Rar Configuration: Upload UME Roles
Rar Configuration: Upload UME Roles
Rar Configuration: Upload UME Roles
RAR CONFIGURATION
Upload UME Roles:
Go to Java Portal home page->user management->Import->browse the UME Roles at OS level
VersionIT Page 1
Rashed’s GRC RAR configuration
then click on return to batch import and upload the other files in the same way.
VersionIT Page 2
Rashed’s GRC RAR configuration
Now go to Identity management-> select All data sources from drop down->click
on go.
VersionIT Page 3
Rashed’s GRC RAR configuration
Now select J2EE_ADMIN user and assign all the roles to it.
VersionIT Page 4
Rashed’s GRC RAR configuration
click on go on available roles side select all and Click on ADD and then save it.
VersionIT Page 5
Rashed’s GRC RAR configuration
http://<servername>:5<instance>00/webdynpro/dispatcher/sap.com/grc~acappc
omp/AC
VersionIT Page 6
Rashed’s GRC RAR configuration
VersionIT Page 7
Rashed’s GRC RAR configuration
In order to highlight the Superuser Privilege Management link, Goto below link
http://<servername>:5<nr>00/index.html
VersionIT Page 8
Rashed’s GRC RAR configuration
VersionIT Page 9
Rashed’s GRC RAR configuration
Click on Create Role, in general information Tab provide unique name in the provided filed(here it is
FF_ROLE) and Goto Assigned Actions Tab. then Type *FF* in the Text Field. click on GO button.
Now select User from the drop down and click on Go button
VersionIT Page 10
Rashed’s GRC RAR configuration
Select J2EE_ADMIN user-> modify->goto assigned roles tab->type *FF* in the space and click go-> select
all-> ADD-> save it.
VersionIT Page 11
Rashed’s GRC RAR configuration
VersionIT Page 12
Rashed’s GRC RAR configuration
VersionIT Page 13
Rashed’s GRC RAR configuration
Now Run the below Queries at database level. ( Open SQL Server Mgmt Studio )
INSERT INTO SAP<SID>DB .VIRSA_CC_CONFIG VALUES (105, 0, 'http', 'J2EE Engine Protocol')
INSERT INTO SAP<SID>DB .VIRSA_CC_CONFIG VALUES (106, 0, '50000', 'J2EE Engine Port')
VersionIT Page 14
Rashed’s GRC RAR configuration
VersionIT Page 15
Rashed’s GRC RAR configuration
meanwhile logon to ABAP Stack and create a Logon group using transaction SMLG
VersionIT Page 16
Rashed’s GRC RAR configuration
click on create
VersionIT Page 17
Rashed’s GRC RAR configuration
VersionIT Page 18
Rashed’s GRC RAR configuration
VersionIT Page 19
Rashed’s GRC RAR configuration
VersionIT Page 20
Rashed’s GRC RAR configuration
select ' Web As ABAP' in the drop down and click on go.
VersionIT Page 21
Rashed’s GRC RAR configuration
VersionIT Page 22
Rashed’s GRC RAR configuration
VersionIT Page 23
Rashed’s GRC RAR configuration
VersionIT Page 24
Rashed’s GRC RAR configuration
VersionIT Page 25
Rashed’s GRC RAR configuration
VIRSAR3_02_METADATA AS METADATA
VIRSAR3_03_METADATA AS METADATA
By clicking on create
VersionIT Page 26
Rashed’s GRC RAR configuration
VersionIT Page 27
Rashed’s GRC RAR configuration
click next
VersionIT Page 28
Rashed’s GRC RAR configuration
clikc next
VersionIT Page 29
Rashed’s GRC RAR configuration
click next
VersionIT Page 30
Rashed’s GRC RAR configuration
VersionIT Page 31
Rashed’s GRC RAR configuration
click on FINISH
Repeat the above steps for all other JCo destinations given above.
now go to http://<servername>:5<instance>00/webdynpro/dispatcher/sap.com/grc~acappcomp/AC
and click on Risk analysis remediation-> Configuration tab->Connectors->Create
VersionIT Page 32
Rashed’s GRC RAR configuration
VersionIT Page 33
Rashed’s GRC RAR configuration
Check, if the connector really works by going to below URL and test search for Backend users
http://<server>:<port>/webdynpro/dispatcher/sap.com/grc~ccappcomp/CCDebugger
VersionIT Page 34
Rashed’s GRC RAR configuration
provide * in Obj ID field and click on Search obj... users in backend must be shown here.
VersionIT Page 35
Rashed’s GRC RAR configuration
Save it
VersionIT Page 36
Rashed’s GRC RAR configuration
VersionIT Page 37
Rashed’s GRC RAR configuration
VersionIT Page 38
Rashed’s GRC RAR configuration
click Continue
VersionIT Page 39
Rashed’s GRC RAR configuration
Save it
VersionIT Page 40
Rashed’s GRC RAR configuration
VersionIT Page 41
Rashed’s GRC RAR configuration
VersionIT Page 42
Rashed’s GRC RAR configuration
VersionIT Page 43
Rashed’s GRC RAR configuration
VersionIT Page 44
Rashed’s GRC RAR configuration
VersionIT Page 45
Rashed’s GRC RAR configuration
Now go to ABAP Stack. Using the transaction SE38 run below two programs
/VIRSA/ZCC_DOWNLOAD_DESC
VersionIT Page 46
Rashed’s GRC RAR configuration
VersionIT Page 47
Rashed’s GRC RAR configuration
Create a text file in any location and browse the path in the local file field and execute it.
VersionIT Page 48
Rashed’s GRC RAR configuration
VersionIT Page 49
Rashed’s GRC RAR configuration
VersionIT Page 50
Rashed’s GRC RAR configuration
click on Foreground
VersionIT Page 51
Rashed’s GRC RAR configuration
VersionIT Page 52
Rashed’s GRC RAR configuration
Click on Upload.
VersionIT Page 53
Rashed’s GRC RAR configuration
click function Authorization-> browse for R3_function_action and R3_function_permission files and
Upload them.
VersionIT Page 54
Rashed’s GRC RAR configuration
click on Rule set-> Browse for ALL_Ruleset file and Upload it.
VersionIT Page 55
Rashed’s GRC RAR configuration
click on Risk-> browse for R3_Risk_Ruleset, R3_risks, R3_risks_desc files and upload them.
VersionIT Page 56
Rashed’s GRC RAR configuration
VersionIT Page 57
Rashed’s GRC RAR configuration
One final step of configuring Compliance Calibrator is making “Global” rule set as Default rule set for risk
analysis.
Click the Configuration Tab on top.
From left navigation menu, Click Risk Analysis.
Click Default Values.
The following screen will be displayed.
VersionIT Page 58
Rashed’s GRC RAR configuration
Run Background jobs for USER/PROFILE/ROLE Synchronization, batch risk analysis and Management
report.
VersionIT Page 59
Rashed’s GRC RAR configuration
==>USER/PROFILE/ROLE Synchronization
click on SCHEDULE
VersionIT Page 60
Rashed’s GRC RAR configuration
Click on SCHEDULE
Perform same steps for Role and Profile Synchronization one after the other.
VersionIT Page 61
Rashed’s GRC RAR configuration
VersionIT Page 62
Rashed’s GRC RAR configuration
After Completion of all the Background jobs below screen gets displayed.
VersionIT Page 63
Rashed’s GRC RAR configuration
Now login to RAR Config URL. below screens should be shown if the configuration is successful.
VersionIT Page 64
Rashed’s GRC RAR configuration
VersionIT Page 65
Rashed’s GRC RAR configuration
VersionIT Page 66
Rashed’s GRC RAR configuration
VersionIT Page 67