<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Communication vs. System User Types in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927129#M1599357</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was researching something else when I came across an article or note (forgot already) but what I do remember is that SAP was moving more towards System ids and not using Communication Ids. Furthermore Communication ids could be changed over to System ids with no impact (to account behavior).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My searches have come up short and now seeking out to see if any one read this or has insights into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Jun 2011 20:11:48 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2011-06-21T20:11:48Z</dc:date>
    <item>
      <title>Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927129#M1599357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was researching something else when I came across an article or note (forgot already) but what I do remember is that SAP was moving more towards System ids and not using Communication Ids. Furthermore Communication ids could be changed over to System ids with no impact (to account behavior).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My searches have come up short and now seeking out to see if any one read this or has insights into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 20:11:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927129#M1599357</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-06-21T20:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927130#M1599358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What were your search terms?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are several discussions about this on SDN and the better ones reference SAP Note 622464.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are also many other SAP notes which describe symptoms of this user type problem in applications (Workflow, STMS, IS-* ... all the usual suspects  &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 20:44:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927130#M1599358</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-06-21T20:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927131#M1599359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are definately helpful. As for the part around moving away from "Communcation" user types and only use "System", any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know eRecruit needs to use Communication users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Matt Urban on Jun 21, 2011 1:57 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 20:55:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927131#M1599359</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-06-21T20:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927132#M1599360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know eRecruit needs to use Communication users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;There is a use-case for this when the end-user should be named as the communication partner but should not be SAPGui capable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Communication users are personalized backend users for real humans in this case, who can also change their own passwords via non-SAP protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In those cases you typically use real SSO anyway and delete the password, so can also use SYSTEM users for them if there are no licensing implications and they do not / should not be able to start external http debugging calls to the backend...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not aware of any defendable use-case for COMMUNICATION type users anymore, but suspect that you want HR applicants to have their own accounts in the backend and they are still using their own named IDs and passwords of the backend sytem. Okay... maybe there is a use case still.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When making the change, you need to consider:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SYSTEM type users cannot change their own passwords.&lt;/P&gt;&lt;P&gt;SYSTEM type users do not need to change their own passwords based on password rules.&lt;/P&gt;&lt;P&gt;SYSTEM type users cannot &lt;U&gt;issue&lt;/U&gt; SAP login tickets, but &lt;STRONG&gt;can&lt;/STRONG&gt; accept them if issued by the calling system (external portal?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In all three cases, you have a higher level of security &lt;STRONG&gt;against&lt;/STRONG&gt; DoS attacks and client / server side "identity hoppers" (proprietary terminology of Julius Bussche...:-) by using SYSTEM type users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As of release 7.30 you can also assign security policies directly to the users which will give them a different password policy to follow than the RZ11 login parameters (until they pass the interview... and become employees, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not familiar with eRecruit. Does the implemention guide recommend COMMUNICATION type users explicitly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 21:28:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927132#M1599360</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-06-21T21:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927133#M1599361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;In all three cases, you have a higher level of security &lt;STRONG&gt;against&lt;/STRONG&gt; DoS attacks and client / server side "identity hoppers" (proprietary terminology of Julius Bussche...:-) by using SYSTEM type users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting statement. Could you explain or provide documentation into how-so? Its my understanding that both System and Communication user types can be leveraged for external RFC connections and system-to-system communications and would be suspect to DoS &amp;amp; "identity hopping" (C) Julius Bussche. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have marked this thread as answered but your statement has sparked an intriguing path I would like to travel down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 21:39:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927133#M1599361</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-06-21T21:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927134#M1599362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you can interactivately change the password (as is the case with COMMUNICATION type users), then you can:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) Break the existing interface(s) as their previously correct passwords fail.&lt;/P&gt;&lt;P&gt;b) Logon with the new password from your own client application where you have more access.&lt;/P&gt;&lt;P&gt;c) Logon to systems which issue SSO2 logon tickets and then find interfaces which make subsequent calls to other systems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For me these are 3 very good reasons to avoid COMMUNICATION type user ID's, particularly if they have saved logon data in connection configurations (SM59, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 21:59:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927134#M1599362</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-06-21T21:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927135#M1599363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks great points.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 22:00:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927135#M1599363</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-06-21T22:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927136#M1599364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I read your answers I feel like I hardly know anything in SAP security. &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.sap.com/1024/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 10:47:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927136#M1599364</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-10-03T10:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Communication vs. System User Types</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927137#M1599365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well... you used the search (winner) and now you know this (another winner), so you will be fine..&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Oct 2014 11:18:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/communication-vs-system-user-types/m-p/7927137#M1599365</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-10-03T11:18:38Z</dc:date>
    </item>
  </channel>
</rss>

