<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trusted RFC - Difference between actual user and batch user in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701147#M1769149</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_RFCACL and S_RFC are two separate authorization objects. The user needs S_RFC in the RFC server system to get authorizations to run server functions called through RFC. The S_RFCACL is to attach the trusting user to the trusted user. In a trusted/trusting connection the trusting user must have both authorization objects, S_RFC and S_RFCACL.&lt;/P&gt;&lt;P&gt;In ALE scenarios it is suggested to use a communication type user like "ALREMOTE". As it is not a dialog user nobody can logon with this through SM59 but it can be used for RFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Endre.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Sep 2013 07:10:37 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2013-09-18T07:10:37Z</dc:date>
    <item>
      <title>Trusted RFC - Difference between actual user and batch user</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701144#M1769146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we discuss at the moment the opportunity to use only Trusted RFC Conenction between our sap-systems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the most cases we want to use a Trusted connection with the actual user. This mean i need my user also in the target system with the authorizations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other setting is, that we use Trused with a batchuser - not actual user.&lt;/P&gt;&lt;P&gt;In this case it looks like a connection without trusted - Only difference is for me that i do not have to assign a password into the rfc and the user needs authorizations for trusted (S_RFCACL).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this correct or do you have some more informations regarding the difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my first understanding the difference between trusted with a batchuser and non trusted with a batchuser is only the password topic - You do not need to assign a password into the rfc, the authorization topic with trusted rights and you have to connect the systems via Trusted/Trusting.&lt;/P&gt;&lt;P&gt;But maybe iam wrong &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you see this topic from security points?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Sebastian Konrad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Sep 2013 15:23:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701144#M1769146</guid>
      <dc:creator>sebastian_konrad</dc:creator>
      <dc:date>2013-09-16T15:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted RFC - Difference between actual user and batch user</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701145#M1769147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sebastian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the user stored in the RFC destination must not be a dialog user, otherwise anybody with access to the destination (SM59) can logon with this user to the target system. In a trusted/trusting connection the trusted dialog user must have a trusting dialog user connected by S_RFCACL and can only logon as the user which is connected to his trusted user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Endre Udvaros.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 13:36:57 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701145#M1769147</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2013-09-17T13:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted RFC - Difference between actual user and batch user</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701146#M1769148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Endre,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer - If i understand it correct it is no difference which way i use? Only the authorizations (S_RFCACL &amp;lt;-&amp;gt; Instead of only S_RFC).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it a problem when someone uses such configurations with trusted and a batch user in an ALE szenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are your settings and why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Sebastian Konrad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 06:22:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701146#M1769148</guid>
      <dc:creator>sebastian_konrad</dc:creator>
      <dc:date>2013-09-18T06:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted RFC - Difference between actual user and batch user</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701147#M1769149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S_RFCACL and S_RFC are two separate authorization objects. The user needs S_RFC in the RFC server system to get authorizations to run server functions called through RFC. The S_RFCACL is to attach the trusting user to the trusted user. In a trusted/trusting connection the trusting user must have both authorization objects, S_RFC and S_RFCACL.&lt;/P&gt;&lt;P&gt;In ALE scenarios it is suggested to use a communication type user like "ALREMOTE". As it is not a dialog user nobody can logon with this through SM59 but it can be used for RFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Endre.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 07:10:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/trusted-rfc-difference-between-actual-user-and-batch-user/m-p/9701147#M1769149</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2013-09-18T07:10:37Z</dc:date>
    </item>
  </channel>
</rss>

