Application Development and Automation Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Security note 1576763 - rdisp/auth_check_user_list

Former Member
0 Likes
1,037

Hi All,

In one of the security notes it is advised to set parameter rdisp/auth_check_user_list to TRUE. However, for us it is not clear what this parameter actually does. There is no documentation available on the support portal nor in the documentation in the system itself.

Does anyone know what the parameter actually does? Also does it have any side-effects that we have to be aware of before implementing it?

Thanks!

Maaike

1 ACCEPTED SOLUTION
Read only

Former Member
0 Likes
873

Hi,

From what I can make out from from the OSS note:

TH_USER_LIST is a remote enabled FM which can be called by RFC from another system. Triggering the FM will provide a list of users logged into that destination. In conjunction with the OSS note, setting rdisp/auth_check_user_list = TRUE will force an additional authorisation check against the FM for S_RZL_ADM therefore requiring the RFC user in the target system to have admin authorisations to be able to return this information.

Hi All,

In one of the security notes it is advised to set parameter rdisp/auth_check_user_list to TRUE. However, for us it is not clear what this parameter actually does. There is no documentation available on the support portal nor in the documentation in the system itself.

Does anyone know what the parameter actually does? Also does it have any side-effects that we have to be aware of before implementing it?

Thanks!

Maaike

4 REPLIES 4
Read only

Former Member
0 Likes
874

Hi,

From what I can make out from from the OSS note:

TH_USER_LIST is a remote enabled FM which can be called by RFC from another system. Triggering the FM will provide a list of users logged into that destination. In conjunction with the OSS note, setting rdisp/auth_check_user_list = TRUE will force an additional authorisation check against the FM for S_RZL_ADM therefore requiring the RFC user in the target system to have admin authorisations to be able to return this information.

Read only

0 Likes
873

Hi,

I have seen that, but how do I translate that into more functional language? I'm not sure what that function module actually does and what it means that access is being restricted. Can it do any harm?

Thanks

Maaike

Read only

0 Likes
873

The function module presents a list of logged on users. I assume the logic behind it is to reduce the information available to perform an exploit using a known active userID.

Read only

0 Likes
873

I understand the intention, but I'm worried about possible side-effects. Just spoke to a Basis consultant about this and his guess is that the only potential side-effect could be the proper working of transaction AL08 (logged on users across all application servers). If that is the case, then we'll have to figure out next steps.