<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Password Rule for System Users in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504648#M1259111</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Yes, it will continue with same password, but when you change the new it will take new method&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Exactly. And that is exactly where it can cause a big problem or force you to use less secure methods with less usability features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not change the password, then it will remain protected from changed rules if the user type is &lt;EM&gt;correct&lt;/EM&gt;... in which case it is your responsibility to protect the password over time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you take a look in USR02 in old clients, you might even find Type D users with code version A hashes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is why cardinality of connections is important...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Apr 2009 19:49:42 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-04-30T19:49:42Z</dc:date>
    <item>
      <title>Password Rule for System Users</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504642#M1259105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are planning to implement new password rule to incorporate minimum 1 digit in the password using RZ10 parameter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is - what would happen to the system users that are already created in the system?&lt;/P&gt;&lt;P&gt;Would the system users continue to function with their original passwords?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2009 12:43:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504642#M1259105</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-28T12:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Password Rule for System Users</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504643#M1259106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They can continue till next password changes (From the server restart)&lt;/P&gt;&lt;P&gt;If u r changing password duration it will calculate from last changes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2009 13:42:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504643#M1259106</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-28T13:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Password Rule for System Users</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504644#M1259107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ravi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password for System Users do not expire, password duration is not applicable to them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Apr 2009 13:46:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504644#M1259107</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-28T13:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Password Rule for System Users</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504645#M1259108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the rules are only checked on new passwords not existing ones - I recall implementing such complex password rules once and having the same concerns you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we made the change in development we noticed no issues with existing users and their passwords, but when we changed passwords going forward after the change, we had to have the specified number of digits.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2009 13:41:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504645#M1259108</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-30T13:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Password Rule for System Users</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504646#M1259109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can instruct the system to force a password change (and therefore enforce the new rules) even before it's validity has expired by changing the default of the system profile parameter login/password_compliance_to_current_policy from 0 to 1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this is only available in higher releases and SYSTEM and SERVICE type users are exempted from password rules for existing passwords and cannot change their own either (unless authorized to administrate their own user group) so this will not work for you - except being usefull as a "big hammer" to find incorrect user types...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best solution in my opinion is to &lt;STRONG&gt;first&lt;/STRONG&gt; correct the cardinality of your users with saved logon data (ensure 1:1 connections) so that the calling system can always be identified by the name of the user ID in the target. When you have isolated them, then you can generate a new password for the user in the target and maintain it in the source in virtually one go. This is also an important prerequisite for restricting their authority in a meaningfull way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't have the cardinality of the user ID's sorted out first, rather don't change anything yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some tips:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Download RFCDES to Excel per SID to document your progress and changes.&lt;/P&gt;&lt;P&gt;- Create the new users first in the target client (SU01) with the old access...&lt;/P&gt;&lt;P&gt;- Use 8 character upper-case passwords, so that these users do not force the whole system to remain downwardly compatible.&lt;/P&gt;&lt;P&gt;- Use a naming convention for them so that you can range SM19 user filters.&lt;/P&gt;&lt;P&gt;- Then switch the RFC logon data in the sources (SM59).&lt;/P&gt;&lt;P&gt;- Monitor the RFC calls on the new users with SM19 dynamic filters (to be able to build their role).&lt;/P&gt;&lt;P&gt;- Download the Server RFC profiles for the old users from ST03N to start with.&lt;/P&gt;&lt;P&gt;- Monitor the RFC logons of the old users with RSUSR200 until they stop.&lt;/P&gt;&lt;P&gt;- Remove the roles of the old users (but not delete or lock) and monitor ST22 for dumps.&lt;/P&gt;&lt;P&gt;- Insert the Function Module into the menu of the role and maintain SU24 for them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you don't have to write the passwords down, and if you need to change it you can for 1 connection without bombing out the others. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that, there are some "tricks" to synchronize the passwords of SYSTEM and SERVICE users (because the initial password is the productive one already). But generally they will mostly weaken your security at the same time and force you into using very granular security in authorizations and config, even if the trick is designed as a needle in a haystack...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or alternately use trusted RFC to eliminate the password completely, but you need to be very carefull with that as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers and good luck,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2009 15:18:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504646#M1259109</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-30T15:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Password Rule for System Users</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504647#M1259110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it will continue with same password, but when you change the new it will take new method&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2009 17:55:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504647#M1259110</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-30T17:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Password Rule for System Users</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504648#M1259111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Yes, it will continue with same password, but when you change the new it will take new method&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Exactly. And that is exactly where it can cause a big problem or force you to use less secure methods with less usability features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not change the password, then it will remain protected from changed rules if the user type is &lt;EM&gt;correct&lt;/EM&gt;... in which case it is your responsibility to protect the password over time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you take a look in USR02 in old clients, you might even find Type D users with code version A hashes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is why cardinality of connections is important...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2009 19:49:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/password-rule-for-system-users/m-p/5504648#M1259111</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-30T19:49:42Z</dc:date>
    </item>
  </channel>
</rss>

