
ID name2 FIELD f2
ID name10 FIELD f10.
Effect
Explanation of IDs:
object
Field which contains the name of the object for which the authorization is to be checked.
name1 ...
Fields which contain the names of the
name10
authorization fields defined in the object.
f1 ...
Fields which contain the values for which the
f10
authorization is to be checked.
AUTHORITY-CHECK checks for one object whether the user has an authorization that contains all values of f (see SAP authorization concept).
You must specify all authorizations for an object and a also a value for each ID (or DUMMY).
The system checks the values for the IDs by AND-ing them together, i.e. all values must be part of an authorization assigned to the user.
If a user has several authorizations for an object, the values are OR-ed together. This means that if the CHECK finds all the specified values in one authorization, the user can proceed. Only if none of the authorizations for a user contains all the required values is the user rejected.
If the return code value in SY-SUBRC is 0, the user has the required authorization and may continue.
The return code value changes according to the different error scenarios. The return code values have the following meaning:
4
User has no authorization in the SAP System for such an action. If necessary, change the user master record.
8
Too many parameters (fields, values). Maximum allowed is 10.
12
Specified object not maintained in the user master record.
16
No profile entered in the user master record.
24
The field names of the check call do not match those of an authorization. Either the authorization or the call is incorrect.
28
Incorrect structure for user master record.
32
Incorrect structure for user master record.
36
Incorrect structure for user master record.
If the return code value is 8 or 24, inform the person responsible for the program. If the return code value is 4, 12, 16 or 24, consult your system administrator if you think you should have the relevant authorization. In the case of errors 28 to 36, contact SAP because authorizations have probably been destroyed.
Individual authorizations are assigned to users in their respective user profiles, i.e. they are grouped together in profiles which are stored in the user master record.
Note
Instead of ID name FIELD f, you can also write ID name DUMMY. This means that no check is performed for the field concerned.
The check can only be performed on CHAR fields. All other field types result in 'unauthorized'.
Example
Check whether the user is authorized for a particular plant. In this case, the following authorization object applies:
Table OBJ: Definition of authorization object
M_EINF_WRK
ACTVT
WERKS
Here, M_EINF_WRK is the object name, whilst ACTVT and WERKS are authorization fields. For example, a user with the authorizations
M_EINF_WRK_BERECH1
ACTVT 01-03
WERKS 0001-0003 .
can display and change plants within the Purchasing and Materials Management areas.
Such a user would thus pass the checks
AUTHORITY-CHECK OBJECT 'M_EINF_WRK'
ID 'WERKS' FIELD '0002'
ID 'ACTVT' FIELD '02'.
AUTHORITY-CHECK OBJECT 'M_EINF_WRK'
ID 'WERKS' DUMMY
ID 'ACTVT' FIELD '01':
but would fail the check
AUTHORITY-CHECK OBJECT 'M_EINF_WRK'
ID 'WERKS' FIELD '0005'
ID 'ACTVT' FIELD '04'.
To suppress unnecessary authorization checks or to carry out checks before the user has entered all the values, use DUMMY - as in this example. You can confirm the authorization later with another AUTHORITY-CHECK -
No Authorization check for MultiProvide (S_RS_MPRO)
Hello Every body
We have a problem regarding the authorization check for MultiProviders. We have assigned the auth. object S_RS_MPRO to a user for one specific MultiProvider. We have also turned on the settings for "MultiProvider" and "MultiPro. (Query) in IMG.
Unfortunately the user has access to all the MultiProviders. We have traced the user and have found out, that there is no authorization check for the MultiProviders.
We have tried to remove the settings mentioned above and use InfoCube (Query) setting instead in conjunction with S_RS_ICUBE. No luck here neither.
One thing that could be important to mention is that the Settings for "MultiProvider" and "MultiPro. (Query) in IMG has been implemented before the object has been assigned to a user.
For that We removed the settings from all Roles, and then we assigned the object to a user, and at last we activated the settings for "MultiProvider" and "MultiPro. (Query) in IMG. No luck here neither.
Bottom line is that the system does not check for S_RS_MPRO
Any kind of suggestion would be appreciated
/FZA
SAP_BW 350
SP 12
BI_CONT 353
PI_BASIS 2004_1_6400.820 BW-BEX-OT-OLAP-AUT 619778 No check of S_RS_ICUBE for Multiprovider 16.10.2003
2. 0.800 BW-WHM-DST-AUT 626385 Multiprovider: Authorization in query fails 07.10.2003
3. 0.790 BW-BEX-OT-OLAP-AUT 662617 Activity is 'Change', but only 'Display' is checked 07.01.2004
4. 0.760 BW-WHM-DST-AUT 626574 MultiProvider authorization check during query 17.10.2003
5. 0.760 BW-WHM-DBA-MPRO 520588 New authorization object S_RS_MPRO 05.11.2003
6. 0.750 BW-WHM-DST-AUT 736996 Authorization check performed on S_RS_MPRO 28.06.2004
7. 0.700 BW 693363 SAPBWNews BW SP03 NW'04 Stack 03 RIN 22.04.2005
8. 0.690 BW 692636 SAPBWNews BW SP02 NW'04 Stack 02 RIN
hallo
Please have allok at the mentioned OSS note
Mike -
Trace deactivated for user SAPSYS
hi,
I see the following message in the sap system for one application server only for ENQ Process
I see the message in SM21
Trace deactivated for user SAPSYS
I could not find any other details of the sam
Please let me know of what can be the reason for the sameCheck Security Audit setting in SM19 to see if by any chance theres a trace enabled for SAPSYS that is failing to "activate".... Long shot but worth trying.
Regards
Juan -
Failing all pre-requisite checks for 11.2.0.2.0 RAC on HP-UX Itanium 64
Hi Guys,
For Typical OR Advanced Grid Installation (GUI), all pre-requisites are failing on both nodes, like memory, swap, node reachability, groups, user & lot more.....
But when I try to check Pre-requisite from command line, everything seems to be ok.
This is what the output...
$ ./runcluvfy.sh stage -pre crsinst -n sph1erp,sph2erp -fixup -verbose
Performing pre-checks for cluster services setup
Checking node reachability...
Check: Node reachability from node "sph1erp"
Destination Node Reachable?
sph1erp yes
sph2erp yes
Result: Node reachability check passed from node "sph1erp"
Checking user equivalence...
Check: User equivalence for user "oracle"
Node Name Comment
sph2erp passed
sph1erp passed
Result: User equivalence check passed for user "oracle"
Checking node connectivity...
Checking hosts config file...
Node Name Status Comment
sph2erp passed
sph1erp passed
Verification of the hosts config file successful
Interface information for node "sph2erp"
Name IP Address Subnet Gateway Def. Gateway HW Address MTU
lan2 10.10.16.51 10.10.16.48 10.10.16.51 10.10.1.12 78:AC:C0:8A:07:76 1500
lan900 10.10.1.174 10.10.0.0 10.10.1.174 10.10.1.12 78:AC:C0:8A:07:6E 1500
Interface information for node "sph1erp"
Name IP Address Subnet Gateway Def. Gateway HW Address MTU
lan2 10.10.16.50 10.10.16.48 10.10.16.50 10.10.1.12 3C:4A:92:48:71:BE 1500
lan900 10.10.1.173 10.10.0.0 10.10.1.173 10.10.1.12 3C:4A:92:48:71:B6 1500
Check: Node connectivity of subnet "10.10.16.48"
Source Destination Connected?
sph2erp[10.10.16.51] sph1erp[10.10.16.50] yes
Result: Node connectivity passed for subnet "10.10.16.48" with node(s) sph2erp,sph1erp
Check: TCP connectivity of subnet "10.10.16.48"
Source Destination Connected?
sph1erp:10.10.16.50 sph2erp:10.10.16.51 passed
Result: TCP connectivity check passed for subnet "10.10.16.48"
Check: Node connectivity of subnet "10.10.0.0"
Source Destination Connected?
sph2erp[10.10.1.174] sph1erp[10.10.1.173] yes
Result: Node connectivity passed for subnet "10.10.0.0" with node(s) sph2erp,sph1erp
Check: TCP connectivity of subnet "10.10.0.0"
Source Destination Connected?
sph1erp:10.10.1.173 sph2erp:10.10.1.174 passed
Result: TCP connectivity check passed for subnet "10.10.0.0"
Interfaces found on subnet "10.10.0.0" that are likely candidates for VIP are:
sph2erp lan900:10.10.1.174
sph1erp lan900:10.10.1.173
Interfaces found on subnet "10.10.16.48" that are likely candidates for a private interconnect are:
sph2erp lan2:10.10.16.51
sph1erp lan2:10.10.16.50
Result: Node connectivity check passed
Check: Total memory
Node Name Available Required Comment
sph2erp 63.9GB (6.7004024E7KB) 4GB (4194304.0KB) passed
sph1erp 63.9GB (6.7004024E7KB) 4GB (4194304.0KB) passed
Result: Total memory check passed
Check: Available memory
Node Name Available Required Comment
sph2erp 53.3556GB (5.5947372E7KB) 50MB (51200.0KB) passed
sph1erp 52.2323GB (5.47695E7KB) 50MB (51200.0KB) passed
Result: Available memory check passed
Check: Swap space
Node Name Available Required Comment
sph2erp 188.7773GB (1.97947352E8KB) 4GB (4194304.0KB) passed
sph1erp 188.7773GB (1.97947352E8KB) 4GB (4194304.0KB) passed
Result: Swap space check passed
Check: Free disk space for "sph2erp:/var/tmp/"
Path Node Name Mount point Available Required Comment
/var/tmp/ sph2erp /var 13.8074GB 1GB passed
Result: Free disk space check passed for "sph2erp:/var/tmp/"
Check: Free disk space for "sph1erp:/var/tmp/"
Path Node Name Mount point Available Required Comment
/var/tmp/ sph1erp /var 13.8158GB 1GB passed
Result: Free disk space check passed for "sph1erp:/var/tmp/"
Check: User existence for "oracle"
Node Name Status Comment
sph2erp exists(199) passed
sph1erp exists(199) passed
Checking for multiple users with UID value 199
Result: Check for multiple users with UID value 199 passed
Result: User existence check passed for "oracle"
Check: Group existence for "oinstall"
Node Name Status Comment
sph2erp exists passed
sph1erp exists passed
Result: Group existence check passed for "oinstall"
Check: Group existence for "dba"
Node Name Status Comment
sph2erp exists passed
sph1erp exists passed
Result: Group existence check passed for "dba"
Check: Membership of user "oracle" in group "oinstall" [as Primary]
Node Name User Exists Group Exists User in Group Primary Comment
sph2erp yes yes yes yes passed
sph1erp yes yes yes yes passed
Result: Membership check for user "oracle" in group "oinstall" [as Primary] passed
Check: Membership of user "oracle" in group "dba"
Node Name User Exists Group Exists User in Group Comment
sph2erp yes yes yes passed
sph1erp yes yes yes passed
Result: Membership check for user "oracle" in group "dba" passed
Check: Run level
Node Name run level Required Comment
sph2erp 3 3 passed
sph1erp 3 3 passed
Result: Run level check passed
Check: Hard limits for "maximum open file descriptors"
Node Name Type Available Required Comment
sph2erp hard 63488 63488 passed
sph1erp hard 63488 63488 passed
Result: Hard limits check passed for "maximum open file descriptors"
Check: Soft limits for "maximum open file descriptors"
Node Name Type Available Required Comment
sph2erp soft 1024 1024 passed
sph1erp soft 63488 1024 passed
Result: Soft limits check passed for "maximum open file descriptors"
Check: Hard limits for "maximum user processes"
Node Name Type Available Required Comment
sph2erp hard 3687 3686 passed
sph1erp hard 3687 3686 passed
Result: Hard limits check passed for "maximum user processes"
Check: Soft limits for "maximum user processes"
Node Name Type Available Required Comment
sph2erp soft 3687 2047 passed
sph1erp soft 3687 2047 passed
Result: Soft limits check passed for "maximum user processes"
Check: System architecture
Node Name Available Required Comment
sph2erp ia64 ia64 passed
sph1erp ia64 ia64 passed
Result: System architecture check passed
Check: Kernel version
Node Name Available Required Comment
sph2erp HP-UX B.11.31 B.11.31 passed
sph1erp HP-UX B.11.31 B.11.31 passed
Result: Kernel version check passed
Check: Kernel parameter for "ksi_alloc_max"
Node Name Configured Required Comment
sph2erp 32768 32768 passed
sph1erp 32768 32768 passed
Result: Kernel parameter check passed for "ksi_alloc_max"
Check: Kernel parameter for "executable_stack"
Node Name Configured Required Comment
sph2erp 0 0 passed
sph1erp 0 0 passed
Result: Kernel parameter check passed for "executable_stack"
Check: Kernel parameter for "max_thread_proc"
Node Name Configured Required Comment
sph2erp 1024 1024 passed
sph1erp 1024 1024 passed
Result: Kernel parameter check passed for "max_thread_proc"
Check: Kernel parameter for "maxdsiz"
Node Name Configured Required Comment
sph2erp 1073741824 1073741824 passed
sph1erp 1073741824 1073741824 passed
Result: Kernel parameter check passed for "maxdsiz"
Check: Kernel parameter for "maxdsiz_64bit"
Node Name Configured Required Comment
sph2erp 2147483648 2147483648 passed
sph1erp 2147483648 2147483648 passed
Result: Kernel parameter check passed for "maxdsiz_64bit"
Check: Kernel parameter for "maxssiz"
Node Name Configured Required Comment
sph2erp 134217728 134217728 passed
sph1erp 134217728 134217728 passed
Result: Kernel parameter check passed for "maxssiz"
Check: Kernel parameter for "maxssiz_64bit"
Node Name Configured Required Comment
sph2erp 1073741824 1073741824 passed
sph1erp 1073741824 1073741824 passed
Result: Kernel parameter check passed for "maxssiz_64bit"
Check: Kernel parameter for "maxuprc"
Node Name Configured Required Comment
sph2erp 3686 3686 passed
sph1erp 3686 3686 passed
Result: Kernel parameter check passed for "maxuprc"
Check: Kernel parameter for "msgmni"
Node Name Configured Required Comment
sph2erp 4096 4096 passed
sph1erp 4096 4096 passed
Result: Kernel parameter check passed for "msgmni"
Check: Kernel parameter for "msgtql"
Node Name Configured Required Comment
sph2erp 4096 4096 passed
sph1erp 4096 4096 passed
Result: Kernel parameter check passed for "msgtql"
Check: Kernel parameter for "ncsize"
Node Name Configured Required Comment
sph2erp 35840 35840 passed
sph1erp 35840 35840 passed
Result: Kernel parameter check passed for "ncsize"
Check: Kernel parameter for "shmmax"
Node Name Configured Required Comment
sph2erp 1073741824 1073741824 passed
sph1erp 1073741824 1073741824 passed
Result: Kernel parameter check passed for "shmmax"
Check: Kernel parameter for "shmmni"
Node Name Configured Required Comment
sph2erp 4096 4096 passed
sph1erp 4096 4096 passed
Result: Kernel parameter check passed for "shmmni"
Check: Kernel parameter for "shmseg"
Node Name Configured Required Comment
sph2erp 512 512 passed
sph1erp 512 512 passed
Result: Kernel parameter check passed for "shmseg"
Check: Kernel parameter for "tcp_smallest_anon_port"
Node Name Configured Required Comment
sph2erp 9000 9000 passed
sph1erp 9000 9000 passed
Result: Kernel parameter check passed for "tcp_smallest_anon_port"
Check: Kernel parameter for "tcp_largest_anon_port"
Node Name Configured Required Comment
sph2erp 65500 65500 passed
sph1erp 65500 65500 passed
Result: Kernel parameter check passed for "tcp_largest_anon_port"
Check: Kernel parameter for "udp_smallest_anon_port"
Node Name Configured Required Comment
sph2erp 9000 9000 passed
sph1erp 9000 9000 passed
Result: Kernel parameter check passed for "udp_smallest_anon_port"
Check: Kernel parameter for "udp_largest_anon_port"
Node Name Configured Required Comment
sph2erp 65500 65500 passed
sph1erp 65500 65500 passed
Result: Kernel parameter check passed for "udp_largest_anon_port"
Check: Package existence for "OS-Core-B.11.31( ia64)"
Node Name Available Required Comment
sph2erp OS-Core-B.11.31-0 OS-Core-B.11.31( ia64) passed
sph1erp OS-Core-B.11.31-0 OS-Core-B.11.31( ia64) passed
Result: Package existence check passed for "OS-Core-B.11.31( ia64)"
Check: Operating system patch for "Patch PHKL_38938"
Node Name Applied Required Comment
sph2erp Patch PHKL_39646 Patch PHKL_38938 passed
sph1erp Patch PHKL_39646 Patch PHKL_38938 passed
Result: Operating system patch check passed for "Patch PHKL_38938"
Check: Operating system patch for "Patch PHKL_39351"
Node Name Applied Required Comment
sph2erp Patch PHKL_40207 Patch PHKL_39351 passed
sph1erp Patch PHKL_40207 Patch PHKL_39351 passed
Result: Operating system patch check passed for "Patch PHKL_39351"
Check: Operating system patch for "Patch PHSS_36354"
Node Name Applied Required Comment
sph2erp Patch PHSS_40546 Patch PHSS_36354 passed
sph1erp Patch PHSS_40546 Patch PHSS_36354 passed
Result: Operating system patch check passed for "Patch PHSS_36354"
Check: Operating system patch for "Patch PHSS_37042"
Node Name Applied Required Comment
sph2erp Patch PHSS_37042 Patch PHSS_37042 passed
sph1erp Patch PHSS_37042 Patch PHSS_37042 passed
Result: Operating system patch check passed for "Patch PHSS_37042"
Check: Operating system patch for "Patch PHSS_37959"
Node Name Applied Required Comment
sph2erp Patch PHSS_40804 Patch PHSS_37959 passed
sph1erp Patch PHSS_40804 Patch PHSS_37959 passed
Result: Operating system patch check passed for "Patch PHSS_37959"
Check: Operating system patch for "Patch PHSS_39094"
Node Name Applied Required Comment
sph2erp Patch PHSS_40538 Patch PHSS_39094 passed
sph1erp Patch PHSS_40538 Patch PHSS_39094 passed
Result: Operating system patch check passed for "Patch PHSS_39094"
Check: Operating system patch for "Patch PHSS_39100"
Node Name Applied Required Comment
sph2erp Patch PHSS_40540 Patch PHSS_39100 passed
sph1erp Patch PHSS_40540 Patch PHSS_39100 passed
Result: Operating system patch check passed for "Patch PHSS_39100"
Check: Operating system patch for "Patch PHSS_39102"
Node Name Applied Required Comment
sph2erp Patch PHSS_41496 Patch PHSS_39102 passed
sph1erp Patch PHSS_41496 Patch PHSS_39102 passed
Result: Operating system patch check passed for "Patch PHSS_39102"
Check: Operating system patch for "Patch PHSS_38141"
Node Name Applied Required Comment
sph2erp Patch PHSS_38141 Patch PHSS_38141 passed
sph1erp Patch PHSS_38141 Patch PHSS_38141 passed
Result: Operating system patch check passed for "Patch PHSS_38141"
Check: Operating system patch for "Patch PHCO_40381"
Node Name Applied Required Comment
sph2erp Patch PHCO_40381 Patch PHCO_40381 passed
sph1erp Patch PHCO_40381 Patch PHCO_40381 passed
Result: Operating system patch check passed for "Patch PHCO_40381"
Check: Operating system patch for "Patch PHKL_38038"
Node Name Applied Required Comment
sph2erp Patch PHKL_41005 Patch PHKL_38038 passed
sph1erp Patch PHKL_41005 Patch PHKL_38038 passed
Result: Operating system patch check passed for "Patch PHKL_38038"
Checking for multiple users with UID value 0
Result: Check for multiple users with UID value 0 passed
Check: Current group ID
Result: Current group ID check passed
Starting Clock synchronization checks using Network Time Protocol(NTP)...
NTP Configuration file check started...
Network Time Protocol(NTP) configuration file not found on any of the nodes. Oracle Cluster Time Synchronization Service(CTSS) can be used instead of NTP for time synchronization on the cluster nodes
No NTP Daemons or Services were found to be running
Result: Clock synchronization check using Network Time Protocol(NTP) passed
Checking Core file name pattern consistency...
Core file name pattern consistency check passed.
Checking to make sure user "oracle" is not in "root" group
Node Name Status Comment
sph2erp does not exist passed
sph1erp does not exist passed
Result: User "oracle" is not part of "root" group. Check passed
Check default user file creation mask
Node Name Available Required Comment
sph2erp 022 0022 passed
sph1erp 022 0022 passed
Result: Default user file creation mask check passed
Checking consistency of file "/etc/resolv.conf" across nodes
Node Name Status
sph2erp passed
sph1erp passed
The DNS response time for an unreachable node is within acceptable limit on all nodes
File "/etc/resolv.conf" is consistent across nodes
Check: Time zone consistency
Result: Time zone consistency check passed
Checking settings of device file "/dev/async"
Node Name Available Comment
sph2erp yes failed (incorrect setting for minor number.)
sph1erp yes failed (incorrect setting for minor number.)
Result: Check for settings of device file "/dev/async" failed.
Starting check for The SSH LoginGraceTime setting ...
WARNING:
PRVE-0038 : The SSH LoginGraceTime setting on node "sph2erp" may result in users being disconnected before login is completed
PRVE-0038 : The SSH LoginGraceTime setting on node "sph1erp" may result in users being disconnected before login is completed
Check for The SSH LoginGraceTime setting passed
Fixup information has been generated for following node(s):
sph2erp,sph1erp
Please run the following script on each node as "root" user to execute the fixups:
'/tmp/CVU_11.2.0.2.0_oracle/runfixup.sh'
Pre-check for cluster services setup was unsuccessful on all the nodes.
What could be the issue ????
Any help would be appreciated...
Regards,
ManishStarted with Grid Installation. Copying Software to remote node & linking libraries were successfully without any issue (upto 76%). But got issue while executing root.sh on Node1
sph1erp:/oracle/11.2.0/grid #sh root.sh
Running Oracle 11g root script...
The following environment variables are set as:
ORACLE_OWNER= oracle
ORACLE_HOME= /oracle/11.2.0/grid
Enter the full pathname of the local bin directory: [usr/local/bin]:
Copying dbhome to /usr/local/bin ...
Copying oraenv to /usr/local/bin ...
Copying coraenv to /usr/local/bin ...
Creating /etc/oratab file...
Entries will be added to the /etc/oratab file as needed by
Database Configuration Assistant when a database is created
Finished running generic part of root script.
Now product-specific root actions will be performed.
Using configuration parameter file: /oracle/11.2.0/grid/crs/install/crsconfig_params
Creating trace directory
LOCAL ADD MODE
Creating OCR keys for user 'root', privgrp 'sys'..
Operation successful.
OLR initialization - successful
root wallet
root wallet cert
root cert export
peer wallet
profile reader wallet
pa wallet
peer wallet keys
pa wallet keys
peer cert request
pa cert request
peer cert
pa cert
peer root cert TP
profile reader root cert TP
pa root cert TP
peer pa cert TP
pa peer cert TP
profile reader pa cert TP
profile reader peer cert TP
peer user cert
pa user cert
Adding daemon to inittab
CRS-2672: Attempting to start 'ora.mdnsd' on 'sph1erp'
CRS-2676: Start of 'ora.mdnsd' on 'sph1erp' succeeded
CRS-2672: Attempting to start 'ora.gpnpd' on 'sph1erp'
CRS-2676: Start of 'ora.gpnpd' on 'sph1erp' succeeded
CRS-2672: Attempting to start 'ora.cssdmonitor' on 'sph1erp'
CRS-2672: Attempting to start 'ora.gipcd' on 'sph1erp'
CRS-2676: Start of 'ora.gipcd' on 'sph1erp' succeeded
CRS-2676: Start of 'ora.cssdmonitor' on 'sph1erp' succeeded
CRS-2672: Attempting to start 'ora.cssd' on 'sph1erp'
CRS-2672: Attempting to start 'ora.diskmon' on 'sph1erp'
CRS-2676: Start of 'ora.diskmon' on 'sph1erp' succeeded
CRS-2676: Start of 'ora.cssd' on 'sph1erp' succeeded
ASM created and started successfully.
Disk Group OCRVOTE created successfully.
clscfg: -install mode specified
Successfully accumulated necessary OCR keys.
Creating OCR keys for user 'root', privgrp 'sys'..
Operation successful.
CRS-4256: Updating the profile
Successful addition of voting disk ab847ed2b4f04f2dbfb875226d2bb194.
Successful addition of voting disk 85c05a5b30384f8dbff48cc069de7a7c.
Successful addition of voting disk 649196fbdd614f9cbf26a9a0e6670a6e.
Successful addition of voting disk 8815dfcee2e64f64bf00b9c76626ab41.
Successful addition of voting disk 8ce55fe5534f4f77bfa9f54187592707.
Successfully replaced voting disk group with +OCRVOTE.
CRS-4256: Updating the profile
CRS-4266: Voting file(s) successfully replaced
## STATE File Universal Id File Name Disk group
1. ONLINE ab847ed2b4f04f2dbfb875226d2bb194 (/dev/oracle/ocrvote1) [OCRVOTE]
2. ONLINE 85c05a5b30384f8dbff48cc069de7a7c (/dev/oracle/ocrvote2) [OCRVOTE]
3. ONLINE 649196fbdd614f9cbf26a9a0e6670a6e (/dev/oracle/ocrvote3) [OCRVOTE]
4. ONLINE 8815dfcee2e64f64bf00b9c76626ab41 (/dev/oracle/ocrvote4) [OCRVOTE]
5. ONLINE 8ce55fe5534f4f77bfa9f54187592707 (/dev/oracle/ocrvote5) [OCRVOTE]
Located 5 voting disk(s).
Start of resource "ora.cluster_interconnect.haip" failed
CRS-2672: Attempting to start 'ora.cluster_interconnect.haip' on 'sph1erp'
CRS-5017: The resource action "ora.cluster_interconnect.haip start" encountered the following error:
Start action for HAIP aborted
CRS-2674: Start of 'ora.cluster_interconnect.haip' on 'sph1erp' failed
CRS-2679: Attempting to clean 'ora.cluster_interconnect.haip' on 'sph1erp'
CRS-2681: Clean of 'ora.cluster_interconnect.haip' on 'sph1erp' succeeded
CRS-4000: Command Start failed, or completed with errors.
Failed to start Oracle Clusterware stack
Failed to start High Availability IP at /oracle/11.2.0/grid/crs/install/crsconfig_lib.pm line 1046.
/oracle/11.2.0/grid/perl/bin/perl -I/oracle/11.2.0/grid/perl/lib -I/oracle/11.2.0/grid/crs/install /oracle/11.2.0/grid/crs/install/rootcrs.pl execution failed
sph1erp:/oracle/11.2.0/grid #
Last few lines from CRS Log for node 1, where error came
[ctssd(6467)]CRS-2401:The Cluster Time Synchronization Service started on host sph1erp.
2011-02-25 23:04:16.491
[oracle/11.2.0/grid/bin/orarootagent.bin(6423)]CRS-5818:Aborted command 'start for resource: ora.cluster_interconnect.haip 1 1' for resource 'ora.cluster_int
erconnect.haip'. Details at (:CRSAGF00113:) {0:0:178} in */oracle/11.2.0/grid/log/sph1erp/agent/ohasd/orarootagent_root/orarootagent_root.log.*
2011-02-25 23:04:20.521
[ohasd(5513)]CRS-2757:Command 'Start' timed out waiting for response from the resource 'ora.cluster_interconnect.haip'. Details at (:CRSPE00111:) {0:0:178} in
*/oracle/11.2.0/grid/log/sph1erp/ohasd/ohasd.log.*
Few lines from */oracle/11.2.0/grid/log/sph1erp/agent/ohasd/orarootagent_root/orarootagent_root.log.*
=====================================================================================================
2011-02-25 23:04:16.823: [ USRTHRD][16] {0:0:178} Starting Probe for ip 169.254.74.54
2011-02-25 23:04:16.823: [ USRTHRD][16] {0:0:178} Transitioning to Probe State
2011-02-25 23:04:17.177: [ USRTHRD][15] {0:0:178} [NetHAMain] thread stopping
2011-02-25 23:04:17.177: [ USRTHRD][15] {0:0:178} Thread:[NetHAMain]isRunning is reset to false here
2011-02-25 23:04:17.178: [ USRTHRD][12] {0:0:178} Thread:[NetHAMain]stop }
2011-02-25 23:04:17.178: [ USRTHRD][12] {0:0:178} thread cleaning up
2011-02-25 23:04:17.178: [ USRTHRD][12] {0:0:178} pausing thread
2011-02-25 23:04:17.178: [ USRTHRD][12] {0:0:178} posting thread
2011-02-25 23:04:17.178: [ USRTHRD][12] {0:0:178} Thread:[NetHAWork]stop {
2011-02-25 23:04:17.645: [ USRTHRD][16] {0:0:178} [NetHAWork] thread stopping
2011-02-25 23:04:17.645: [ USRTHRD][16] {0:0:178} Thread:[NetHAWork]isRunning is reset to false here
2011-02-25 23:04:17.645: [ USRTHRD][12] {0:0:178} Thread:[NetHAWork]stop }
2011-02-25 23:04:17.645: [ USRTHRD][12] {0:0:178} Thread:[NetHAWork]stop {
2011-02-25 23:04:17.645: [ USRTHRD][12] {0:0:178} Thread:[NetHAWork]stop }
2011-02-25 23:04:17.891: [ora.cluster_interconnect.haip][12] {0:0:178} [start] Start of HAIP aborted
2011-02-25 23:04:17.892: [ AGENT][12] {0:0:178} UserErrorException: Locale is
2011-02-25 23:04:17.893: [ora.cluster_interconnect.haip][12] {0:0:178} [start] clsnUtils::error Exception type=2 string=
CRS-5017: The resource action "ora.cluster_interconnect.haip start" encountered the following error:
Start action for HAIP aborted
2011-02-25 23:04:17.893: [ AGFW][12] {0:0:178} sending status msg [CRS-5017: The resource action "ora.cluster_interconnect.haip start" encountered the foll
owing error:
Start action for HAIP aborted
] for start for resource: ora.cluster_interconnect.haip 1 1
2011-02-25 23:04:17.893: [ora.cluster_interconnect.haip][12] {0:0:178} [start] clsn_agent::start }
2011-02-25 23:04:17.894: [ AGFW][10] {0:0:178} Agent sending reply for: RESOURCE_START[ora.cluster_interconnect.haip 1 1] ID 4098:661
2011-02-25 23:04:18.552: [ora.diskmon][12] {0:0:154} [check] DiskmonAgent::check {
2011-02-25 23:04:18.552: [ora.diskmon][12] {0:0:154} [check] DiskmonAgent::check } - 0
2011-02-25 23:04:19.573: [ AGFW][10] {0:0:154} Agent received the message: AGENT_HB[Engine] ID 12293:669
2011-02-25 23:04:20.510: [ora.cluster_interconnect.haip][18] {0:0:178} [start] got lock
2011-02-25 23:04:20.511: [ora.cluster_interconnect.haip][18] {0:0:178} [start] tryActionLock }
2011-02-25 23:04:20.511: [ora.cluster_interconnect.haip][18] {0:0:178} [start] abort }
2011-02-25 23:04:20.511: [ora.cluster_interconnect.haip][18] {0:0:178} [start] clsn_agent::abort }
2011-02-25 23:04:20.511: [ AGFW][18] {0:0:178} Command: start for resource: ora.cluster_interconnect.haip 1 1 completed with status: TIMEDOUT
2011-02-25 23:04:20.512: [ora.cluster_interconnect.haip][8] {0:0:178} [check] NetworkAgent::init enter {
2011-02-25 23:04:20.513: [ora.cluster_interconnect.haip][8] {0:0:178} [check] NetworkAgent::init exit }
2011-02-25 23:04:20.517: [ AGFW][10] {0:0:178} Agent sending reply for: RESOURCE_START[ora.cluster_interconnect.haip 1 1] ID 4098:661
2011-02-25 23:04:20.519: [ USRTHRD][8] {0:0:178} Ocr Context init default level 23886304
2011-02-25 23:04:20.519: [ default][8]clsvactversion:4: Retrieving Active Version from local storage.
[ CLWAL][8]clsw_Initialize: OLR initlevel [70000]
Few lines from */oracle/11.2.0/grid/log/sph1erp/ohasd/ohasd.log.*
=====================================================================================================
2011-02-25 23:04:21.627: [UiServer][30] {0:0:180} Done for ctx=6000000002604ce0
2011-02-25 23:04:21.642: [UiServer][31] Closed: remote end failed/disc.
2011-02-25 23:04:26.139: [ CLSINET][33]Returning NETDATA: 1 interfaces
2011-02-25 23:04:26.139: [ CLSINET][33]# 0 Interface 'lan2',ip='10.10.16.50',mac='3c-4a-92-48-71-be',mask='255.255.255.240',net='10.10.16.48',use='cluster_int
erconnect'
2011-02-25 23:04:26.973: [UiServer][31] CS(60000000014b0790)set Properties ( root,60000000012e0260)
2011-02-25 23:04:26.973: [UiServer][31] SS(6000000001372270)Accepted client connection: saddr =(ADDRESS=(PROTOCOL=ipc)(DEV=92)(KEY=OHASD_UI_SOCKET))daddr = (A
DDRESS=(PROTOCOL=ipc)(KEY=OHASD_UI_SOCKET))
2011-02-25 23:04:26.992: [UiServer][30] {0:0:181} processMessage called
2011-02-25 23:04:26.993: [UiServer][30] {0:0:181} Sending message to PE. ctx= 6000000001b440f0
2011-02-25 23:04:26.993: [UiServer][30] {0:0:181} Sending command to PE: 67
2011-02-25 23:04:26.994: [ CRSPE][29] {0:0:181} Processing PE command id=173. Description: [Stat Resource : 600000000135f760]
2011-02-25 23:04:26.997: [UiServer][30] {0:0:181} Done for ctx=6000000001b440f0
2011-02-25 23:04:27.012: [UiServer][31] Closed: remote end failed/disc.
2011-02-25 23:04:31.135: [ CLSINET][33]Returning NETDATA: 1 interfaces
2011-02-25 23:04:31.135: [ CLSINET][33]# 0 Interface 'lan2',ip='10.10.16.50',mac='3c-4a-92-48-71-be',mask='255.255.255.240',net='10.10.16.48',use='cluster_int
erconnect'
2011-02-25 23:04:32.318: [UiServer][31] CS(60000000014b0790)set Properties ( root,60000000012e0260)
2011-02-25 23:04:32.318: [UiServer][31] SS(6000000001372270)Accepted client connection: saddr =(ADDRESS=(PROTOCOL=ipc)(DEV=92)(KEY=OHASD_UI_SOCKET))daddr = (A
DDRESS=(PROTOCOL=ipc)(KEY=OHASD_UI_SOCKET))
2011-02-25 23:04:32.332: [UiServer][30] {0:0:182} processMessage called
2011-02-25 23:04:32.333: [UiServer][30] {0:0:182} Sending message to PE. ctx= 6000000001b45ef0
2011-02-25 23:04:32.333: [UiServer][30] {0:0:182} Sending command to PE: 68
2011-02-25 23:04:32.334: [ CRSPE][29] {0:0:182} Processing PE command id=174. Description: [Stat Resource : 600000000135f760]
2011-02-25 23:04:32.338: [UiServer][30] {0:0:182} Done for ctx=6000000001b45ef0
2011-02-25 23:04:32.352: [UiServer][31] Closed: remote end failed/disc.
2011-02-25 23:04:36.155: [ CLSINET][33]Returning NETDATA: 1 interfaces
2011-02-25 23:04:36.155: [ CLSINET][33]# 0 Interface 'lan2',ip='10.10.16.50',mac='3c-4a-92-48-71-be',mask='255.255.255.240',net='10.10.16.48',use='cluster_int
erconnect'
2011-02-25 23:04:37.683: [UiServer][31] CS(60000000014b0790)set Properties ( root,60000000012e0260)
2011-02-25 23:04:37.683: [UiServer][31] SS(6000000001372270)Accepted client connection: saddr =(ADDRESS=(PROTOCOL=ipc)(DEV=92)(KEY=OHASD_UI_SOCKET))daddr = (A
DDRESS=(PROTOCOL=ipc)(KEY=OHASD_UI_SOCKET))
2011-02-25 23:04:37.702: [UiServer][30] {0:0:183} processMessage called
2011-02-25 23:04:37.703: [UiServer][30] {0:0:183} Sending message to PE. ctx= 6000000002604ce0
2011-02-25 23:04:37.703: [UiServer][30] {0:0:183} Sending command to PE: 69
2011-02-25 23:04:37.704: [ CRSPE][29] {0:0:183} Processing PE command id=175. Description: [Stat Resource : 600000000135f760]
2011-02-25 23:04:37.708: [UiServer][30] {0:0:183} Done for ctx=6000000002604ce0
2011-02-25 23:04:37.722: [UiServer][31] Closed: remote end failed/disc.
2011-02-25 23:04:41.156: [ CLSINET][33]Returning NETDATA: 1 interfaces
2011-02-25 23:04:41.156: [ CLSINET][33]# 0 Interface 'lan2',ip='10.10.16.50',mac='3c-4a-92-48-71-be',mask='255.255.255.240',net='10.10.16.48',use='cluster_int
erconnect'
What could be the issue ????
Experts Please help me. Doing setup for the PRoduction Env...
Do response ASAP...... Thanks
Regards,
Manish -
RFC_NO_AUTHORITY error for user SAPSYS in client 000
Hi
I have a lot of abap dumps in ST22 RFC_NO_AUTHORITY error for user SAPSYS in client 000 for today which I'm not sure what they mean. I don't have a SAPSYS user in client 000.
The reason that I'm concerend is we had an incident with the SAP server last night where it became unresponsive about 2.30 am and had to be manually rebooted this morning. The R3 jobs all ran OK but the BW loads failed and had to be re-run this morning. There were no unusual jobs or programs running last night and the Server Event Log does not contain any further information as to the probable cause of the problem.
I'm not sure if this error is related to the BW jobs running and was wondering did anyone come accross it and what it means.
Thanks
SiobhanCheck notes 944615 and 93254.
Rich -
Create authorization check for a report
Hi,
I need to create an authorization check for a report. It means that I need to restrict the usage of the report to couple of users ( 'USER1' and 'USER2' ). How can I do that? I did read through a lot of threads regarding this piece got a bit confused and stuck while creating the authorization object.
Say the report name is ZHR_TIMEABC.
Can anyone explain how to create an authorization object and how are they tied to the object and call them in the abap code?
Thanks in advance,
VGHi,
Thanks. Here is my understanding, S_C_FUNCT calls a system generated function module to make an authority check. So, if different users say USER1 and USER2 have different authroization levels, defined in their user profile, just adding this piece code will take care of authroization check for the program OR do I need to take care of something else?
If so, when do we need to create the authorization objects using SU20 and assign the group and follo this process? When do we use this approach ( lot of threads on authority check have mentioned this procedure)?
Your inputs will be helpful to understand this concept.
Thanks,
VG -
Authorization Check for Special Stock Indicator in IE02
Dear Gurus,
Would like to check with you if there is an authorization check for change in Special Stock Indicator in IE02-SerData Tab?
For example, the User will only be allowed to change the Special Stock Indicator only to "E" - Sales Order.
Would appreciate your help.
Thanks.Hi,
This cannot be done by using standard auth object. Standard SAP doesnt support control via this field.
Take help of your ABAP team and create an customized authorization object "Z_OBJECT" with field SOBKZ and which check these field value in table EQBS. Assign this auth object to role and profile you want.
Use the user exit IEQM0003 Additional checks before equipment update. Give a logic to check auth object when while using equipment change tcode. -
Authorization check for a program/table
Hi ,
Can anyone help me out in
How to do authorization check for an abap program and also a table.
I have no idea about the authorizations.
My requirement is that I need to do the authorization check in such a manner that only users having a certain profile
1. should be able to execute the program
2. View of the entries of the table.
Thanks & Regards,
KeerthiHello Keerhi ,
I got you wrong at first!
If you want to have only certain users to be able to do certain operations, then you need to assign the appropriate roles to those users!
First find the role
second add the user in the role ( PFCG T code---> USers tab)
Raj -
How to turn off the authorization checks for a object in infoproviders?
Hi - how can I turn off the authorization check for an object (ex: 0orgunit) in infoproviders?
I have 0orgunit as an authorization-relevant object and is used in one of the cubes. When reports are run for this cube, this is causing authorization issues. The object is present in other cubes also but I have to remove or turn off the authorization check of this cube alone. How to do this? Please help.
Thanks,
Raj.Hi Raj,
Srinivas, is right , however in BI7 the correct transaction is RSECADMIN and not RSADMIN.
In BW3.5, use RSSM transaction to do thins.
OR
Go to transaction RSECAUTH ---> Choose the authorization object that has been created for org unit(and has been assigned to the user). Go to change mode. Remove the cube from the dimension 0TCAIPROV
If you are using old authorization concept in 3.5 or in 7.0
Go to RSSM. In the checks for infoprovider, enter your infoprovider name. Choose change.Here you will see a checkbox to switch off the authorization.
Hope this helps you,
Best regards,
Sunmit. -
No ICF authorization CHECK for executing /sap/bc/bsp/sap/hap_document
In EP we are trying to access bsp
and we are getting error ,User T000209 (client 350) has no ICF authorization CHECK for executing /sap/bc/bsp/sap/hap_document
How to give authorization please help
venkateswararaoFirst Check is the ICF service is active using the SICF transaction.
Then Check for the authorization objects SAP_HR_HAP_EMPLOYEE
and SAP_HR_HAP_MANAGER.
Add the above roles to your user , it should work -
Authorization Check for Storage Location
Hi Experts,
I have the following requirement :-
I have Plant : P081 created under Company Code : P110.
I have got various Storage Locations under this Plant for example
KT01 - Main Stores
KT24 - Remote Store.
The KT24 store is basically a remote location store. I have activated the Authorization for the Storage Location KT24 in the SPRO Settings
Material Management --> Inventory Management and Physical Inventory --> Authorization Management --> Authorization check for storage location.
I have maintain the following authorizations for the Object M_MSEG_LGO as follows :-
1. OBJECT : M_MSEG_LGO.
>> 2. USER ID : 081Store
>> 3. PLANT : P081
>> 4. STORAGE LOCATION : Kt24
>> 5. ACTIVITY : 01-03
>> 6. MOVEMENT : 101, 102, 201, 221, 261
and authorization for T_code MIGO_GR and MIGO_GI . I want to restrict the user for transaction only for this storage location but the system is allowing the user to post GR document for KT01 stores also.
Can any one suggest a solution or settings that need to be done for the user to be restricted to prepared GR for Storage Location KT24 only.
Thanks in advance.
AJHi,
You set the authorizations to users with tcode PFCG. To know the reason of deny some access run tcode SU53 after SAP denies the access to some documents / objects.
Regards,
Eduardo
Maybe you are looking for
-
How do I install Samba 3.4.6 on my MacBook Pro?
I'm having many odd problems associated with using Samba at work (where PCs and linux boxes rule & Macs are shunned). I hear the samba version that ships with the latest OS X (I have a 17" MacBook Pro running 10.6.2) is kind of out of date and was ho
-
Customize X Axis range in Stacked Line Graph
I have built a stacked line graph. The values on x-axis range from 0 to 5,00,000. Howvever when the graph is displayed the maximum range that is shows is around 90,000-1,00,000. Is there a way to select specific values for X-Axis. Thanks, Mitiksha
-
Hi All, I am using XML publisher APIs to generate reports. For a particular table the report shows a single record but when I run the query(used in the data template) in SQL plus it retrieves 3 records. The RTF template has a FOR-EACH statement and t
-
Hi, Where can i find the SQL queries(unsolved) through which i can learn to write complex queries... As I am a novice programmer it would be better if the range varies from easy to complex ones. Thanks in advance. Mythili
-
Since Mavericks, I can't mount ISO files on my Mac over a network
Since upgrading to OS X Mavericks, when I want to mount an ISO file on my Mac from my Windows 8.1 PC, I get an error saying it can't mount it. I have to copy the file to the PC to mount the ISO file. Is this due to how Mavericks switched from AFP/SMB