Logon Groups in ABAP system

Hello All,
I have set up SLD on my J2EE Web AS to connect to my newly installed ABAP 2004s system. After the set up in RZ70, I am able to see my ABAP system listed in the "Technical Systems-> WebAS ABAP" in my J2EE engine's SLD.
Now, I am trying to set up JCO connections in webdynpro content admin. And I can't see a logon group in the wizard.
Do I need to create a logon group in my ABAP 2004s system? If yes, how do I create one? Do I need to add any users in the logon group? I am a novice about logon groups, is it similar to a member group in portal? What other settings do I need to give to this newly created group (if one needs to be created).
Thanks,
Ky

Thanks Michael. I created a logon group ("MYLGNGRP") and published to SLD using RZ70. Now I can see the logon group in my SLD in the message server settings.
However, when I create a JCO destination and "Test" it, I got the below error.
[code]com.sap.mw.jco.JCO$Exception: (102) RFC_ERROR_COMMUNICATION: Connect to message server host failed Connect_PM  TYPE=B MSHOST=XXXX GROUP=MYLGNGRP R3NAME=NSP MSSERV=sapmsNSP PCS=1 ERROR       Group MYLGNGRP not found TIME        Mon Mar 19 18:17:58 2007 RELEASE     640 COMPONENT   LG VERSION     5 RC          -6 MODULE      lgxx.c LINE        3515 DETAIL      LgIGroup COUNTER     1 [/code]
Is there any configuration that needs to be done on MYLGNGRP?
Thank you,
Ky

Similar Messages

  • How to use logon group of backend systems via reverse proxy

    Hi
    we have setup EP 6.0 in DMZ2 and connected backend servers in INTERNAL network. We have another firewall for DMZ1. In order to provide access to EP and respective backend systems, we have installed two reverse proxy servers on Apache, one in DMZ1 and another in DMZ2. We could able to reach to the backend system successfully in this setup by using proper rewrite rule for virtual systems in order to connect to multiple systems.
    However we have observed that connection for backend systems is established only to respective CI and not to any of the application server, even though we have created "Load Balancing" systems in EP and used the same logon group of backend systems.
    Kindly suggest us if there is any option using which we can establish connection via Load balancing option in this current setup of ours.
    Thanks
    Pradeep

    Hi Mechael/Dutt
    We r using Integrated ITS in WAS 6.40. and we r maintaing seperate entries for each systems in rewrite rule.
    Thanks
    PRadeep

  • How to create Logon groups for JAVA Systems

    Hi,
    I am implementing an BI JAVA Landscape. We do have 1 Central Instance(CI) and 2 Dialog Instances (DI) JAVA Standalone. Everything based on NW04s
    I have set up a Web Dispatcher to do a load balancing. The Web Dispatcher is connected to the Message Server (MS) of the JAVA CI to get all the information about the Engines.
    I am now looking to create Logon groups to distibute the load according the application used applications. I am not sure if there is a possibility to set up logon groups (server groups) directly somewhere in the J2EE engine, or if I have to set this up in the WebDispatcher konfiguration files?!
    Thanks in advance and best regards,
    Dominik

    We're trying to do something similar with NetWeaver CE 7.1.
    According to [this documentation|http://help.sap.com/saphelp_nwce10/helpdata/en/45/3dbe11a82b6bf1e10000000a1553f6/frameset.htm] there are 3 steps to doing this for NetWeaver CE 7.1:
    1. Logon Groups
    2. Web Dispatcher profile changes
    3. HTTP Provider property changes
    We've set up a Logon Group in the NetWeaver nwa and associated the two instances (one host) with it.
    "[Configuring Logon Groups Using Configuration Files|http://help.sap.com/saphelp_nwce10/helpdata/en/45/3c3f0cad9f4c2de10000000a1553f6/frameset.htm]" says: "...to create the files using HTTP Provider service."
    There it doesn't say exactly how to generate those 3 text files; it says: "1. Create the icrgroups.txt and urlinfo.txt files that define the logon groups. For more information, see the documentation of SAP Web Dispatcher." ; but, has no link to what it says to see.  So, I manually go to ["SAP Web Dispatcher", "Assigning Logon Groups"|http://help.sap.com/saphelp_nwce10/helpdata/en/b4/9aa8862e714e6db8e74e48e5d3283b/frameset.htm].  But, it all pretty much breaks down there because it's referring to apparently non-NetWeaver CE 7.1 stuff (as near as I can tell); for instance, how do the transactions SMLG and SICF relate to NetWeaver CE 7.1, or am I in the wrong place?
    I tried to press ahead with files similar to the examples here, but I hit this error in the Web Dispatcher:
    [Thr 5132] *** WARNING => ICT: path prefix /Curam/ not allowed in this context. Only prefix / allowed. [ictxxptab.c 764]
    [Thr 5132] *** WARNING => When a file is specified in wdisp/J2EE/url_map_location only URL prefix '/' is supported. See also SAP note 1033470. [icrxx.c 2925]
    The note reference looks hopeful, but I cannot read it; I get:
    Note 1033470  
    The requested SAP Note is either in reworking or is released internally only
    Does anyone have a copy of this Note or knows if it's helpful?
    Has anyone done this with NetWeaver CE 7.1?
    Tahnks,
    William

  • How to logon the j2ee engine with logon group

    hi everyone,
    I have installed an HA j2ee engine system with MSCS.
    But i donot know how to logon the DI&CI with logon group like ABAP system
    Thanks very much
    Regards
    Peter

    http://help.sap.com/saphelp_nw70/helpdata/EN/b5/e8239ef7bd494f896a84625d4b688f/frameset.htm

  • How to allow login using email address (ALIAS)  to Abap system

    Hi,
    we are developing some Abap Webdympro to logon to an Abap system, release Netweaver 731, in order to allow our end user to logon via Internet browser to this system.
    So our Abap system is acting like a Portal system, but it's not a J2EE system, it's just a Netweaver Abap system with the following components installed:
    SAP_BASIS
    SAP_ABA
    PI_BASIS
    ST-PI
    IW_BEP
    SAP_BW
    UI2_700
    UI2_701
    UI2_702
    UI2_731
    UI2_FND
    UI2_SRVC
    UI5_731
    UISAPUI5
    UI_INFRA
    No SSO is configured on the ABAP system, and no connection to the LDAP directory is in place , and it is neither  foresee.
    In this moment we are able to login with the user-id of the user we created into the SU01, butt we would like to allow the access using the ALIAS of the users too.
    The ALIAS of these users is like '[email protected]'.
    We did some test but trying to logon we recive always the message:
    "500 SAP Internal Server Error
    ERROR: System logon form fields have invalid values (termination: ERROR_MESSAGE_STATE)"
    On the network I'm able to find only post related to this issue using a J2EE portal, but nothing using an ABAP system as Portal.
    Any idea ?
    Regards

    Hello Arul,
    welcome to the SDN CRM Development forum.
    1. I think you should clear the data with duplicate E-Mail adresses in the external tool.
    2. Unsubscription could be done by a Marketing Attribute which could be set by using a Target Group which is created by Campaign Automation. Have a look at this Toppic. There is also a Best Practice avaliable at http://help.sap.com/bp_crmv340/CRM_DE/index.htm.
    3. Also HTML or Simple text can be mained in a Marketing Attribute. You have to use different Mail Forms to which are sent to different Target groups.
    Regards
    Gregor

  • How can I login ABAP System of the EP System?

    Hi experts.
    I installed EP system, which from "as ABAP" and "as java","as EP" composition.
    i can use j2ee_admin normal logon EP (http://myportal:<port>/irj/portal),But i don't create new user,
    ume.persistence.data_source_configuration = dataSourceConfiguration_abap.xml
    i can't contact ABAP System by SAPGUI which  Application Server: myportal<IP>,SYSID:000
    SYS number: 01
    i want to logon on the ABAP System of the EP,How should I do?
    Best Regards.
    dingding lee

    Hi Karl Rigen ,
    yes,i just installed EP component :"as ABAP" and "as java","as EP".
    j2ee_admin login ep in screen shown,
    System Administrator->System configure -> UME configure
    SAP system
    UID:SAPJSF
    Specific application server connectivity
    Application server:localhost
    i click test connect  display "successful".
    need i  installed other ABAP systems ?

  • Logon group PUBLIC ?

    I've installed the latest NW2004s SP11 and created a logon group PUBLIC in MSLG but I can't logon with that group.
    Even when I try to create a proxy in VS2003 and .netNCO, the wizard tells me that there is no PUBLIC logon group  on my msg server.
    Is it possible, that this feature is disabled on the trial products ?
    Best regards,  Harald.

    check this weblog by Thomas Jung
    <a href="/people/thomas.jung/blog/2006/02/08/as-abap-sneak-preview-lessons-logon-groups">AS ABAP Sneak Preview Lessons: Logon Groups</a>
    (Particulary the paragrah titled "The Message Server")
    Raja

  • J2EE logon groups in an ABAP+JAVA system

    Hi,
    We are trying to restrict java calls to specific App servers in our ABAP+JAVA system. So if we have 5 App servers, we want all J2EE requests to go to 3 Apps only.
    We are using SAP web dispatcher for this purpose. When checking on SAP help site, it suggested two options.
    1) Configuring Logon Groups on AS Java
    2) Configuring Logon Groups Using Configuration Files
    Which of the above would be a better option for ABAP+JAVA system?
    Has anyone implemented this before? If yes, can you share your experiences/lessons learned??
    Thanks.
    Fahad

    1. Log on to the ABAP system.
    2. Call transaction SPRO.
    3. Go to SAP Solution Manager Implementation Guide -->
    SAP Solution Manager --> Basic Settings --> SAP Solution Manager
    System --> General Settings --> Client Copy
    4. Perform the following steps:
    a) Maintain Profile Parameters
    b) Create Client
    c) Copy Client 000
    d) Convert UME

  • Send Idoc's to R/3 System with logon group

    Hello everybody,
    I have the next scenario
    Sender R/3 Idoc -> XI -> Receiver R/3 Idoc
    now I have a doubt, the receiver system has a logon group, is there any benefits for me in XI to use the logon group to send the Idocs to this system?, and if it's better to use logon group how can I use it, juts by defining the RFC that exists in SM59 that points to the receiver R/3 system in XI as load balancing and pointing to the logon group????, thanks in advance for your answers.

    Julio,
    Yes you are right, load balancing can be achieved using logon groups in the RFC destination for the IDoc adapter. It basically enables the ABAP dispatcher to decide whats the best available application server to process the inbound message sent by PI.The purpose is to load-balance successive connections across a group of ECC application servers.
    To do this a connection is established through the message server (the central ECC instances communication process) to determine which ECC instance is to handle the RFC call.
    The key parameters here are:
    u2022     the hostname, on which the message server process runs,
    u2022     the system name of the ECC central instance, and
    u2022     The logon group, which indicates the cluster of applications servers that an ECC instance will be selected from, to serve the request.
    Greetings,
    Gerardo.

  • Java connector calls against sap system with logon groups

    hi there.
    i want to use java connector to connect to a sap system and run a function. my problem: the sap system has more than one instance and i do not want to connect against the central instance. i want to use a logon group. does anyone have an idea how to handle this?
    thanks,
    martin

    hi,
    check this
    http://help.sap.com/saphelp_nw04/helpdata/en/f6/daea401675752ae10000000a155106/frameset.htm
    http://nwadave.com/NwadExplorer/data/SAPDoc/architecture/SAP-Client_LogonAndCommunication.doc
    let me know  u need any further info
    bvr

  • How to create logon group in a JAVA only system?

    We have a JAVA-only CI and several JAVA-only application servers.
    They are all for a single EP7.
    How to make sure that no end EP7 user can use CI ?
    Thanks! Points!

    Hi Jeff,
    You might want to check the following documentation for setting up logon groups on your AS Java environment using NW Administrator tool: <a href="http://help.sap.com/saphelp_nw04s/helpdata/en/a9/775a421b5ec153e10000000a1550b0/frameset.htm">Logon Groups Configuration</a>
    You can also check this <a href="https://www.sdn.sap.com/irj/sdn/thread?threadID=384105">thread</a> which might apply to your environment.
    Hope this helps.
    Regards,
    Joseph

  • Issue with parallel operation of SAP NW SSO 2.0 and SNC Client Encryption (Logon Groups)

    Hi!
    One of our customers is using the SNC Client Encryption solution to ensure encryption using SNC (based on Kerberos Technology) for their SAP GUI Dialog connections. They have lots of SAP backends DEV, QAS, PRD all with the SNC Client Encryption SNC Lib installed. The profile parameter snc/identity/as contains the following value: p:CN=SAP/<ServiceAccount>@<DOMAIN>.
    Example: p:CN=SAP/[email protected]
    The customer is using one AD Service Account "SNCServiceUser" with one registered SPN "SAP/SNCServiceUser" for all systems (yes, this is not recommended... but the case).
    Important: All users use group entries in the SAP Logon (saplogin.ini). Means, for SAP logon the SNC name can not be manually configured on the SAP Front End. With group logons, the application server's SNC name is dynamically requested by the message server each time a SAP GUI connection is started. The SNC Name is greyed out in this case as dynamically obtained from the applications servers profile parameter snc/identity/as.
    Now our customer implements SAP NetWeaver Single Sign-On 2.0 within his landscape. Based on the Secure Login Server 2.0 (SP3) he likes to use X.509 based authentication to his AS ABAP backends using SAP GUI SNC while others still use SNC Client Encryption.
    Replacing the SNC Library on the AS ABAP
    The Secure Login Library 2.0 (SP3) has been installed on one of the ABAP systems and the SNC Client Encryption SNC Library (which is based on SSO 1.0) is no longer used, thus we changed the parameter snc/gssapi_lib to point to the new SNC library. We removed the old PSE.ZIP containing the keytab and created the new SAPSNCSKERB.PSE incl. the keytab and proper credentials. To ensure parallel operation, we kept the snc/identity/as value as is =  p:CN=SAP/[email protected].
    After restarting the system with initialized Secure Login Library 2.0, still the SNC client encryption works fine for existing users.
    The problem
    We created on the Secure Login Server an SNC certificate for the AS ABAP which has the following X.509 Distinguised Name Fomat: CN=SAP/[email protected] This is to avoid having to change the snc/identity/as to an "real" X.509 DN which would lead to non-working SNC Client Encryption for all the other users using SAP GUI and logon groups.
    As soon as we install the PSE via STRUST on the system the SNC Client Encryption solution stops working with error „Server refuses kerberos key exchange“.
    As part of an pilot implementation we have installed Secure Login Client 2.0 (SP3) on some test PCs. The test PC with SLC is able to perform Single Sign-On with SNC based on X.509 (incl. Encryption) to the ABAP system.
    Seems the SAP System now only tries to do X.509 based authentication thus key exchange fails. The problem is, we cannot change the snc/identity/as value because of the logon groups. If we were able to do so, we would in any case set the server identity to X.509 DN and in addition create the SAPSNCSKERB.PSE incl. keytab. This should work, as confirmed by SAP see this post.  
    Any ideas how to solve this and have both solutions in parallel?
    Appreciate any help.
    Regards,
    Carsten

    Hi all,
    we was able to fix the issue. It was an issue with the customers cluster configuration and the  $SECUDIR variable. This tricky issue leads to non working or sporadic working SNC Client Encryption...
    This was how the configuration looks before:
    Environment variable $SECUDIR is defined:
    "/ABCDEF<SID>/usr/sap/<SID>/DVEBMGSxx/sec“
    sapgenpse seclogin -l -v
    running seclogin with USER="<SID>adm"
    Credentials for username '<SID>adm':
    0 (LPS:OFF):
             (LPS:OFF): /ABCDEF<SID>/usr/sap/<SID>/DVEBMGSxx/sec/SAPSNCSKERB.pse
    1 (LPS:OFF):
             (LPS:OFF): /usr/sap/<SID>/DVEBMGSxx/sec/SAPSNCS.pse
    After changing the $SECUDIR to "/usr/sap/<SID>/DVEBMGSxx/sec“ and re-creating the credentials, it worked like a charm.
    As a result of this we can confirm, this configuration and SNC Client Encryption works with CommonCryptoLib in parallel to the SSO configuration.
    And Valerie was right with 2. SLC starting from V. 1.0 SP2 PL3 was able to convert the CN= part of the SNC Name into an SPN, was my mistake. In addition SNC Client Encryption starting from Version 1 SP1 PL1 does this also.. just to make this clear
    Thread closed hope this helps someone
    Carsten

  • Need help in creating webas abap system

    hi
    new to create jco and techinical system need help
    experts  i have few faqs on creating techinical system plz help me
    i have 4.7ee r/3  and portal 2004s  sp9
    wer can i find these values plz give me navigation
    SID ==  ?
    MESG SEVER PORT ===?
    to add application server
    application host name ==?
    application instance number ==?
    client number ==?
    logical client name ==?
    it is asking to select a software component wat we have to select to finish
    wen i gave some dummy values
    i get an error
    CIM_ERR_ALREADY_EXISTS: Instance already exists: SAP_BCApplicationServer.CreationClassName="SAP_BCApplicationServer",Name="C11.Number.00.HostName.rama"
    is it necessary to have WAS in r/3 to connect to portal plz explain

    i want to use jco
    but for that we need to create a techinical system
    i followed these steps for techinical system
    1 Step
    selected web as abap
    2nd step
    sid = PRD
    installation number== INITIAL
    database host name== super
    3rd step
    message server name = 3600+instance
    i took system number from sap gui(21)
    so i gave 3600+21=3621
    central application sever
    instance number ==21
    next pressed button -->add new logon group
    entered longon group == entered value
    which i found in t-code -smlg
    4th Step
    Add application server
    host == gave r/3 ip 198.168.0.2
    instance==21
    client number = 800
    logical client = left it empty
    5 th step
    selected one componenet and finished
    after this i created the jco
    1st Step general data
    name =test1
    client=800
    2nd step  j2ee cluster
    checked the box
    use local j2ee engine
    3rd step
    selected dictionary meta data
    4 th
    selected the techinical system
    5th
    user name -->sapuser
    pasww-->india
    pressed finish
    now i found the jco in green color
    but i pinged it 
    i got mesg
    ping failed

  • Logon Load Balancing / Configuring Logon Groups problem

    In existing system setting:
    One Logon group (PUBLIC) and point to one instances.  This setting is work and SAP LOGON default clinet no is 320.
    I try to install one more instances on other server and add to same Logon group (PUBLIC).
    Install compent as below:
    SAP ERP 2005 Support Release 2 -> SAP systems -> MS SQL, Server -> High available system -> Base on ABAP System -> Dialog System
    The instance has been installed and start and stop this instance is successful.
    Add instance into logon group (PUBLIC)
    Logon system via logon group, the logon redirect to new instanace server. But the default client no has been changed from 320 to 001. Change client from 001 to 320 and logon. But no response from new instance server.
    Any suggestion to solve this problem.
    Thanks!

    I found the profile in profile directory as below:
    default.1.pfl
    COQ_D02_BSSPI11   (New Instance)
    START_D02_BSSPI11  (New Instance)
    COQ_DVEBMGS02_bssco11     (existing Instance)
    START_DVEBMGS02_bssco11  (existing Instance)
    I strat the new instance and add to Public group and logon successful.
    The problem is in transaction RZ10.
    I cannot select COQ_D02_BSSPI11  and START_D02_BSSPI11  profile from Profile field.
    how to fix it.
    Thanks!

  • Connection to ECC with SAP Logon Group failing

    I'm creating a new system connection to an ECC backend using a logon group (transaction SMLG in ABAP stack).  I have created the connection with the wizard as a SAP_R3_LoadBalancing connection and given it the appropriate Group, Logical System Name, Message Server, Remote Host Tppe and SAP Client.  Also I've given it an Alias.
    SSO is working correctly between the portal and ECC.
    The System Connection Tests > Connection Test for Connectors works, as can been seen::
    Test Connection with Connector
      Test Details:
    The test consists of the following steps:
    1. Retrieve the default alias of the system
    2. Check the connection to the backend application using the connector defined in this system object
      Results
    Retrieval of default alias successful
    Connection successful
    However, if I try to connection to this system with the Alias, it fails.  If I change the alias to a system with a standard R3 connection with a specified hostname, it works.  The /etc/services is correct and contains the appropriate entries.  Any ideas?
    Regards,
    Graham

    Hi Srikishan,
    Thanks for the response. When user from CRM logged in another language than EN for eg. FR, clicks on external link in CRM, takes to EN, only if that language FR is not installed in ECC, else it will take to the same language in which CRM user logged in. This cannot be controlled in SSO configuration. Is this correct?
    In case if FR is installed in both the systems, ie CRM and ECC, but user wants to log only to EN when clicked the external link(to ECC) from CRM, how we can configure this, Is any parameter can control or SSO setup configuration available? Please advice.
    Regards,
    Shahul Hameed

Maybe you are looking for

  • Why can't I download Shockwave 11 on Windows 2000

    I have a Windows 7 but I'm trying to update some plugins that keep popping up on every page that loads on my mom's computer saying it needs updating. (The computer only runs slow when it pops up which drives me crazy) She has a Windows 2000 and Shock

  • Data import from ASCII file : javasript to determine correct account

    Hi, I am importing data from an ASCII file and need to use a conversion file with javascript to determine the correct account depending on the amount I am importing. As an example: If external account B4711 carries an amount of 1000 it needs to be im

  • Wobbling Display

    Hi All I am using a Proview 19' CRT monitor with my G5 Mac. The resolution is set at 1600 X 1200. Recently (the past 2-3 days) the picture goes all wavy at the bottom of the screen for a few seconds when I switch to/from edit mode in iPhoto and every

  • MBP fan behavior question

    Hi, Looking to (finally) upgrade my Powerbook G4. This is a very quiet machine, and the fans only kick in when editing video, playing games, etc. So I am wondering... Is it true that the new Macbook Pro fans are on all the time? Are there any models

  • XML IDoc conversion: No known segments identified ,only few times

    Hi all, Our scenario is in production and is working fine,few times i get the below error. This is a Daily run scenario.This week it ran 5 time right and 2 , times it failed  to create Idocs for the same sccenario. Can any one help me. <SAP:Category>