Configure IBM Cognos to use SAP

To use an SAP server as your authentication provider, you must use a supported version of SAP BW.

In SAP BW, you can assign users to user groups or roles or both. The SAP authentication provider uses only the roles.

The authorization rights required by the SAP user depend on who uses IBM® Cognos® components: users or administrators.

SAP Authorization Settings for IBM Cognos Users

The authorization objects in the following table are required for any IBM Cognos user.

Table 1. SAP authorization settings for IBM Cognos users

Authorization object

Field

Value

S_RFC

Authorization check for RFC access

Activity

 
 

Name of RFC to be protected

RFC1 RS_UNIFICATION, SDTX, SH3A, SU_USER, SYST, SUSO

 

Type of RFC to be protected

FUGR

S_USER_GRP

User Master Maintenance: User Groups

Activity

03

 

Name of user group

*

Some of the values shown, such as *, are default values that you may want to modify for your environment.

SAP Authorization Settings for IBM Cognos Administrators

If users perform administrative tasks and searches for users and roles, the values from the following table must be added to the S_RFC authorization object in addition to the values for IBM Cognos users.

Table 2. SAP authorization settings for IBM Cognos administrators

Authorization object

Field

Value

S_RFC

Authorization check for RFC access

Activity

16

 

RFC_NAME

PRGN_J2EE, SHSS, SOA3

 

Type of RFC object to be protected

FUGR

Some of the values shown, such as *, are default values that you might want to modify for your environment.

Connectivity Between SAP BW and IBM Cognos on UNIX

To configure connectivity between SAP BW and IBM Cognos components on a UNIX operating system, ensure that you install the SAP shared library file (provided by SAP) and add it to the library path environment variable as follows:

  • AIX

    LIBPATH=$LIBPATH:<librfc.a_directory>