<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anonymous Logon in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382451#M1042526</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you want to know about it? What is the scenario as the context is important.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Aug 2008 17:42:52 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-08-18T17:42:52Z</dc:date>
    <item>
      <title>Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382450#M1042525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm new to SAP security. Can anyone give me some insight on anonymous logon?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 17:29:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382450#M1042525</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-18T17:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382451#M1042526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you want to know about it? What is the scenario as the context is important.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 17:42:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382451#M1042526</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-18T17:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382452#M1042527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Wes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anonymous logon enables you to access your SAP NetWeaver systems in anonymous mode, without providing any form of authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please go through the following links for more info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nwmobile71/helpdata/en/43/d91d23eaca456de10000000a155369/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nwmobile71/helpdata/en/43/d91d23eaca456de10000000a155369/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example of an Anonymous Logon Procedure&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nwmobile71/helpdata/en/2b/d920774b8a11d1894c0000e8323c4f/frameset.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nwmobile71/helpdata/en/2b/d920774b8a11d1894c0000e8323c4f/frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope the above info is helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Satish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 17:51:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382452#M1042527</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-18T17:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382453#M1042528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I received a request to create user ID in our CRM environment for anonymous logon. This is a fix to an issue our project team is having with displaying attached documents. This solution was prescribed by SAP support (SAP NOTE). I'm intrigued due to the fact the ID does not need any permission at all. I would like an understanding of such a setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 17:51:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382453#M1042528</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-18T17:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382454#M1042529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Wes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have the note number? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's portal related then Satish's answer looks good, if it's not then I'm not so sure.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 18:08:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382454#M1042529</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-18T18:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382455#M1042530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it's portal related, the links provided helpdes a lot. By this is in reference to SAP note 606745.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Wes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 18:13:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382455#M1042530</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-18T18:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382456#M1042531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; I'm intrigued due to the fact the ID does not need any permission at all. &lt;/P&gt;&lt;P&gt;By the sound of it, this is a "service" (see object S_SERVICE) which is not checked and whatever that service does... it is not invoking any authority or permission related checks (or is possibly running under a different user context - a service type user, or an RFC destination has the authority to do what-ever-it-does anonymously).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case, I would recommend 3 aspects to take a closer look at:&lt;/P&gt;&lt;P&gt;- Check your system config - to authenticate and authorize the anonymous service call.&lt;/P&gt;&lt;P&gt;- Who can access the service or the RFC - this is often on the application or even client side.&lt;/P&gt;&lt;P&gt;- Which authority does that service or RFC have - so that it cannot do more than you want it to do anonymously.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 20:11:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382456#M1042531</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-08-18T20:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous Logon</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382457#M1042532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2008 15:30:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/anonymous-logon/m-p/4382457#M1042532</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-05T15:30:42Z</dc:date>
    </item>
  </channel>
</rss>

