Synchronisation of CUA and satelite system

we have implemented CUA and 3 satelite systems (PROD, TEST, QAS). By accident the complete user-access information has been deleted in QAS. Is there any possibility to push the information from CUA again into QAS to synchronize CUA and satelite system?

HI Dagmor,
Find CAU cookbook:http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/fe4f76cc-0601-0010-55a3-c4a1ab8397b1?quicklink=index&overridelayout=true
But it would be good if more elaborate your problem "user-access information has been deleted" like what you did in system. So that we can check and support you with better solution.
Hope this helps..

Similar Messages

  • How to create automatically users&roles in CUA and child systems

    Hi,
    i have a CUA on a 2 chlid R/3 systems (test and training) and 2 portal systems (test and training).
    i need to create a web application to create automatically users test and users training in CUA and see them in the R/3 chlid systems and at the same time to create autmatically a roles in CUA and R/3 chlid systems for those users (we sppose that the role is already stored in a table).
    are there any standard BAPI or Funcion modules that can do this job?
    is the role created automatically in CUA can be seen automaticall in the portal child system?
    any help?
    Thanks&Best regards

    Thank you all. I got the solution.
    Regards
    Rajesh

  • Synchronisation between server and local systems

    Hello guys,
    I hired a Vserver running with Debian and would like to synchronise it spaced (after/before start/shutdown of my local systems and in between every 30 minutes or so) with my local systems, more precisely with my home directories or some directories I define and not the complete system.
    How could that be realised best?
    Should I take some programs or are there any small scripts as well that do that work?
    I apologise for that stupid question but I have not any experiences with issues like backup and synchronisation.
    Thank you in advance.
    Last edited by orschiro (2009-06-04 23:28:31)

    Hello tkdfighter,
    sorry but I can't follow you. Could you please be more detailed because I don't know how the functions you speak from can help me in my case.
    Basically I just have that problem because I synchronise the server from two different machines and so the archive name differ from machine to machine. I already took a look on the Wikipage but unfortunately it helped me not with that problem.
    Greets
    Last edited by orschiro (2009-06-16 17:56:24)

  • Integrate GRC 10.1 with CUA and how to import roles from CUA & Child systems into GRC for provisioning

    Hello,
    I am trying to integrate CUA into our GRC 10.1 system through the below steps and so far I have completed the below steps following SAP Notes 1680108 and 1616121:
    1. Connected CUABOX to GRCBOX like a plug-in system.
    2. Updated CUA Global System and CUA Model Distribution in Maintain CUA settings under User Provisioning.
    3. Next I am trying to import the roles from CUA(CUABOX) into GRC(GRCBOX) to be able to provision roles in CUA Child Systems(ECCBOX).
    After reading few discussions in SCN, I have figured that we have to download a template in Role Import and populate it accordingly to upload the CUA child system roles into GRC system for provisioning in CUA Child Systems.
    Unfortunately, this template has multiple fields and I am unable to determine the fields that should be populated as CUA Global System and CUA Child System to import into GRC. Also, when we upload CUA Child System Roles template what selections should be made in Role Import window.
    Any help in this regard is very helpful.
    Thank you,
    Pawan

    Hi Alessandro,
    I have "Create user if does not exist" setting checked for both change action and assign role action and also have CUA enabled. Here is the list of steps that I am performing:
    1. Create an access request for new account, T-CUA_CHILD and select a role from a child system ECC Z_ECC_ROLE_IN_CHILD_SYSTEM.
    2. Approvals provided to assign the ECC role.
    3. I see the following in GRFNMW_DBGMONITOR_WD.
               Auto provisioning activity at end of request at Path GRAC_DEFAULT_PATH and Stage              GRAC_SECURITY
                   New User:T-CUA_CHILD created in System(s): ECC (created without role assignments)
                   T-CUA_CHILD User does not exist in target system CUA
    GRC created an account without role assignment in ECC but also throwed me an error that the user does not exist in CUA.
    However, if I select roles from both CUA and ECC it creates the account in both systems with the selected role assignments.
    So I am wondering if there is way to provide CUA access to users by default for new account requests types. I have tried setting up default roles for CUA but it does not assign the roles by default until I select the CUA system.
    Thank you for your help!
    Pawan

  • Client Delete and Logical System and CUA

    I'm getting ready to do some client clean up in prep for an upgrade from ECC 5 to ECC 6 soon.
    Currently we have a 3 system landscape: DV1 QA1 PR1
    Clients on these systems are as follows: (not including 000, 001, 066)
    PR1:100 - the production client
    QA1:100 - Integration Master - not used except for RFC connections for Solution Manager
    QA1:110 - Cycle 1 testing - not used
    QA1:120 - Cycle 2 testing - not used
    QA1:200 - Old training master client - not used
    QA1:201 - Old training client - not used
    QA1:710 - no longer being used for testing
    QA1:720 - client used for system and integration testing
    DV1:100 - Configuration - not used
    DV1:110 - ABAP development
    DV1:120 - Configuration
    DV1:700 - Template for test - not used
    DV1:710 - Test with prod data
    Most have a logical system defined for the client.
    I am going to delete those I've underlined above as they are no longer used.
    Some of these are setup in the CUA system.
    All are showing up in Solution Manager SMSY system landscape.
    My plan is to backup the system database first! 
    Then:
    1) Delete the client(s) (SCC5) one by one
    2) Remove the client from CUA (SCUA)
    3) Remove the logical name (SALE)
    What I am unsure about is the order of the process.  Should the CUA and ALE modifications come before actually deleting the client?
    Does this sound like a reasonable plan to clean up our client landscape?
    Thanks in advance for your suggestions and help.
    Laurie McGinley

    Dear Laurie,
    Order should be like below:
    1) Remove the client from CUA (SCUA)
    2) Delete the client(s) (SCC5) one by one
    3) Remove the logical name (SALE)
    More over you should delete these clients from Solution Manager also inorder not to have error message when you go to solution Manager for doing anything on that system.
    Please revert back for any queries.
    Regards
    Shailesh Mamidwar

  • How to create automatically users&roles in CUA and in chlid systems?

    Hi,
    i have a CUA on a 2 chlid R/3 systems (test and training) and 2 portal systems (test and training).
    i need to create a web application to create automatically users test and users training in CUA and see them in the R/3 chlid systems and at the same time to create autmatically a roles in CUA and R/3 chlid systems for those users (we sppose that the role is already stored in a table).
    are there any standard BAPI or Funcion modules that can do this job?
    is the role created automatically in CUA can be seen automaticall in the portal child system?
    any help?
    Thanks&Best regards

    You can use one of the various ways Java EE provides you, e.g. container managed authentication.
    It's also all in the Java EE tutorial: [http://java.sun.com/javaee/5/docs/tutorial/doc/bncas.html].
    You can configure it in the application server as well: [http://tomcat.apache.org/tomcat-6.0-doc/realm-howto.html].
    Here is an example how to use it in JSF: [http://ocpsoft.com/java/acegi-spring-security-jsf-login-page/].

  • SAP CUA connector changes password in master system AND child systems?

    Please confirm if OIM can change the password in both SAP CUA master and child systems through SAP CUA connector. The connector guide mentions the following parameter can be defined in SAP CUA IT Resource.
    Parameter: SAPChangePasswordSystem Flag that accepts the value X or ' '
    If the value is X, then the password is changed
    only in the master system. If the value is ' ', then
    the password is changed in both master and child
    systems.
    This parameter is used by the Reset
    Password function.
    Thanks!

    Hi,
    1) You can use report RSCCUSND to distribute users from CUA to child client. Check section "Sending User Master Data to a Child System" in [CUA cookbook|http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/fe4f76cc-0601-0010-55a3-c4a1ab8397b1?quicklink=index&overridelayout=true].
    2) if the user account has not been synced to CUA then you should be able to delete it in child system. The button should be displayed for unsynced users. You can use transaction SCUG to sync users between new child system and CUA. Check section "Transfering Users from New System" in [CUA cookbook|http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/fe4f76cc-0601-0010-55a3-c4a1ab8397b1?quicklink=index&overridelayout=true].
    Cheers

  • Support Message from satelite system: Reported By field blank only from BI

    Hi,
    I have configured the Incident Management for solman 7.1 with SP12. I am using the transaction type ZMIN that is a copy of SMIN.
    In our landscape are two satelite systems: BI and ECC
    When I create a message from managed/satellite system via HELP>Create Support Message, it comes to Solman the field "Reported By" is not filled automatically if I created the message from BI. The Creation from ECC works fine: the field "Reported By" is filled automatically.
    The system data is fetched up correctly and it includes the system info, component code and all details. Even the Support Team Determination with BRF+ is working fine.
    Not successful actions to solve the problem:
    - I tried some access sequences in Partner Determination for "Reported By":
         - Preceeding Document -> Reporter -> Current User
         - User
    - Checked IB52
    - Checked DNO_CUST04
         No_User_CHECK; No Existence Check for User; field value:X
    - Checked BP (Generated with BP_GEN):
         identification in BP seems correct (I added created/expiry date manually)
    - Checked BCOS_CUST.
    - Checked Read RFC.
    Has someone an idea what the problem could be?
    Thank You for your effort in advance,
    Beda

    Hi,
    1) Under identification tab in external BP no. put details as
    <Server short name>space<client>space<search term
    (which you have maintained in address tab or employee no.
    of that user in satellite system)>
    2) In ID type put CRM001
    3) Under identification put details as <Server short
    name>space<installation no.>space<client>space<search
    term (which you have maintained in address tab or
    employee no. of that user in satellite system)>
    4)Go to trns. BP>select BP role as "Employee"> Indentification tab--> Maintain user name same as user id of employee in satellite system or serch term you maintained while creating BP.
    Try this. Reward the points for useful answer.
    Regards,
    Niks

  • CUA and Risk Analysis

    We have installed GRC 5.3 AC and using it with CUA. Connector names are same as names in CUA.
    While doing Risk Analysis for user in Master system, it shows violations. For same user, when I do risk analysis in child system (which has same roles) it does not show any violations.
    Are we missing anything?
    Thanks,

    Thanks,
    I checked those notes but it talks about Analysis from CUP where as I'm currently looking into Risk Analysis from RAR only.
    I checked with another user-id with different roles but it shows violation in both Master and Child system. Wehre as earlier user-id still shows violation in Master system only even though roles are same in both systems.
    So, i suspect some of rules are not generated (i ran rule generation again).
    Is there any way to check/generate rules for particular system?

  • Integrate Password CUA and Active Directory (AD)

    Hello Everybody,
    We have integrated AD with our CUA system.
    Is it possible integrated the same password CUA and AD?
    How can I configure this?
    Thank you,
    Luciana

    Luciana,
    I am not sure if you are aware, but the Active Directory domain controller uses a protocol called Kerberos to authenticate a user when they logon to the domain. Therefore, to logon to SAP in the way you require it is best to use Kerberos so that the credentials for the user already available on the workstation, in the credentials cache can be used to securely authenticate the same user to the SAP system, e.g. CUA ABAP via SAP GUI. This means that no passwords need to be transmitted or stored anywhere, and the only authentication needed is that already done using Active Directory when the user logs onto their Workstation. Also, you can use this method to encrypt the communications - giving you added benefit, rather than just using the authentication provided.
    This is achieved using an interface which SAP provided in SAP GUI and in SAP application servers called SNC (Secure Network Communications). For SNC to work, you need a GSS-API library installed on each workstation where SAP GUI is installed, and on the app servers you want to logon to using this secure authentication method. SAP provide SNC libraries, but they are only available if your SAP app server is on Windows. In your case where SAP is on HP/UX, you need to use an SNC library available from a SAP partner. This partner will provide you with all the software and support you need to make the solution work, and meet your needs.
    I would like to recommend one such partner, but I am biased because I work for the vendor providing this product :-). The partner is called CyberSafe. You can make contact with me offline and I can arrange a free evaluation of the products, or you can visit the CyberSafe website at <a href="http://www.cybersafe.com/links/snc.htm">this site</a> to find out more. Or, you may decide to look for other partners who have solutions to help you, in which case you need to look on the SAP website for SAP SNC partners.
    I hope this is useful ?
    Thanks,
    Tim

  • Rename 600+ users in CUA implemented 3 system landscape

    Hello All,
    Task ahead :
    Rename around 600+ users in my Production system which is my CUA central system as well. I am having a simple 3 system landscape.
    Advice on :
    What can be the pitfalls for this activity ?
    Since CUA is ON, there would not be a Rename Option available any more...so How to proceed with this activity ?
    Is there any negative impact for such renaming actions in the system.
    Any inputs would be rewarded handsomely...
    Thanks for your time.
    Br,
    Sri

    Hi Happyman,
    How do i perfrom the Rename in my central system ? Its OK, i can delete child systems from the centrral CUA and perfrom a rename and then re add it back to CUA...bt my query is how to tackle this issue in central PRD system.
    does that means i need to delete the existing CUA altogether and recreate it again after utilising the rename option ?>
    Thx for the inputs...
    Br,
    Sri

  • CUA - Adding Child systems after implementation

    Hello all, just have a quick question:
    We have about 10 systems all with 8-10 clients in each of them and are in desperate need of the CUA.  I wanted to just do a couple of systems at first so that everyone could get used to the CUA and then add the rest of the systems at a later time.  Is there anything wrong with this?  Or does the whole distribution model have to be setup BEFORE setting up the CUA?
    Thanks

    i know your question is answered but i wanted to add my comment anyway - i was not around the last few days ... so: endure it now !
    there's no restriction as to when to add other clients/systems to your distribution model. you can go step by step here if you like.
    i have an adivce anyway: normally i do it systemwise (not client-wise) because in that way i find it more transparent what ports (WE20/21) and rfc-destinations (SM59) i have created (because i maintain them with the same names/numbers in all the systems in one landscape - just in case there is a system-copy to a new sandbox or somesuch ... then my settings will already be there).
    but that's just a personel preference.

  • CUA Authorusation on systems

    Hey there,
    In our SAP landscap we plan to use CUA. The user-maintenance is divided in two sections. Section A maintain the production systems, Section B maintain the Development systems. We have one CUA for all systems.
    Cal anyone help wich authorization object I have to use to make the propely authorization profile?
    Thanks Hans Bloem

    Hi Hans,
    Have a look at S_USER_SAS and S_USER_SYS.
    Jurjen

  • Synchronize priority between solman and satellite system

    Hi,
    I've changed priority in solman to
    1- very high
    3 - high
    5 - medium
    9 - low
    But priority in satellite system did not change.
    It was shown as
    1 - very high
    2-  high
    3 - medium
    4 - low
    How can i synchronize the priority in satellite system?
    The satellite system have to follow the numbering in SOLMAN
    Kindly assist.
    regards,
    Biah

    Hi Blah,
    as per sap the standard priority are 1 ,2 .3 ,,4 and this wil be available in all the satellite systems as per standard installation.
    So in solman you can maintain the same way just like satelite system using
    tran----
    Dno_cust01
    ..goto SLF1 priority and maintain the same ...i.e 1,2,3,4
    and
    Spro-
    solman-> scenario specific-> service desk ->........maintain category and priority
    Above step will Syn with SLFN priority with SLF1
    So from now where you post ticket within solman or outside only the standard 1,2,3,4 will be thre
    Hope it clarifies your doubt and solves ur problem
    Regards
    Prakhar

  • Delete the old CUA and build a new CUA on the Solution Manager

    Hello together,
    I'm about to delete the old CUA and build a new CUA on the Solution Manager.
    The users are in multiple systems almost the same.
    This raises the following questions:
    If I export the printers from the old CUA in a file and import into the new CUA (Solution Manager, then the printer can be administered directly in Solman?
    Furthermore, if I depended on the second or third child System  and attached to the new CUA, the user description data are not overwritten, as bsp: with the description data of the last-connected system?
    By delete the CUA child system in which users are blocked. Can you handle it?
    I thank you in advance
    Mirsad

    > If I export the printers from the old CUA in a file and import into the new CUA (Solution Manager, then the printer can be administered directly in Solman?
    -->the assignment of printers, not the printers themselves of course....
    > Furthermore, if I depended on the second or third child System  and attached to the new CUA, the user description data are not overwritten, as bsp: with the description data of the last-connected system?
    If you mean adress data, already existing adresses are not overwritten. Such users will show up in scug as 'identical' or different' and can be handled accordingly.
    > By delete the CUA child system in which users are blocked. Can you handle it?
    Users without assignement to the central system get a global lock if the cua is removed in the central system. They still exist in usr02 in the central system, but with the global lock flag as indication, that they existed only for adminstrative means. The local lock flags in the child systems stay untouched. So if you take over these users into the new CUA they get the correct lock flag form the child system.
    b.rgds, Bernhard

Maybe you are looking for

  • How to open an PDF file from Java Application

    Hi I am developing a GUI application in java swing. on clicking one button, I want to open PDF file from my swing application. Is there any API through which I can achieve this? Tapan Maru Sun Certified Java Programmer

  • Issue with SODIS and email with attachment

    Hello all, I am using CL_BCS classes in report to send the PDF output as an attachment to the email ids. I also have a standard disclosure template active in the SODIS with some text paragraphs. When it is active, the BODY of the email which is gener

  • HT5137 my iMessage will not activate

    my imessage will not activate, can someone please help me with this?

  • Configuration steps for campaign excecution

    hello experts, Could anyone of you help me in step by step implementaion process for campaigns?If you can provide me with a real time scenario that would be great. Thanks in advance....

  • Web Dynpro Tree expanding

    Hi there! I am using the tree element in web dynpro. Not the tree in the table. I need to expand a part of the tree during loading I do not find an example. Any help is warmly appreciated. Thanks in advance, Frank