The main goal of this report is to provide the GRC Access Control administrator with diagnostic of LDAP
connection and configuration. The report collects LDAP configuration data and compares to expected value
for a correct behavior. This comparison result into a detailed log to assist GRC administrators with a root cause analysis.

*This is only a diagnostic tool, the LDAP on GRC can still present other issues even if all the items are checked*

  1. How to Install LADT:
    In transaction se38 create a new Z report named ZLADT_LOG type include.
  2. Copy the file log.txt source code into the report, save and activate.
  3. In transaction se38 create a new z report named ZLADT type executable program.
  4. Copy the file main.txt source code into the report, save and activate.

How to operate LADT:

  1. In transaction se38 choose report ZLADT and execute.
  2. In the field Ldap Connector, insert the LDAP connector that want to test and run the report.

The result log shows 3 types of messages:

1)    A success message will show status “OK” and it means that the step is
correctly configured.

2)    A warning message will show status “Attention” and it means that one or
more optional steps are not configured correctly. This message shows a return
code, which can be interpreted in the next section of this note to implement the
optional steps.

3)    An error message will show status “Error” and it means that one or more
mandatory steps are not configured correctly. This message shows a return code,
which must be interpreted in the next section of this note to implement the
optional steps.

Please refer to the following procedures to correct the error.

CODE 00000 – Check your LDAP configuration according the error message.

CODE 00001 – Set program id equal to RFC ID in SM59 as below:

/wp-content/uploads/2015/11/00001_837213.jpg

Code 00002 – Maintain a server for the LDAP Transaction:

/wp-content/uploads/2015/11/00002_837214.jpg

CODE 00003 – Assign the LDAP Connector to a connector group:

/wp-content/uploads/2015/11/00003_837245.jpg

CODE 00004 – Assign integration scenario AUTH in SPRO for LDAP connector:

/wp-content/uploads/2015/11/00004_837246.jpg

CODE 00005 – Assign integration scenario PROV in SPRO for LDAP connector:

/wp-content/uploads/2015/11/00004b_837247.jpg

CODE 00006 – Assign integration scenario AUTH in SPRO for LDAP connection type:

/wp-content/uploads/2015/11/000006_837248.jpg

CODE 00007 – Set application type 12 to LDAP connector:

CODE 00009 – Change the application type of LDAP connector to 12:

7 8 9.jpg

CODE 00010 – Set application type 12 to LDAP connector group:

CODE 00011 – Active LDAP connector group:

CODE 00012 – Change the application type of LDAP connector group to 12:

10 11 12 .jpg

CODE 00014 – Check the ldap field mapping for action 0003, make sure that all fields are set for LDAP connector and SAP:

CODE 00016 – Check the ldap field mapping for action 0004, make sure that all fields are set for LDAP connector and SAP:

14 15 16 17.jpg

CODE 00015 – Maintain field mapping for LDAP connector action 0003

/wp-content/uploads/2015/11/15_837253.jpg

CODE 00017 – Maintain field mapping for LDAP connector action 0004

/wp-content/uploads/2015/11/17_837254.jpg

CODE 00018 – Maintain connector type as LDAP

/wp-content/uploads/2015/11/18_837255.jpg
CODE 00019 – Maintain attributes for LDAP connector

/wp-content/uploads/2015/11/19_837257.jpg

(*This image is only illustrative, please check with your basis team your user path)

CODE 00020 – Maintain LDAP connector as a user search data source (not mandatory).

/wp-content/uploads/2015/11/000020_837258.jpg

CODE 00021 – Maintain LDAP connector as a user detail data source (not mandatory).

/wp-content/uploads/2015/11/21_837259.jpg

CODE 00022 – Maintain LDAP connector as user authentication (not mandatory).
/wp-content/uploads/2015/11/22_837260.jpg

CODE  00023 – Maintain LDAP connector as end-user authentication (not mandatory).

/wp-content/uploads/2015/11/23_837261.jpg

Your feedback is welcome! Feel free to share your impressions of the program in the comments box.

To report this post you need to login first.

5 Comments

You must be Logged on to comment or reply to a post.

Leave a Reply