<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: USR40 - password in exception list error message in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327350#M1395574</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;You will make a greater security gain, with much less effort and frustration... by simply requestion a minimum of 1 special character in the password.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Julius. I was wondering if maintaining parameters such as the below ones would answer the external audit check for password rules.&lt;/P&gt;&lt;P&gt;login/min_password_digits&lt;/P&gt;&lt;P&gt;login/min_password_letters &lt;/P&gt;&lt;P&gt;login/min_password_specials&lt;/P&gt;&lt;P&gt;Do we still need the USR40 table maintained after the above parameters are maintained? In our case login/min_password_digits and login/min_password_letters both have a value 1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, my actual question :)..It may not be possible for us to inform the 4000+ users...so somehow we wanted them to be notified in a user-friendly way...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you are right...if one is aware of the exception list then some possibilities may be eliminated :)...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Nov 2009 19:53:02 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-11-06T19:53:02Z</dc:date>
    <item>
      <title>USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327346#M1395570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;At our company, we planned to maintain USR40 table with easily guessed passwords. We ended up preparing a quite a big list. There are as many as 4000 users and we are afraid that this may create a big impact. I say impact because the error message that pops up when user changes his password to one of the exceptional ones is as following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Password is in exception table"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we change the above error message to a customized one? We want to make it some what more detailed so that users are not frustrated.&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 15:45:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327346#M1395570</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T15:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327347#M1395571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe you should be able to edit the message text in SE91, the message number is 194, but I have never edited this text - you will need to ensure the message class is entered as well. I suggest a trawl through the help for SE91 message maintenance and working with appropriate team to maintain these messages, as they're SAP standard. I think the message class for this one is 00.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: tvenables on Nov 6, 2009 4:58 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 16:30:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327347#M1395571</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T16:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327348#M1395572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tom for your reply...May be I should contact the ABAP team for the change...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be great if someone can let me know the steps to be followed..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 19:02:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327348#M1395572</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T19:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327349#M1395573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; We ended up preparing a quite a big list. &lt;/P&gt;&lt;P&gt;You will make a greater security gain, with much less effort and frustration... by simply requestion a minimum of 1 special character in the password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is particularly true if your "very big list" does not yet have any special characters in it... &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another usefull trick is to let each user know that there is this rule in the password's structure which they need to adhere to, without them having to take a guess at which pattern is permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, from gaps in patterns you can even take a better guess at what the admin's password is.... Mwwaahhh ha haha!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My 2 cents,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 19:26:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327349#M1395573</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T19:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327350#M1395574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;You will make a greater security gain, with much less effort and frustration... by simply requestion a minimum of 1 special character in the password.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Julius. I was wondering if maintaining parameters such as the below ones would answer the external audit check for password rules.&lt;/P&gt;&lt;P&gt;login/min_password_digits&lt;/P&gt;&lt;P&gt;login/min_password_letters &lt;/P&gt;&lt;P&gt;login/min_password_specials&lt;/P&gt;&lt;P&gt;Do we still need the USR40 table maintained after the above parameters are maintained? In our case login/min_password_digits and login/min_password_letters both have a value 1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, my actual question :)..It may not be possible for us to inform the 4000+ users...so somehow we wanted them to be notified in a user-friendly way...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you are right...if one is aware of the exception list then some possibilities may be eliminated :)...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 19:53:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327350#M1395574</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T19:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327351#M1395575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on how you set the login/* parameters - as this will influence not only the structure of the password but also the likelihood of a certain pattern.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A classical example is if the password validity period is set to 30 days, then including the months (January, February, etc) is a good idea. More likely you have 90 days, so including the seasons will be a significantly better idea. But one special character somewhere in the password combined with a lock counter set to 5 (my recommendation) is much easier for the users to remember (as a rule, not the password...) and you to communicate to them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally, when I get this USR40 message, then I do think a bit about the password quality and have a little list of known "silly passwords" like 'ASDF', 'SUMMER', 'TEST', etc which I maintain, but that's it. It should really be self-explanatory to the user that their password is rubbish. Otherwise, don't include it in the USR40 and concentrate on the special characters and possibly even 1 number to "break" the word or phrase.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; It may not be possible for us to inform the 4000+ users...so somehow we wanted them to be notified in a user-friendly way...&lt;/P&gt;&lt;P&gt;SM02 system message is one option. A session_manager transaction start at next logon is another. There is also an exit in the SAPGui logon program you could use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cool is also an email from the CEO to all employees, after you hack his / her password in a (legal!) audit &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 20:09:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327351#M1395575</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T20:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327352#M1395576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 20:18:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327352#M1395576</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T20:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: USR40 - password in exception list error message</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327353#M1395577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This table actually has an amusing history, but as you have closed the thread I will save that for another day &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you take a read through the FAQ sticky thread at the top of the forum page, you will find a hint in the thread about "forcing" passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 21:53:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/usr40-password-in-exception-list-error-message/m-p/6327353#M1395577</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-06T21:53:21Z</dc:date>
    </item>
  </channel>
</rss>

