How to process security-related SAP Notes


Frank Buchholz, Active Global Support – Security Services June 2009

Security Notes in the SMP

Check for security-related SAP Notes

Check for security-related SAP Notes using Transaction ST13 -> Tool RSECNOTE Execute tool RSECNOTE within transaction ST13 A special authorization is required to execute this tool.

Let's choose one note as a example how to implement notes.Transaction ST13 -> Tool RSECNOTE Result The tool RSECNOTE shows security-related notes which should be implemented for this system.

Implement Note using transaction SNOTE Download Note Start transaction SNOTE and download the note.

Implement Note Download other required Notes if necessary Some notes require other notes as a prerequisite (even if we try to keep security-related notes almost independent from other patches). If requirements are present. they are automatically processed.

Implement Note Submit implementation process Finally. you have to confirm that you have read the note – and of course that you have defined sufficient test procedures.

Implement Note Integration with Transport Management You use transaction SNOTE in a development system. Therefore a transport request is used to transport the correction to the productive system.

Implement Note Check if correction can be applied Transaction SNOTE checks if all corrections can be applied to the ABAP programs.

Implement Note Activate objects

Implement Note Confirm Note

Transaction ST13 -> Tool RSECNOTE Refreshed Result Success !!

Appendix A Install RSECNOTE using note 888889

Install RSECNOTE using note 888889 Implementing note 888889 using transaction SNOTE may lead to some error messages. which are related to the settings of the System Change Options:

Install RSECNOTE using note 888889 Change System Change Options In transaction SE06 -> System Change Option (you can use SE03. too) activate the Namespaces/Name Ranges /SSA/ and /SSF/ for modification.

Install RSECNOTE using note 888889 Go ahead…

Install RSECNOTE using note 888889 Go ahead…

Install RSECNOTE using note 888889 Go ahead…

Install RSECNOTE using note 888889 Go ahead…

Install RSECNOTE using note 888889 Choose one main program and go ahead…

Install RSECNOTE using note 888889 Success !!

Appendix B Send Results of RSECNOTE using Mail

Send Results of RSECNOTE using Mail Online Help SAP Connect Configuration http://help.sap.com/saphelp_nw70/helpdata/EN/2b/d926324b8a11d1894c0000e8323c4f/frameset.htm Defining Output Devices for Printing Using E-Mail http://help.sap.com/saphelp_nw70/helpdata/EN/ae/16193ce8fac413e10000000a114084/frameset.htm You have to configue at least all steps which are related to the sending process based on SMTP In addition we like to highlight the topic converning Secure E-Mail On the following slides we show some of the configuration

Send Results of RSECNOTE using Mail Define MAIL Printer (1) Transaction SPAD Define a virtual printer which sends the spool request using SMTP to the mail server Typically you choose the device type PDF1 to create mails containing a PDF attachment

Send Results of RSECNOTE using Mail Define MAIL Printer (2) Transaction SPAD Set the Host Spool Access Method to ‚M' The reciepient mail address will be defined later as part of the backgroung job definition

Send Results of RSECNOTE using Mail Create Role for Background User Transaction PFCG Create a role for the background user

Send Results of RSECNOTE using Mail Create Background User Transaction SU01 Create a background user and assign the role The mail address in mandatory and will be used as the sender (and reply) address

Send Results of RSECNOTE using Mail Create Report Variant for Background Job Transaction SA38 Create a variant RSECNOTE for the report /SSA/NXS Set the service parameter to the value SECURITY_CHECK

Send Results of RSECNOTE using Mail Schedule Background Job Transaction SM37 Create a background job Add a step for the report /SSA/NXS with variant RSECNOTE Use the background user RSECNOTE Set the MAIL printer Set the receiver mail address Define a title Consider. to add a second step for sending the mail at once using report RSCONN01 with variant INT Schedule the job regularly. e.g. weekly

Send Results of RSECNOTE using Mail Result

Thank you!

