One Portal user has several user in other systems - how to handle SSO

Hi,
I read a lot through several threads but could not really find the information that I need:
Problem:
Each PERSON has ONLY ONE unique portal user to log in. In SAP SRM / EBp these persons sometimes must have multiple users. Normally they login in than with TIMO1 or TIMO2 etc..
But how can we handle that with SSO?
The SOO cookie will always login only one explicit user.
Such that I thought about a BSP application or something in-between: Portals opens this custom application via SSO. The application deletes the SSO cookie and depending on the selected user it will login the user to EPb / SRM.
Who has any Ideas how to realize that. Or is there a better possibility for that?
Thanks for HELP
TIMO

Hello Guys ...
thanks for the posts, but I think I did not make realy clear what I need:
SOO works fine, that is OK.
But I need to login from the portal, being loged in as user 1243243 (we use numbers) into EBp (SRM) as JOHN or JOHN2. Depending on the company I would like to shop for.
I am aware of the fact, that SAP Portal offers something like user-mapping. But we would like to avoid aditional maintenance in the Portal area (internal reasond). So user-mapping in the portal is no option.
I think I realy need such a "LOGIN APPLICATION" inbetween
PORTAL - LOGIN APP - SRM
Thanks 4 your help!

Similar Messages

  • Webdynpro - Check if a portal user has a user in R/3 Backend

    Hi Experts,
    i have following problem, and maybe some of you can help me out with an idea or (much better) a solution:
    Our Company is running an Enterprise Portal on NW2004s (SPS 18). Currently i am developing a Java WebDynpro Application for the portal called Transactionstarter. Withhin this application a portal user can simply add a backend System (R/3), a transaction and a Description. This information will be stored in a xml file in userhome in KM. When the user clicks the description, SAP WinGui will open with the transaction he defined before. We use SSO for opening the transaction if the user has a backend user. If not, the loginscreen of the backend will appear.
    All this works fine.
    Now we have the requirement for an automated system check.
    The portal user can run an initial system check. This system check should check all configured backend systems if the portal user has a user in R/3 backend.
    But how can i check if my portal user exists in backend?
    I cannot use JCO because we have a lot of Systems (more than 300 all together) and i don´t want to create a destination for every system. Or did i misunderstood something with JCO?
    Does anyone of you have a solution, how i can check every system, if the portal user has also a backend user?
    Thanks in advance.
    Regards
    Pascal

    Hi Pascal,
    with JCO you can use also the method JCO.createClient:
    public static JCO.Client createClient(java.lang.String client,
                                          java.lang.String user,
                                          java.lang.String passwd,
                                          java.lang.String lang,
                                          java.lang.String mshost,
                                          java.lang.String r3name,
                                          java.lang.String group)
    Creates an instance of a client connection to a remote SAP system (with load balancing)
    Parameters:
    client - SAP logon client
    user - SAP logon user
    passwd - SAP logon password
    lang - SAP logon language
    mshost - Host name of the message server
    r3name - Name of the SAP system
    group - Name of the group of application servers
    Returns:
    the newly created client
    for connections to other systems. So you can avoid to create destinations
    Regards
    Matteo
    Edited by: Matteo Fusi on Apr 1, 2009 11:33 AM

  • Apple recently merged all my devices so that if I miss messages or facetime calls on one device, they get forwarded to my other devices. how do I UNDO this so this no longer happens?

    Apple recently merged all my devices so that if I miss messages or facetime calls on one device, they get forwarded to my other devices. how do I UNDO this so this no longer happens?

    If you don't want them to be unified, don't use the same Apple ID for FaceTime and iMessage on our devices.  Go to Settings>Messsages>Send & Receive, tap the ID, sign out, then sign back in with a separate ID.  Do the same thing in Settings>FaceTime.

  • How do I use one iTunes library for several user accounts?

    This is definitely a question!
    I have several user accounts for my osx. One I use at home, one at work etc.
    What I never have been able ta manage is a way to use the same iTunes library (the same music files) for the different accounts.
    When a new user profile is created, everything in it is set to scratch.
    I have tried all kinds of tricks:
    - Direct iTunes to look for It's library on the other users folder (wich doesn't really work, cus even if you are Admin you don't have access to other users folders through another user).
    - Creat an alias for the other library-folder and refere to it.
    etc. etc. You name it...
    Anyone?

    Hi,
    This will help you - http://docs.info.apple.com/article.html?artnum=93195
    Regards

  • Is there a way of making one portal instance serve several domain names ?

    We have one Portal instance (3.0.8) that contains one Intranet, one Extranet and 5 Internet sites (Page hierarchies). After redirecting calls to the diffrent domains (sites) to their corresponding Portal page in the webserver, the URL reveals that we are actually running all these sites on the same Portal domain. I know that we can change the Portal domain by running the ssodatan script, but is it possible to have one portal instance work for several Portal domains ? I realise that this is probably far fetched, but I just had to ask... This will not create a big problem for us, it's mostly an esthetical issue.
    Morten

    Yes you can do this.
    Your machine must have multiple IPs with a different name associated with each IP.
    Look at the ssodatax scripts. This script allows you to make additional entries into the login server repository to register new names with the login server.
    Add each name using the ssodatax script and you will be fine.
    Rich

  • I have 2 Apple ids and two corresponding iCloud accounts. My five Apple devices are linked to one or the other. As one consequence a small number of my contacts are associated with one iCloud account, the majority with the other. How can I merge?

    For reasons not entirely clear to me I have ended up with two Apple ids, two iCloud accounts and my Apple devices being associated with one or the other iCloud account/Apple id. One of the complications is that my contacts are partially owned by one iCloud account, partially by the other.
    Is there any way to
    - merge the contacts (I have tried exporting from one and importing into the other but one set will overwrite the other)?
    - migrate all devices to one single iCloud account without being locked out for 3 months?
    - merge Apple ids or just delete one of them without locking out devices?
    Grateful for any suggestions because this is turning into a headache.

    You can merge the contacts from one account with your other one without overwriting them.  Sign into the first account, download them as vCard (iCloud: Export contact information as a vCard), email them to a device signed into the account you want to merge them with, tap the vCard and choose Add..., then Create New Contacts.
    You can also migrate a copy of the data in one account and merge it with the other by signing into the account you are leaving, then signing out (or deleting the account if not running iOS 8), then choosing Keep on My iDevice when prompted.  Then sign into the other account and choose Merge when prompted.  This won't move Notes however.  If you are syncing notes that you want to migrate from the other account, you can temporarily add the account to your Mac as a secondary account by going to System Preferences>Internet Accounts (or Mail,Contacts,Calendars)>Add Account>iCloud and signing in with the other account ID.  Then enable notes syncing in the secondary account.  You will then be able to open the notes app and drag and drop notes from one account to the other.  When you're done, delete the secondary account from your Mac.
    You can't merge IDs as Apple does not allow it.  Also, you won't be locked out of anything for 3 months.  The "90-day switch" rule only applies to changing your iTunes store account, not your iCloud account.  Just leave your iTunes store account as-is.  The ID you use for the iTunes store does not have to be the same as the ID you use for iCloud.

  • Screen Variant  , user has dif field than others

    Hello All,
    I have three questions, which are related to each
    1-I wonder what is the differences between Screen variant(IE FB50 you can define screen variant) and user parameter SU3 or SU01D  as in
    SPRO Tcode  O7E6 based on some FB50 Field( GL entry ) you can define user parameter and select Field for
    Also as third one we can define variant for tcode under  SHD0, I thought if you create the Var under
    this option it should be available in FB50 as well -which they are- but when I am
    looking at FB50 variant selection I can see more than what I can find under
    SHD0, why is that?
    2- I have user that her screen in FB50 is different than
    anybody else, her screen columns are few (she doesn’t have Value date Field), I
    asked her to reset the screen var(over phone) but seems she still has issue. Any
    help please?
    3- I copy her ID from Prod to QA; I have all column and Field
    that she is looking for not sure if user parameter or screen var comes when basis
    refresh QA from Prod
    Thanks for your help,
    Hamid

    hi sri,
        Transaction code : <b>SHD0</b>
        First you have to create a screen variant.
        Second you want tp assign the screen variant to the
        transaction variant.
        thrid you can assign it to the specific user in the
        standard variant.
       so that particular user only will be having that screen variant.
    Reward points if it is helpful.
    Regards
    Alfred

  • I have two devices on my account : one iPhone5S and one iPhone5 both connected to iCloud. When I deleted 500 contacts on one device they disappeared automatically from the other. How can I get them back

    How can I get back deleted contacts from iCloud?

    If both phones were syncing contacts with the same account, that's normal.  iCloud syncs changes on one devices to all other devices sharing the account.
    If you don't have another backup source for your contacts, you may be able to restore them from your iCloud backup by following Winston Churchill's user tip here: https://discussions.apple.com/docs/DOC-4841.

  • Several user account with ID=0

    Hello I find I have a problem:
    My OS X has several user accounts with the same ID, particularly with ID=0. This ID should belong to root user account only.
    Terminal: dscl . -list /Users UniqueID
    daemon                  1
    diegopaniz              0
    Guest                   201
    KEKA                    501
    nobody                  -2
    root                    0
    Someone know how to fix it?
    TKS!!!
    rickricardu

    If you're using "diegopaniz," change the UID to something in the 500 range. Otherwise delete it. You seem to already know how to use dscl.

  • Help, my user has disappeared in login screen except Guest User after updating to 10.7.2

    After updating to 10.7.2, I can not login to system because there is only one Guest User icon. Why my user has disappeared in login screen? How to solve it? I don't know is this related with iCloud?
    Thanks in advanced.

    Solution:
    https://discussions.apple.com/message/16333057#16333057
    Lession:
    DO NOT USE SYMANTEC/PGP SOFTWARE

  • List folders specific user has permission

    Hi, i am from Spain, excuse my bad English
    I have a 2008 r2 file server with more than 100 folders and more than 500 subfolders
    I want to list folders and subfolders that specific user has permissions
    Is this posible?
    How?
    Thanks in advantage

    Hello,
    I have developped one script powershell for my customers. I have uploaded this script on the technet Gallery.
    The link for download it's here
    https://gallery.technet.microsoft.com/Get-a-list-with-the-share-811d1221

  • Is it possible to create a variable that tells you which slides the user has visited?

    Hi there.
    I'm working on a project where I want a slide to show a continue button and hide 2 textboxes, but ONLY when the user has already visited 2 other slides. I can only find variables that tell you the slide the user previously visited.
    Is it possible to set up a variable that does this?
    I want to create the following advanced action:
    If the user has visited slides 62 AND 87, show image_536 and hide text_caption_243 and text_caption_242
    I don't want the action to happen if only 1 of the 2 slides have been visited - it has to happen when both have been visited.
    Hope that makes sense.
    I'm using Captivate 7.
    Thanks.

    You will need two variables, it can be booleans. I'll label them v_one and v_two with a default value of 0
    Since I don't know how the slides are formatted, do you use a Next button or are all the slide frames visited? You'll need to have an event on those two slides to trigger an action:
    Assign v_one with 1     on slide 62
    And a similar action on the other slide to toggle v_two (do not use the toggle command, if the user visits a slide twice, it would be toggled back to 0).
    You didn't specify where those text containers have to be (please, label your objects and slides)? But you'll need conditional advanced action triggered by another event somewhere:
       IF v_one is equal to 1   AND
           v_two is equal to 1
      Show text1
      Show text2

  • Login error: user has expired

    Hello!
    I just install solaris 11.1 on my server and wanna go to install Sun Ray Software install. I`m twice reboot my server while installing soft. And after last reboot I can`t login into my account. I catch message error what my user account has expired. I can`t find any info about this trouble. Can you help me, please?

    Helios- Gunes EROL wrote:
    Hi;
    As mention please share how you create your user, What is os and DB version? your other user has same problem? The user has any role?
    Also see:
    How to Keep the Same Password when Expiry Time is Reached and Change is Required [ID 98481.1]
    Regard
    Helioscreate user abc identified by abc default tablespace USERS temporary tablespace TEMP;
    Linux 2.6.18-238.el5 #1 SMP Sun Dec 19 14:22:44 EST 2010 x86_64 x86_64 x86_64 GNU/Linux
    Oracle Database 11g Enterprise Edition Release 11.2.0.3.0 - 64bit
    Other users don't have problem at this moment.
    He has the roles which granted him select privilges on some tables.

  • Log In screen shows my normal user names and "OTHER". How to remove OTHER?

    My Log In screen (start up box) shows my normal user names and something called "Other". How do I get rid of this Other name?
    I tried deleting "Other" in the System > Accounts, but he is not there.
    Cheers.

    How to disable the root user
    Mac OS X v10.6 and later
    1. From the Apple menu choose System Preferences....
    2. From the View menu choose Accounts.
    3. Click on the lock and authenticate with an administrator account.
    4. Click Login Options....
    5. Click the "Edit..." button at the bottom right
    6. Click the "Open Directory Utility..." button.
    7. Click the lock in the Directory Utility window.
    8. Enter an administrator account name and password, then click OK.
    9. Choose Disable Root User from the Edit menu.

  • Deferent between oem user and admin user

    Hi,
    For the SL500 robot,
    Does any body knows the deferent between oem user and admin user?
    does one of them has privileges on the other?
    Yigal

    Dear all,
    Thanks a lot for all of you.
    I have already set local user and domain user in "Logon as a batch job" security policy on my PC. So I can do jobs well if I set logon user that is a any local user in my PC. I can't do a job if I set logon user that is a domain user. So I don't know what it wrong?
    Should I add domain user in "Logon as a batch job" security policy on AD Server not in local PC's "Logon as a batch job" security policy?
    I don't have privilege to change policy on AD Server. And I have to make sure it will work if add my domain user in "Logon as a batch job" security policy on AD Server. So should I add policy on AD Server or just add in local PC.
    Any idea?
    Thanks and regards.

Maybe you are looking for