The Protect4S RFC user in the satellite systems needs the role ESEC_SA_SATELLITE to work correctly. From time to time, this role needs to be updated.
Should this happen, all Protect4S customers will be advised by mail to update the role in all satellite systems. This can be done using the CUA, manually or also via central update in Protect4S:
For this central update to work, an extra role must be added to the Protect4S ABAP RFC user : ESEC_SA_SATELLITE_PUSH
It is also possible to download the required Protect4S satellite role from the Solution Manager in which Protect4S is installed. The 3 roles ESEC_SA_SATELLITE for the ABAP RFC satellite system user user and the (optional) role required for automatic role distribution ESEC_SA_SATELLITE_PUSH plus the role required for the Mitigation of OSS Notes ESEC_SA_SATELLITE_MITIGATE are always shipped with every version of Protect4S.
Log in to the Solution Manager on which Protect4S has been installed and execute transaction PFCG. Select the appropriate role ESEC_SA_SATELLITE and select from the menu "Role", "Download" :
From the PFCG menu, select "Role", "Download":
Confirm the popup:
Select a location for the role on your PC and save the file
You may repeat this step for roles ESEC_SA_SATELLITE_PUSH and ESEC_SA_SATELLITE_MITIGATE when you use the automatic distribution of Protect4S satellite user roles or the Automatic Mitigation of OSS Notes functionality.
Login to the satellite system, execute transaction PFCG and select Role, Upload from the PFCG menu:
Confirm the popup:
Select the role file you downloaded to your PC in the previous step:
Provide permission to upload the file:
Overwrite the old version of the role that exists
Make sure all lights are green in PFCG
You may repeat this step for role ESEC_SA_SATELLITE_PUSH if you want to use automatic distribution of Protect4S satellite user roles.
You may repeat this step for role ESEC_SA_SATELLITE_MITIGATE if you want to use the Automatic application of OSS Notes functionality.
If one of the lights is not green, it could be that the authorization profile needs to be regenerated and/or redistributed to the Protect4S satellite system user. Ask an SAP user administrator to do this if you do not know how to do this.