SAP Note 888889 Automatic checks for security notes using RSECNOTE

Note Language: English Version: 14 Validity:
Valid Since 30.04.2010

The SAP EarlyWatch Alert report contains selected checks about "Security". Among other things, there is a check to determine whether or not selected and required security-relevant notes or HotNews have been implemented in the system. The report displays an overall status. An administrator uses the tool RSECNOTE to create the detailed evaluation of the required security-relevant notes in the system to be analyzed. This note responds to the following situations: o In the SAP EarlyWatch Alert report, the "Service Preparation Check" unit complains that Note 888889 is not implemented. As a result, the check for security-relevant notes can only be carried out partially in the "Security" section. You want to use the tool RSECNOTE to check the implementation status of security-relevant notes in your system. However, this tool is not yet available in your system. You require detailed information on implementing and executing the tool RSECNOTE, and on interpreting the results. You call transaction ST13. In the F4 help for the "Tool Name" field, the entry RSECNOTE is missing. If you manually enter RSECNOTE and then execute it, the system issues the message "The tool RSECNOTE does not exist". The tool RTCCTOOL shows that the tool RSECNOTE is missing.





Other terms
EarlyWatch Alert, EWA, security, RSECNOTE, RTCCTOOL, ST13

Reason and Prerequisites
The tool RSECNOTE is part of the software component ST-A/PI as of Release 01M_*. Correction instructions are available for the installation in Release 01L_*. As of Support Package 3 for the Service Content Plug-In ST-SER 701_2008_2, various services in the Solution Manager require the tool RSECNOTE on the managed system to check whether or not security-relevant notes are implemented. The service report shows that this tool is missing and makes reference to this present Note 888889.

Below you will find: - a guide to implementing the tool RSECNOTE - documentation on using the tool and information about the background and further procedures


Install the tool RSECNOTE in all systems in which you want to use the tool. As a result of the tool RSECNOTE. The report shows the following three sections: o "Missing recommendations" This section shows the required security-relevant SAP Notes and HotNews. HotNews are flagged with a red traffic light and notes are flagged with a yellow traffic light. Enter /SSA/RTC if you are asked to specify a main program for /SSA/INT. In transaction ST13. See Note 69455 for more information. Documentation for the tool RSECNOTE You use transaction ST13 to start the tool RSECNOTE. SAP_BASIS Release 700 and subsequent releases. implement the corrections manually and confirm the message. "Successfully implemented recommendations" Page 2 of 10 o o 17. notes that contain security corrections and notes that are relevant for your system due to the existing software components (taking the releases and the Support Packages into account) are displayed.2011 . In this case. Comment: As of SAP_BASIS Release 620 Support Package 55. Object S_TCODE S_ADMI_FCD S_PTCH_ADM Field TCD S_ADMI_FCD TABLE COMPONENT ACTVT Value ST13 ST0R ' (or empty) SECURITY-CHECK 02 (change) 2. /SSA/. Go to "System Change Option" in transaction SE06 and set the software component ST-A/PI and the namespaces/name ranges "General SAP Name Range".SAP Note 888889 Automatic checks for security notes using RSECNOTE Guide for creating the tool RSECNOTE 1. You can also install the tool RSECNOTE in Release 01L_* by implementing the correction instructions using transaction SNOTE. and /SSF/ to "Modifiable". select the tool and start it by choosing "Execute" or F8. For example: You cannot implement a specific note using transaction SNOTE because you manually changed the affected program beforehand. for example. you can also start the tool as the report RSECNOTE by using transaction SA38. "Manually confirmed recommendations" Report messages can also be confirmed manually. SAP_BASIS Release 640 Support Package 13. Assign the following authorizations to all the users for whom you want to provide access to the tool. This should only happen in exceptional cases that require it. SAP recommends that you install Release 01M_* of the software component ST-A/PI.03.

the system checks only that at least the required kernel patch is installed. If the system to be checked does not have an online connection to SAPNet. List of security-relevant notes that are checked The tool RSECNOTE checks security-relevant notes or HotNews that are entered as related notes in this present note. which contains the recommendations for the tool RSECNOTE for the specified date. This means that all recommendations are selected. Note Assistant You can use the Note Assistant (transaction SNOTE) to implement the correction instructions. including the recommendations for the tools RTCCTOOL and RSECNOTE.SAP Note 888889 Automatic checks for security notes using RSECNOTE This section shows the security-relevant notes and HotNews that are required for the system and that are implemented successfully. You can also use the tool RSECNOTE to update the list manually (menu path: List -> Refresh from SAPNet). You can find additional information about the Note 17. During a check. however. Enter ND* as the table key. It does not check whether the gateway has also been safeguarded.com/securitynotes). Make sure that you have specified a table key.sap. see Note 863362. An overview of other security-relevant notes or HotNews is provided on the SAP Service Marketplace under the quick link /SECURITYNOTES (https://service. After the system is upgraded or Support Packages are imported. For further information on the SAP EarlyWatch Alert report.2011 Page 3 of 10 . to update the recommendations.03. EarlyWatch Alert report The SAP EarlyWatch Alert report also provides a summary of the results of the tool RSECNOTE. Use the transport files contained in it if you do not have any systems that have an online connection to SAPNet. Start the tool RTCCTOOL or RSECNOTE before you export the transport request. For Note 1298433 "Security note: Bypassing security in reginfo & secinfo". a note that was implemented earlier may no longer be listed.zip. a system loads the list automatically using the service connection to SAPNet once a day. To do this. A note or a HotNews is no longer required if your system release or Support Package level already contains the correction. Attached to this note is the file Transport_Files_<date>. Updating recommendations The quantity of checked notes or HotNews is managed online by SAP. then you can also use a transport to import the current recommendations from another system that has a connection to SAPNet. create a "Transport of Copies" and enter the object key R3TR TABU /SSF/PTAB.

Header Data Release Status: Released on: Master Language: Priority: Category: Primary Component: Secondary Components: XX-INT-SR Security Response Released for Customer 03.05.2010 07:08:40 German Recommendations/additional info Advance development SV-SMG-SER SAP Support Services Valid Releases Software Component ST-A/PI Release BASIS_46B From Release 01L_BCO46 B To Release 01M_BCO46 B and Subsequent

