[418] in SAPr3-news
Re: Authority objects and transactions
daemon@ATHENA.MIT.EDU (Phil Harris)
Tue Jul 25 22:57:31 1995
To: sapr3-news@MIT.EDU
Date: 25 Jul 1995 20:46:52 GMT
From: phharris@ix.netcom.com (Phil Harris)
In <3v319c$bgs$1@mhafm.production.compuserve.com> Peter B Schumacher
<75357.3343@CompuServe.COM> writes:
>
>The ABAP trace utility has been around since the early 1.X
>versions. However, anyone care to estimate how long it will take
>Phil H to trace each transaction and document the Authorizations
>required for each?
>
>A better method/tool is to use the SU53 transaction. Running
>this immediately following a failed transaction will yield the
>Authorization, required values and the user's matching
>Authorization; if the user had a matching object.
>
>When I use SU53 I create a blank user account (no authorizations)
>or a copy of the users acct. and run the transaction from this
>account. Then run SU53 and download or print the SU53 report.
>Next, use the report to search ("Used In") using the Information
>menu option to locate all of the profiles that already contain
>the Authorization.
>
>Phil, why reinvent the wheel? Most, if not all of the SAP
>delivered Auths are already setup with everything your users need
>by application area - and then some. Use these as the starting
>point, copy them and tailor them to your needs.
>
>------------------------------------------------------
>If at first you don't succeed, stop reading the manual.
>------------------------------------------------------------
Peter,
I agree it will take a good while to trace all the transactions. I
also think su53 takes a good while too. I was hoping that someone had
a better way of doing it than using these two options.
I personally do not feel I can plug in the default profiles and use
them. In my opinion, security was an afterthought for SAP. I believe
they provided me the tools to implement an adequate level of security,
but I do not believe using their default profiles provides me that
level of security.
I do not believe I can have a high level of confidence until I know all
transactions and programs and the authorizations required for each.
There is a good probability, in my opinion, that there will be several
instances where in giving a user the ability to perform transaction
xx01, you will also - by default - give them access to several other
transactions. If you have any suggestions on how to make me more
comfortable without knowing all transaction and program authorization
combinations, I would appreciate it.
Thanks, Phil
_______________________________________
I'll take the dirt road
It's all I know
I've been walking it for years
It's gone where I need to go
Oh, it ain't easy
It ain't supposed to be
But I'll take my time
Life won't pass me by
'Cause it's right there to find
On the dirt road