DDIC and SAP* changing into usertype system

In order to secure the Standard Users DDIC and SAP* against misuse i
planned to change them into SYSTEM accounts instead of DIALOG.
Is there, in case of a standard SAP implementation, any indications that
we shouldn´t do this?
In the guidelines and forums i couldn't find any arguments against
such a situation.
The SAP* accounts is further secured by setting the system profile
parameter 'logon/no_automatic_user_sapstar' to 1.
Thanks in advance for your reactions.
With kind regards,
Edwin Stam

As of release 7.00 EhP1 there is a new procedure for this.
See --> Lock DDIC user but keep the RDD* jobs working. and the link to the help.sap.com documentation.
The users are already blocked from authenticating via trusted RFC. Changing the user type to system will also prevent them from being used on the issuing system for SAP Logon Tickets as well as attaching a SAPGui to a logon session in the backend systems. You can also disable the password in SU01 (which will delete the password hash).
Alcatraz for standard users...
Cheers,
Julius
Edited by: Julius Bussche on Dec 16, 2009 3:28 PM

Similar Messages

  • When are DDIC and SAP* used in Client 066 and 001

    Hi everyone,
    Can someone please shed some light on when DDIC and SAP* users are supposed to be used in logging into client 066 and 001?
    Your inputs will be greatly appreciated.
    Thanks!
    Divine Grace Banzon

    User DDIC is a user with special privileges in installation, software logistics, and the ABAP Dictionary. The user master record is created in clients 000 and 001 when you install your R/3 System.
    User SAP* is default superuser in SAP System, in the clients 000 and 001. A user master record is defined for SAP* when the system is installed. However, SAP* is programmed in the system and does not require a user master record.
    Hope this will help.
    -Pinkle

  • DDIC AND SAP*

    Hi
       Kindly let me know the what is the difference between DDIC and SAP* .
    Selvan

    Hello ,
    SAP* is the only user in the SAP System that does not require a user master record, SAP* has by default the password PASS, as well as unlimited system access authorizations.
    To secure SAP* against misuse, you should at least change its password from the standard PASS. For security reasons, SAP recommends that you deactivate SAP* and define your own superuser.
    The maintenance user for the ABAP Dictionary and software logistics, user DDIC.
    The user master record for user DDIC is automatically created in clients 000 and 001 when you install your SAP System. User DDIC special privileges for certain operations. For example, DDIC is the only user that is allowed to log on to the SAP System during an upgrade.
    "But, in which * Parameter Name* i have to activate"
    login no_automatic_user_sapstar  1

  • Unable to access user DDIC and SAP*

    +Hi GURUS,+
    +I installed solutionmanager 4.0 and i loggen in the system(000) with DDIC user and check the TCODE SICK.+
    ++When i restarted the server it was not allow me to login awith user  DDIC and SAP in 000 client.++*
    +It's giving error message:+
    +Password log on nolonger possible too many times failed attempts.+
    ++Could you please help me out is there any way to set DDIC and SAP from windows level(i mean sap inst directry..usr/sap/<sid>/sys/profile)*
    Regards
    JAn

    Hi,
    Unlock it at Database level
    UPDATE usr02 SET uflag = 0 WHERE bname = "SAP*" AND mandt = <client number>
    Or
    Run the sql query at sql prompt and then login to sap with sap* and password "pass".
    SQL> delete from usr02 where mandt=<your login client> and banme='SAP*';
    Rakesh

  • DDIC and SAP* locked due to bad logins

    Hi!
    I'm setting up a WAS 7.0/CRM5.1 system and have encountered som problems.
    My DDIC and SAP* users have been locked in both the production client and the 000 client.
    I found a note on how to solve this and that was to delete the SAP* from the USR02 table. Then the password would be PASS and I would be able to log on.
    I deleted the SAP* user from client 000, but I stil can't log on! Should the user be deleted in the other clients as well or have I done something bad?
    regards
    rollo

    - enter oslevel as user <sid>adm of ora<sid>
    - on oracle use e.g. sqlplus, connect as sapr3 (resp. sap<SID) and enter <i>delete from usr02 where mandt = '000' and bname = 'SAP*';</i> then <i>commit;</i>
    - as of WebAs 7.0 it's forbidden by default to logon as SAP* so you also have to set profile parameter and restart the system.
    see also SAP note <a href="https://websmp201.sap-ag.de/~form/handler?_APP=01100107900000000342&_EVENT=REDIR&_NNUM=68048&_NLANG=E">68048</a> and <a href="https://websmp230.sap-ag.de/sap(bD1kZSZjPTAwMQ==)/bc/bsp/spn/sapnotes/index2.htm?numm=0000862989&nlang=E">862989</a>

  • Integrate Other SAP Worklist into CRM System

    Dear Guru,
    I have successfully call the work item in ECC to CRM,
    the workitem is generated from workflow and will call a dialog program
    I've maintain the "Transaction Launcher Logical Systems and URLs"
    the URL i've maintained is directly from URL that has been given when I test the ITS Service in ECC,
    then I paste it to the configuration above
    http://xxx.ccc.aaa:8000/sap/bc/gui/sap/its/zhleave?
    but it call a wrong program, n after I trace the URL that CRM call is
    http://xxx.ccc.aaa:8000/sap/bc/gui/sap/its/zhleave?transaction=ZHLEAVE&OKCODE=ONLI&P_ACTION=DISPLAY&P_WI_ID=000000517557
    Can you help me, which configuration that will add the additional paramater in that URL?
    Please need your guidance indeed....
    BR,
    Robin

    Hi,
      To intergrate SAP WebDynPro into crm, we should consider the following steps
    1.) Create Business Partner Role under Tr. CRMC_ui_Profile and PFCG.
    2.)Check whether internet tool contain client id.
    3.)Check Tr:SU01 for autorizations
    Regards
    Subbaraju

  • Loading transaction data to CRM and SAP/R3 from legacy system

    Where can I find information about expected timing to load orders from a legacy system to CRM and SAP R/3? Does anyone know how long it would take to do the update in CRM using RFC's and BAPI's and then load to SAP/R3 if the order had an average of 3.2 line items per order and there were 50.7 million orders? It is assumed we would run multiple loads concurrently. So I guess a better question is how long does it normally take to load one order with 3.2 line items onto CRM and also SAP R/3?
    Any advise would be greatly appreciated. Thank you.

    Hi Qutubuddin,
    Can you please let me know how you achieved moving data from non sap system to r3 using webdynpro java?
    thanks
    sunil

  • Error While importing SAP query into quality system

    Hi,
    When Itried to import the dataset(Transport Request)  generated in develoment system into Quality system I am getting the following error.
    Query already exists and Infoset contains a structures which is not there in data dictionary .
    How to oversome this error to import successfully into quality system
    thanks

    hi,
    You need to transport your Z tables to the quality.
    Make sure you transport all the data elements , domain.. etc to the quality.
    Thats why its giving you the error.
    It does not find the Z tables in Quality
    Regards,
    Vinod

  • Link between SAP BW and SAP R/3 (Source System)

    Dear all,
    I want to create a source system connecting BW to Sap R/3.
    I have, I think, correctly fill the different fields.
    But I have an issue regarding activation of this source system.
    I can not activate the source system, I have the following error message : Result of the destination check: Client 602 is not available. Please choose an existing client RSAR 375.
    Is there someone who could help me to resolve this issue.
    Best Regards,
    Gregory

    Seems that client 602 does not exist.
    Are you sure that client 602 exist in R/3 system?
    If it does then check if you are pointing to the right R/3 system, otherwise provide a valid client number.
    Hope it helps,
    Andreu

  • All my .mov and DV changed into these wierd files ive never heard of Before.

    Did my computer get infected with some wierd virus? the files are named some bizarre binary code EXAMPLE:
    þü-¤é¯à.±Œ© date modified reads as dec 31st 1903 1:30 PM it says it is zero kb for file size and kind says ALIAS...
    Very strange all the files have a different wierd binary language and the modified dates are all dec 31st 1903.. 57 files have been affected.. they were all .MOV files or DV files before...this incident..now they dont work and are not recognized by finder..when i go to "get info" the dialog box appears for a half a second then dissapears..

    Hi Gary, is this the biit drive?
    Could be many things, we should start with this...
    "Try Disk Utility
    1. Insert the Mac OS X Install disc, then restart the computer while holding the C key.
    2. When your computer finishes starting up from the disc, choose Disk Utility from the Installer menu at top of the screen. (In Mac OS X 10.4 or later, you must select your language first.)
    *Important: Do not click Continue in the first screen of the Installer. If you do, you must restart from the disc again to access Disk Utility.*
    3. Click the First Aid tab.
    4. Select your Mac OS X volume.
    5. Click Repair Disk, (not Repair Permissions). Disk Utility checks and repairs the disk."
    http://docs.info.apple.com/article.html?artnum=106214
    Then try a Safe Boot, (holding Shift key down at bootup), run Disk Utility in Applications>Utilities, then highlight your drive, click on Repair Permissions, reboot when it completes.
    (Safe boot may stay on the gray radian for a long time, let it go, it's trying to repair the Hard Drive.)
    If perchance you can't find your install Disc, at least try it from the Safe Boot part onward.

  • I hear that Apple has been hacked and viruses uploaded into the system. Is this true?

    My trusted friend informed me that Apple has been hacked and viruses are being uploaded. Better find out the truth....so, is this true?

    Have a read from the New York Times:
    http://www.nytimes.com/pages/technology/index.html?adxnnl=1&adxnnlx=1333795205-E mIT8EJSN69/qTw5iqTTxA
    Ciao.

  • How to change the original system of a CR?

    Dear gurus,
    we have imported some workbench and customizing CRs into a system B mannually from system A,
    there is no transport link between A and B.
    But when we want to import those CRs into system C , which has transportation link with B, we can not found those CRs, i guess because those CRs is release on A ,not B.
    Could you please help me how to import those CRs into system C, just like other 'normal' CRs?
    do i need to modify the original system of the CRs? if so , could you pls tell me how to do that?
    thanks and best regards.
    Jun

    Hi Nicole,
    there are many system objects inside our CR, DDIC, FM ...
    so we can not  change them one by one.
    what we are trying to do is to port a custom solution from one system to another,there is no link between them , and in the target system, those CRs can be transport to other systems normally using STMS.
    we are trying to include those crs into a new cr in the target system , but failed.
    could you please provide more informaiton on how to solve this?
    thanks and best regards.
    jun

  • SAP MDM 5.5 System Copy

    Hello we receive from the business a request to do an refresh of our SAP MDM 5.5 QA system with the MDM 5.5 Production system.
    But I didnu2019t find any informationu2019s about this process on SAP MarketPlace neither in Googleu2026..
    Does anybody know what is the step for doing such a refresh ?
    Or where could I find info about this ?
    Many thanks in advance for your help.
    Dom./

    Hi  Dominique,
    You can create an Archive file to the repository from production environment and unarchive it into QA system.
    This will this repository will be exactly same as production.
    To create an Archive file follow following steps:
    1. Open MDM console and mount MDM Prod server. Right click on the repository and select "Create Archive".
    2. this will create a file with .a2a extn on MDM server Archive directory.
    To unarchive repository in QA follow below steps:
    1. Copy .a2a file of Prod repository from Prod MDM server archive directory and copy in QA MDM Server archive directory.
    2. mount QA MDM server in Console and right click and select Create Repository from Archive. This will open a popup window. specify DBMS details here and .a2a file of Prod repository.
    this way new QA repository will have exact same data and configurations from PROD repository. You can also over write an existing QA repository instead of creating a new repository using .a2a file of Prod repository.
    Hope this will help. Revert if  you have any question.
    BR,
    Shiv

  • PS CS6  - text and font changes by clicking on it - not reversible

    Sometimes I open a file with layers in PS and click on a text layer, to move or change it,
    and immediately the text and font changes into another text/font from the document.
    Can not save the file then the problem stays forever. I can´t touch/change any text layer
    without this problem. Happens on every ca. 10th - 20th file  I open...
    Please help me, how can this be fixed?

    There was a bug in 13.0.0 that could corrupt text layers that way.
    It was fixed in 13.0.1, but documents saved with 13.0.0 could already be corrupted and there is no way to fix them automatically.

  • Extracting data from SAP and dumping it into Non SAP System

    Hi All,
    We have an MS based in house system.  For our business process improvement, we need to import our customer's data and dump it into our application that has SQL server database - Our customers are running SAP.  Wanted to find out what steps we need to follow from the design perspective... also I am assuming we wll need an access to our customer's system to  code RFCs - is that correct ? Any information will be highly appreciated.
    Thanks,
    Neelima.

    Hi,
    it's really hard to answer your question without additional knowledge of your landscape. SAP support many ways of integrations. One way is using RFC. You would simply call function modules from your .NET application using RFC library. Another way is using web services. You can easily expose any RFC enabled function module as web service (if you are on NetWeaver). Another solution is using REST interface. Recently, there have been many articles dedicated to this approach here on SDN. This can be pretty nifty solution. Another way is file based integration (IDocs or simple flat files transfered via FTP).
    Cheers

Maybe you are looking for

  • Advice please: how to link java client with oracle AS

    Dear Sirs... how can i link java swing application with oracle application server? do i have to develop web service and then deploy it on the AS? or i should use another methodology? what exactly should i provide or should i use? thanks for any help

  • How to get result in comma separated

    I have the follwing query with simple join select c.f_category_id,c.f_category_name,sc.f_subcategory_id,sc.f_subcategory_name from mcp_adv_category c join mcp_adv_category_trans ct on c.F_CATEGORY_ID =ct.F_CATEGORY_ID join mcp_adv_subcategory sc on c

  • Dates for import are all wrong

    Hiya - I have been trying to import clips made last week. The date is correct but the year is 2009. They will put themselves into a 2009 event folder with other projects in. I have tried to create a 2010 event folder and drag the project into it but

  • How to pass command line arguments to JWS app

    Hi, I want to pass command line arguments to my JWS application. However those arguments are dynamic (eg the username of the user who launched the app) and thus I can not use the argument tag of JNLP file. So what do I need to do in this case? Thanks

  • Any script to start Replication and Caching automatically?

    yes, I know there're two stored procedures to start Replication and Caching, ie. call ttRepStart() and call ttCacheStart(). but, is there any methods, like unix shell script, to start them easily? i can't find on the installation provided. thanks!