Security upgrade question

Hello there, we have just gone through some new installations and upgrades (support pack level.. etc.). We've encountered few problems after this, could anyone of you kindly advise.
After running the program PFCG_TIME_DEPENDENCY in SA38, we received the following warning messages:
"Authorisation profile for role SAP_XXXXX does not exist", and
"Role SAP_XXXXX does not contain a profile or authorisations"
When I further select the message, it navigates me to another message that says "Messages for SU22 and the Profile Generator".
I checked these roles (all are SAP standard roles) in PFCG, and those that do not contain authorisation profile is because the organizational level is not maintained.
Now my question is, do I need to separately go though all these hundreds of roles one by one to maintain the organizational level for them, or is there way to mass-maintain?
Or.. does this have anything to do with SAP_ALL profile regenerate, will that help?
Thank you for answering!

You will probably have PFCG_TIME_DEPENDENCY scheduled as a job already with a variant.
Run it from SA38 via that variant (e.g. all roles "not equal to" SAP* naming convention, etc) if you want to do it manually.
Cheers,
Julius
PS: It might still be interesting to compare the SAP* role menu between the old and the new. Generally, the access changes with SU22 (SAP does this, and you perform the SU25 steps => SU24), but the menu could change as well.

Similar Messages

  • Security upgrade question - Getting 6.1.6 downloaded to iphone.

    Security upgrade question - I have a 4S phone v6.01 with an upgrade to IOS 7.04 already downloaded and ready for install.  I would like to install the 6.1.6 security upgrade instead. How do I delete the ios7 in the queue or have the 6.1.1 pushed as an option to the phone?

    You can't install iOS 6.1.6 on that device and must update it to 7.0.6.
    (101120)

  • New security upgrade

    My IBook G4 will not go to sleep since I installed the latest security upgrade. The screen saver comes on but the Laptop does not go to sleep.

    "Can someone help me figure out how to rebuild my database"
    Hold down the Option key when starting Entourage.
    You may want to direct further questions regarding MS Office to Microsoft's own discussions:
    http://www.microsoft.com/mac/community/community.aspx?pid=newsgroups

  • Roku Photobridge no longer connects to Mac after OSX Tiger security upgrade

    I do the MacOS security upgrades as soon as they come out, and around mid-July, I noticed that my Roku Photobridge (aka HD1000) could no longer connect to my Mac. The error I get on the Roku is "User/Pass OK but read permission denied". Here's what I know:
    - another Mac user on the Roku forum reports the same problem, with roughly the same timing, and he also installed the same security updates
    - the Roku has its own account/user on the Mac, and all the permissions look fine (in fact, they're all 644 if you look at them using the command line)
    - the Roku uses Windows Sharing; I've confirmed that Windows Sharing is on for its account
    * the firewall on the Mac is set to allow Windows Sharing through
    Any ideas or help would be gratefully appreciated!

    Let me add: I've repaired permissions and repaired the disk on the Mac. No joy.

  • Need help on assessment of security upgrade to ECC .0

    Hi,
    I am a security guy and am involving in security upgrade from 4.6c to ECC6.0.  I want your suggestions & contribution on preparing the assement of security upgrade.  So can anybody guide me to follow the security strategies <removed_by_moderator>
    I appreciate your kind help.
    <removed_by_moderator>
    Regards,
    Venkat.
    Edited by: Julius Bussche on Mar 12, 2008 8:31 AM

    Best start will be transaction SU25 and its documentation in saphelp.com
    And no, I will not e-mail you anything, this is a forum, where we share knowledge so the other visitors can benefit as well.

  • I can't send mail after last security upgrade

    I haven't been able to send mail using the mail.app via Charters STMP since I applied the last security upgrade from 10.4.6 to 10.4.7. Any ideas?

    I've tried rebooting the computer. Resetting the cable modem. Spoke with Charter and it's not on their end. So I'm stumpped. Any clue?
    Thank you in advance.

  • Not able to get rid of security-related questions in runtime

    Hi,
    I am simply using NetBeans 6.0.1 and the emulator QwertyDevice and the emulator platform WTK 2.5.2 for CLDC.
    I have chosen Alias as trusted in the signing option in the project configuration page. however still I am getting security confirmation questions in runtime to access the local files for instance.
    Would anyone please advise me how to get rid of that?
    Also I have deployed the application on SonyEricsson k800i and would like to get rid of the security confirmations on that device as well. What is the guideline?
    Thank you

    Right clicking on it is not even an option, just hovering over it seems to induce a "nuclear" reset of the whole desktop and graphic card on the iMac.
    Have meanwhile found a possible solution by erasing the dock preference file in the user/library/preferences folder to reset the dock to it's default state. Will try this out through a Skype conversation with that Buddy.
    Was seen here :
    https://discussions.apple.com/message/16447109#16447109
    Thank you for stepping in. Good to know that people are still willing to help in this community.
    Greetz to the UK from France

  • Anyone else having problems with popups since the new security upgrade? can't get rid of them

    anyone else having problems with popups since the new security upgrade? can't get rid of them

    You may have inadvertently installed adware. You do not need to download or install anything to fix it. It ought not to be related to any Apple security update.
    For a description of how this may have occurred, how to avoid it in the future, and for Apple's recommended actions read How to install adware. Apple's instructions are linked in the Recovery Procedure near the end of that document. Read and follow them carefully. Pay particular attention to the easily overlooked passages directing you to restart your Mac when required.

  • I foreget my  security answer questions. --app store

    I foreget my  security answer questions . --app store
    I can not buy any thing without answeing this questions
    Pls help me to repair this problem

    Q - Can I change the answers to the security questions for my Apple ID?
    A - Yes. You can change the answers to the security questions provided when you originally signed up for your Apple ID. Go to My Apple ID and click Manage your account.
    http://support.apple.com/kb/he37
    Manage your Apple ID -
    https://appleid.apple.com/cgi-bin/WebObjects/MyAppleId.woa/

  • HT4312 I am trying to install facetime on my macbook but I get a message I need a security upgrade 2010 005.  My search for updates does not show that I need any such upgrade.  What's the deal here?  David

    I am trying to install facetime on my macbook but I get a message stating I am missing a critical security upgrade 2010 005.  However when I search for upgrades the upgrader says I have all current software.  Catch 22.  What do I do?

    Which version of Mac OSX do you have?
    Firefox 2.0.0.20 is the last ever release for Mac OSX 10.3.9 and earlier versions.

  • Appleworks crashes after security upgrade

    I successfully ran Appleworks 2 weeks ago. I did a "security upgrade" today which updated many files. Now I cannot open Appleworks for a new file, for my 2 week old file, or even on the templates. The starting window comes up and immediately crashes. I deleted the preferences file and the com.apple.appleworks plist. I checked that I have Bauhus 63?? or whatever font was suggested as a problem. What more can I do?

    Welcome to Apple Discussions Margie
    With thanks to Barry, whenever you do an update, it's a good idea to do two maintenance tasks, one for the system (Repair Permissions) and one for AppleWorks (delete preferences).
    To Repair permissions in 10.4.x, launch Disk Utility, found in the Utilities folder in your Applications folder, click on First Aid, then on Repair Permissions.
    (Also explained in my user tip, AppleWorks has stopped working correctly.)To delete AppleWorks’ preference files, go to HD > Users > Library > Preferences. Find and delete the file com.apple.appleworks.plist. Find and open the folder AppleWorks in this Preferences folder, then delete all of the enclosed files (with the exception of the Button Bar Preferences if you have customized the Button Bars). AppleWorks will recreate the preference files as it needs them.
    The security update won't install Bauhaus 93, so if you have it, you probably had it before &, since AppleWorks was working correctly before, I would guess that you have the newer, not-corrupt, version from Word 2004.

  • G5 Xserver won't restart after security upgrade

    I recently installed a security upgrade on my server. Stupid me, I didn't back up the server (no problems before, right?). Rebooted the server, and now it won't boot up. Here's what I've tried...
    1. Starting in Firewire Disk Mode - won't work, I have an a Apple Raid card installed.
    2. Tried restarting from Install cds.
    OK, here's another problem. My server is headless. So I go to the local CompUSA and buy an ATI Radeon 7000 - cheap PCI video card, should work with my Mac, right? Nope.
    Then I head to Fry's and purchase an ATI Radeo 9250. I know they make a Mac model (9200), so this should work, right? Arggghhh, nope. Guess I'll have to buy the Mac Edition. But I thought I'd try the discussion boards one more time...
    Even so, I reviewed the "Headless Installation" instructions, but it doesn't show up as having the install disk inserted.
    3. Tried connecting my MacBook Pro via firewire and try to Apple Desktop Remote In - no luck.
    4. Try to SSH in - says Host is Down.
    Now, this server isn't really mission-critical, so losing everything doesn't overly bother me, but I really want to save this if I can. In the past, I've found I've learned a lot when these things happen.
    G5 XServe   Mac OS X (10.4.8)  

    Brent,
    It might not be the security update that hosed your server, but instead might have been the Apple Hardware RAID card. I troubleshot a difficult-to-find bug on our Xserve G5 when it was being tested prior to deployment, and the problem turned out to be the Apple Hardware RAID card. Turns out, there is a bug in the firmware whereby the Apple Hardware RAID sometimes disconnects from the drives during graceful power down (but not on a restart) before it has finished fully flushing the write caches. LSI Logic fixed this bug in subsequent firmware that only works on their Windows version of the card (the Apple Hardware RAID card is a rebranded LSI Logic megaraid card); Apple split their code off the LSI code tree prior to this fix, and hasn't updated their version of the firmware that was created for the Xserve version of the card.
    Causes mystery garbage blocks from space. Only workaround that I know is to turn off the write caches for all LUNs on the Apple Hardware RAID card.
    I turned in a RADAR report (RADAR Problem ID 4350243) back in November 2005, and I keep following up every four or so months, no progress, and I never get any feedback from Apple except a report that the bug is still open. I don't expect this bug to ever be fixed because the Xserve G5 is EOL, as is the Apple Hardware RAID card.
    So, if you happened to shut your server down rather than restart, you could have some garbage somewhere on your disks because of this bug.
    Good luck.
    Russ
    Xserve G5 2.0 GHz 2 GB RAM   Mac OS X (10.4.8)   Apple Hardware RAID, ATTO UL4D, Exabyte VXA-2 1x10 1u

  • Suggested security upgrade did not install and left me with Trojan horses. Was it a spoof?

    Yesterday evening (Oct. 4 2010) a pop up displaying the Firefox logo suggested a security upgrade for users of 3.6. It did not appear to install properly. There was also a box that suggested an associated update for (I think) Adobe, but there was no associated button. I shut down soon after. This morning, Oct.5, my computer brought up and I.E. window and an AVG threat message suggesting that it would forcibly remove a Trojan horse, but that it could cause a system lock. I did and it reported successful removal. My AVG scan is still running but it is reporting 7 Trojan horses and counting. KZUKEA (2868), Generic19.AKRT, VUNDA.LP,

    It sounds like one of the rogue sites. They tell you that you are running an older version of Firefox and that Adobe Flash is out of date. They tell you to download a file called something like firefox-update.exe or ff-update.exe
    That file contains a trojan.

  • Security Upgrade

    Hello Gurus
    In our company we are upgrading from 4.7 to ECC 6.0. I have never done any security upgrade project before. Now I have been asked to come up with a upgrade documentation and plan. I know we can use su25, but its not just a matter of running su25 and upgrade is complete. I know its a cumbersome process and we have about 10,000 roles. Is there any document or pdf available that describes the entire security upgrade process step by step. Can someone please describe me the upgrade process from scratch and what the approach should be? Currently we have R/3 and BW.
    Thanks

    If you've never done it before, I wouldn't even attempt to do it by myself.  Hire a security expert who has done it before and shadow them.  It's too much of a risk to your company otherwise.

  • Security/session questions

    Hi,
    I have some security/session questions for you guys.
    My application uses flex, blazeds and spring. I use RemoteObjects to initiate calls from flex to java. The application consists of a login screen and 'other screens' available only to authenticated users after login. When the user logs in the server stores user credentials on the FlexContext (FlexContext.getFlexSession().setAttribute). So if the server timeout is reached and the user presses 'refresh' the user is thrown out and the login screen appears.
    Question 1: How can I check if the timeout is reached when the user makes a call to the server, without checking manually against the FlexContext. Are there any config parameters to set?
    Question 2: Is it necesssary to check against the user credentials in the session for every flex-to-server call? (I guess someone can omit the login screen and do a manual call)
    Question 3: If the answer to question 2 is yes, how can I check against the session credentials? The only way I can think of is calling a method which checks the session attribute manually, but then I have to remember to add this method call to each of the methods called from flex through Blazeds. Is it, for example, possible to call the user-logged-in method before the method given in the RemoteObject is called? (If not authenticated, do not run method).
    Hope someone got the time to help me out.

    I appreciate your answer, but as you yourself write, I think there must be a blazeDS way. But as nobody with extensive BlazeDS knowledge answers this post, I probably have to google this topic even more.
    Following are the main changes in my application: (Introducing spring security)
    Everything seems to be working as it should. But as already stated, I'm a newbie. So if anybody see something suspicious, let me know.
    The main problem I had implementing Spring Security was something that should be easy, but somehow it was not: the loading of the context files. Before introducing the spring security I only had one application-context file, and this was loaded by the DispatcherServlet. When introducing security I tried to add this to the same file. It did not work. Then I tried splitting up the files, and loading both using DispatcherServlet. It did not work. Then I tried loading both using ContextLoaderListener. It did not work. Finally I found the solution. Flex settings must be loaded by the DispatcherServlet, and spring security settings must be loaded by ContextLoaderListener. This work. I don't know if this is the only solution.
    On the server:
    web-xml:
    <context-param>
            <param-name>contextConfigLocation</param-name>
            <param-value>
                /WEB-INF/config/web-application-config.xml
                /WEB-INF/config/web-application-security.xml
            </param-value>
        </context-param>
        <filter>
            <filter-name>springSecurityFilterChain</filter-name>
            <filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
        </filter>
        <filter-mapping>
          <filter-name>springSecurityFilterChain</filter-name>
          <url-pattern>/*</url-pattern>
        </filter-mapping>
        <listener>
            <listener-class>org.springframework.web.context.ContextLoaderListener</listener-class>
        </listener>
        <servlet>
            <servlet-name>Spring MVC Dispatcher Servlet</servlet-name>
            <servlet-class>org.springframework.web.servlet.DispatcherServlet</servlet-class>
            <init-param>
                <param-name>contextConfigLocation</param-name>
                <param-value>/WEB-INF/config/flex-application-config.xml</param-value>
            </init-param>
            <load-on-startup>1</load-on-startup>
        </servlet>
    flex-application-context:
    <flex:message-broker>
            <flex:secured/>
        </flex:message-broker>
    web-application-context:
    I had to implement my own authentication mechanism. Had to compare the username/password against an object attribute. So this bean is not mandatory, but I think you have to write down username/password/role in flex-application-context if not provided.
    <bean id="customAuthenticationProvider" class="packagename.CustomAuthenticationProvider">
            <security:custom-authentication-provider/>  
    </bean>
    web-application-security:
    <http entry-point-ref="preAuthenticatedEntryPoint" />
        <beans:bean id="preAuthenticatedEntryPoint"
            class="org.springframework.security.ui.preauth.PreAuthenticatedProcessingFilterEntryPoint " />
        <!-- Securing the service layer -->
        <global-method-security>
            <protect-pointcut expression="execution(*package.ServiceImpl.*(..))" access="ROLE_USER"/>
        </global-method-security>
    On the client:
    private function login():void {
        var cs:ChannelSet =  ServerConfig.getChannelSet(loginRemoteObject.destination);
        var token:AsyncToken;
        token = cs.login(username, password);
      // Add result and fault handlers.
      token.addResponder(new AsyncResponder(loginResultHandler, loginFaultHandler));
    private function logout():void {
        var cs:ChannelSet =  ServerConfig.getChannelSet(loginRemoteObject.destination);
        var token:AsyncToken = cs.logout();
      // Add result and fault handlers.
      token.addResponder(new AsyncResponder(logoutResultHandler, logoutResultHandler));

Maybe you are looking for

  • How can i send multiple films from iMovie06HD to iDVD? ( iDVD gave me ****)

    After 2 weeks of jerky videos, unexpected shutdowns, multiplex and buring errors i yesterday finally had something. Than i noticed, that the chapters didn't work. Allright, i thought, those 5-min chapter-marks are a mess anyway. I got myself iMovie06

  • Free good for bom material

    hai i am new to sap , can any one tell me how to post free good for bom material !!

  • MacPro Raid ?.  Can I stripe 3 promise 450gb SAS drives.

    I'm thinking about ordering a new MacPro Quad core 3.33ghz. Along with the raid card and 3 Promise 450GB SAS drives. Can I stripe across 3 drives or does it half to be 2 or 4. Secondly can I put a SATA drive in the 4th bay and install OSX and use boo

  • Reader 9.3.1 does not open pdf in current browser; opens in new window

    When clicking on a pdf link in a browser, is there a way to open the pdf in the current browser as oppose to the pdf file opening in a new window? Browser: Microsoft IE Operating System: Windows XP Professional I read that this feature has been remov

  • Applets on linked page won't open

    This is probably a really basic question, but I'm stumped. I have two domains and both have applets. When I use a text hyperlink to go to the other site, the .class files don't seem to be made available. Is that what getAppletContext() .showDocument(