<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cua_Admin User in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256259#M1384375</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem is that RFC connections used by CUA are using user CUA_ADMIN. If you want to change it then you need to [modify|http://help.sap.com/saphelp_nw04/helpdata/en/4c/b5b13bbaac1c3ce10000000a11402f/frameset.htm] all RFC connections from child systems to central system. But I agree that it does not make too much sense to just change user name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Oct 2009 09:02:06 GMT</pubDate>
    <dc:creator>mvoros</dc:creator>
    <dc:date>2009-10-20T09:02:06Z</dc:date>
    <item>
      <title>Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256255#M1384371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have CUA linked in with our Solman and during the auditing time,  auditors  are recommending we do not use CUA_ADMIN user, but instead assign the CUA_ADMIN roles to specific users and get rid of this generic account. Is there any note which specifies that CUA_ADMIN user should not be deleted. I know we should'nt be deleting it. Just need the advice wether we should go ahead with this or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Avneesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 04:48:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256255#M1384371</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T04:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256256#M1384372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there is a similar question already [answered on this forum|&lt;A class="jive_macro jive_macro_thread" href="https://community.sap.com/" __jive_macro_name="thread" modifiedtitle="true" __default_attr="1477013"&gt;&lt;/A&gt;;. By default CUA_ADMIN user has SAP_ALL which is why the auditors and SAP don't recommend to use this account. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW why don't you just lock CUA_ADMIN user?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 05:32:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256256#M1384372</guid>
      <dc:creator>mvoros</dc:creator>
      <dc:date>2009-10-20T05:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256257#M1384373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Martin for the quick response. &lt;/P&gt;&lt;P&gt;But we have already removed SAP_ALL from this user. Moreover if we lock the user then the RFC connection to the child systems wont be establish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Avneesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 05:37:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256257#M1384373</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T05:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256258#M1384374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Avneesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like you have already done the important bit which is assigning the correct auths to your user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ask your auditors what the difference is between assigning the same auths to CUA_ADMIN or another system user of a different name.  I bet they do not come up with a serious answer.  Unless they can justify it, dispute their finding and you will be OK.  The important thing is to have the user for CUA connections with the correct auths and set to the correct user type.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 08:22:36 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256258#M1384374</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T08:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256259#M1384375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem is that RFC connections used by CUA are using user CUA_ADMIN. If you want to change it then you need to [modify|http://help.sap.com/saphelp_nw04/helpdata/en/4c/b5b13bbaac1c3ce10000000a11402f/frameset.htm] all RFC connections from child systems to central system. But I agree that it does not make too much sense to just change user name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 09:02:06 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256259#M1384375</guid>
      <dc:creator>mvoros</dc:creator>
      <dc:date>2009-10-20T09:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256260#M1384376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; But I agree that it does not make too much sense to just change user name.&lt;/P&gt;&lt;P&gt;It can however be a start from the perspective of the master system for the text comparison, particularly if you don't have the destination names and logical system names the same and want to keep them apart.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bugger with CUA is that even if you remove SAP_ALL, the user will still by design have strong user administration authorizations... e.g. could create a new user with sufficient authorizations to administrate itself, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An alternative is to use Trusted RFC (possibly even with a current user flag setting for the admins) and then use object S_ICF to restrict access &lt;STRONG&gt;on the client side of the call&lt;/STRONG&gt; to even call or display the destination. This way, groups of destinations can be protected from user's outside of  a certain role (like user admins...) but the destination can still do it's powerfull tasks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can recommend looking into this for CUA as a good example. With a small effort, you will quickly achieve a big security gain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the documentation on the object before activating it, as it is "shared" with S_RFC_ADM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 09:17:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256260#M1384376</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T09:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256261#M1384377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you still need to keep the CUA_ADMIN user is for RFC connections only then why dont you change the userID type from Dialog to system/communications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 12:06:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256261#M1384377</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T12:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256262#M1384378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly Alex!!  I have dropped the mails to auditors. lets see what the points they have regading this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the Reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Avneesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 12:31:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256262#M1384378</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T12:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256263#M1384379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Julius!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Atleast learnt new thing today. Appreciate the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Avneesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 12:35:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256263#M1384379</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T12:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cua_Admin User</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256264#M1384380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everyone for the effort. I am working on it and will update you all with the best solution i found in this case as soon am done it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Avneesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 12:37:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/cua-admin-user/m-p/6256264#M1384380</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-20T12:37:09Z</dc:date>
    </item>
  </channel>
</rss>

