8 Replies Latest reply: Dec 28, 2011 10:00 PM by Diego I. Yaryura RSS

GRC SPM 5.3: Auth. object GRCFF_0001 in the role /VIRSA/Z_VFAT_FIREFIGHTER

Diego I. Yaryura
Currently Being Moderated

Hi experts,

 

According to latest version of "SAP GRC Access Control 5.3 Security Guide" available on SAP service marketplace:

https://websmp105.sap-ag.de/~sapdownload/011000358700000406492008E/AC53_Sec_Guide_en.pdf

 

I should assign the default role "/VIRSA/Z_VFAT_FIREFIGHTER" to FF users. (see page 18):

 

Base user authorizations required to logon as a firefighter. The firefighter role provides authorization for users who have a firefighter ID to run a firefighter transaction. Read SAP Note 1319031 for additional authorizations required after installation of AC5.3 SP07.

 

The authorization object GRCFF_0001 field ACTVT is * as per default, and as the Sec. Guide says, see page 22.

 

What is this authorization for?

 

The documentation of this field (PFCG-> press <F1> on object) states following:

"Authorization Object is used to restrict maintaining and uploading data various tables such as Configuration,Reason Codes, Controllers, Owners and Firefighters"

 

Iu2019ve removed completely this authorization for the role "/VIRSA/Z_VFAT_FIREFIGHTERu201D and users still can use their FF without problems.

 

The problem is in the case of a user having the following auth:

GRCFF_0001 ACTV *

S_TABU_DIS  ACTV 02  Table group: Z****

 

This combination allows FF users to change all the configuration tables in tx. /n/virsa/vfat.

 

What do you think? Is the security guide correct? Why we should give FF users this authorization?. As I said Iu2019ve removed this auth from the role and all works fine anyway.

 

Regards

Diego.