cancel
Showing results for 
Search instead for 
Did you mean: 

question on Group user mapping

Former Member
0 Kudos

HI All,

we have ep7.0 and we have abap as a datasource.

i have created one group and assinged 10 users to this group and also i have given everyone role which have read and enduser permissions,but still i cant do user mapping to this group, please let me know how to do user mapping to a group.

ur help will be greatly appreciated.

thanks,

vinay

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Vinay,

No, you dont need to do user mapping in your case.

If your logon ticket is not working in the current context, you need to check the configuration steps again.

Let me know if you have any other questions regarding the same.

Regards,

Sandeep

Answers (2)

Answers (2)

Former Member
0 Kudos

Hi Vinay,

Ideally, it should not ask you for uid and pswd.

I guess you need to recheck your UM property, im doing the same here.Gimme some time.

Regards,

Sandeep

Former Member
0 Kudos

ok thanks

Former Member
0 Kudos

Hi Vinay,

Follow these steps and lemme know what you observe.

Open the system object.

Under property editor, choose Property Category as User Management

It will display the following

Authentication Ticket Type: SAP Logon Ticket

Logon Method : SAPLOGONTICKET

UserMapping fields:

UserMapping type:

Check the Usermapping type, if it is set to admin,user...change it to select and try the same.I am sure, it should work.

Let me know if you have any further questions.

Regards,

Sandeep

Former Member
0 Kudos

NO I am not getting .I am getting this below error.

i assigned eu-role to users and eu_role have read and enduser permissions.and also changed usermapping type to select instead of admin,user.

Portal Runtime Error

An exception occurred while processing a request for :

iView : pcd:portal_content/com.disney.disco.disco/role/disco/see/se

Component Name : com.sap.portal.appintegrator.sap.Transaction

Exception in SAP Application Integrator occured: Cannot retrieve system object for this alias. System Alias: 'ECC_DEV', System ID: 'pcd:portal_content/com.disney.disco.disco/disney.com.dr1'. User: 'CHUNGTEST', Reason: Access denied (Object(s): portal_content/com.disney.disco.disco/disney.com.dr1).

Exception id: 06:27_25/10/07_0025_3948950

See the details for the exception ID in the log file

Former Member
0 Kudos

Hi Vinay,

There are a cpl of thg that I want to confirm.

1. Is your SSO configured, if yes, how did you test?

2. Does the user "CHUNGTEST" exists in the backend system?

Regards,

Sandeep

Former Member
0 Kudos

1.Yes my SSO is configured,i tested that,we are using saplogonticket,i created a normal transaction ivew ,i can able to login to r3 from portal transaction ivew,because i have super admin role.

2.chungtest is also exist in backend

thanks,

vinay

former_member1
Active Participant
0 Kudos

Hi Vinay,

You can try deleting the user in the back end and re create the user with the the caps on. Some times there is problem with the backward compatibility.

eg: Current user: chungtest, Recreate it with the name CHUNGTEST.

I hope it should help.

Thanks,

Anish

Former Member
0 Kudos

Yes Vinay, you can try what Anish suggested...it works at times.

Regards,

Sandeep

Former Member
0 Kudos

sandeep/anish,

sorry i didnt not mention this before,the user id is in caps only.CHUNTEST.

vinay

Former Member
0 Kudos

Hi Vinay,

Can you test with creating another user and let me know if you still have the same issue going on.

Regards,

Sandeep

Former Member
0 Kudos

hi sandeep,

i tested with creating another user ,but still i have the same issue.

is there any problem with SSO configuration?

thanks,

vinay

Former Member
0 Kudos

hi sandeep,

i just spoken to admin guy ,he said abap is our datasource,so he not creating any user id from portal,he said if he creates userid in r3 ,it will automaticlly pulls the same user id for portal too.and r3 userid is not case sensitive.

thanks,

vinay

Former Member
0 Kudos

Hi Vinay,

Sorry for the delay in response.

I guess there might be some permissions issue for the system object.

Please check the users that you have created, atleast have read permissions in the system object.

Thanks and regards,

Sandeep

Former Member
0 Kudos

hi sandeep,

i am not getting you,you said give the read permissions to system object.

can u tell me how to do this in system object.

i assigned everyone rrole to users which they have read and end user permissions,

and also when i logged in wiht my my user which have super admin role,but i am getting this error "the system is unable to intrepet the SSO ticket recieved"

what is this error?

thanks,

vinay

Former Member
0 Kudos

Hi Vinay,

I guess you have generated the SSO in one client and using the client information on another one. Please check this link as well for more details.

Let me know if you still have any issues.

Regards,

Sandeep

Former Member
0 Kudos

HI Sandeep,

Yes you are right,the admin guy he did like this,

he genrated sso in client 000 and giving credentials to 020 clinet ,this is not the right way to do,because when he logsin and did tried to do sso with 020 client ,system doent allow to do like this,it said sso can be done only with 000 client.

thanks,

vinay

Former Member
0 Kudos

Hi Vinay,

FYI...

Check this link and lemme know if it is handy.

Regards,

Sandeep

Former Member
0 Kudos
Former Member
0 Kudos

hi sandeep,

my question here is we have sap logon ticket for SSO,and user id s and even passwords are same for portal and r3.and i mentioned logon method as saplogticket when i created system in portal.i want to know whether this is possible,if i use like this ,still we need to do user mapping for all users?

thanks,

vinay

Former Member
0 Kudos

Hi Vinay,

SAP provides two different methods to realize SSO between portal and backend applications.

- SAP Logon Ticket

- User Mapping

SAP Logon Ticket can be used when user ids in portal and backend are the same. If you use SAP Logon Ticket and the user ids are the same in portal and backend then you do not need anything else. In this case you do NOT use User Mapping.

Best regards,

Martin

Former Member
0 Kudos

Thanks martin,

I thought the same thing,so in system which we create ,in that i need to mention lognon method paramter as saplogonticket thats right?.even though our datasource is from abap not from Ldap?

thanks,

vinay

Former Member
0 Kudos

Hi Vinay,

Yes, you can go ahead by mentioning the logon parameter as saplogonticket.

Regards,

Sandeep

Former Member
0 Kudos

thanks sandeep,

but when i using logon method as saplogonticket,its once again asking me enter uersid and password,

thanks,

vinay