How to block modification of a VPN profile ? (password and address)

Hello,
we use iPhone Configuration Utility 2.2 to deploy the iPhone in our Enterprise and we are surprised by the fact that it's impossible to block the modifications a parameter configured in the profile.
For example, for VPN, it's possible for the end-user to change the address of connection.
But our biggest problem is that it's impossible to have a rule that will ask the VPN password to the user every time he wants to connect.
It's really a lack of security because if the password is stored in the VPN configuration then everybody with the iPhone unlocked in his hand can connect to the Enterprise !!!
Is there a way to block such a thing ?
Thank you for your help, it's really important for us.

Also, try to log the username/password in your authenticator, just to be sure that credentials changeGood piece of advice, michael. Worth of it. When I changed the credentials manually, it worked correctly,but from the application, when I logout from 'a', 'a' and log in to 'b', 'b', I got a valuable information.
I tried debugging like given below for checking from the application.
class MyAuthenticator extends Authenticator {
    protected PasswordAuthentication getPasswordAuthentication() {
         System.out.println("userrrrrrrrr"+UtilsHTTPS.username);
         System.out.println("pwdddddddddd"+UtilsHTTPS.password);
  .........................................The information I got while debugging from the application was, the username and password does not get printed. It implies that, Authenticator.setDefault(new MyAuthenticator()); does not work as desired ie; even on calling new MyAuthenticator(), it does not get inside the MyAuthenticator class.
Why does this happen? What is the solution for this?

Similar Messages

  • How to block modification in object form

    Hi all,
    Is there a way to block any modification in oject form (both parent and child) after the request was submitted?
    Currently when the request is raised,OIM (9.1.0.2) alows us to view and edit object form values.Is there any way to block this edit functionality ?

    Still it didn't work.
    My requirement is this:
    A user raises a request for a resouce by providing values in parent and child object forms.
    Suppose that he has given group1 in child form and have submitted the request.
    Before this request gets approved he wants to add group2 along with group1 in child form.
    Now he goes to request details page and edit the child object form by adding group2 in child form and when the request gets approved the user got created in the target with two groups.
    My requirement is to block the user from adding group2 in child table after the request is submitted.
    I think in this case since a new record is getting inserted in child table , the end user is able to update his request with new group.

  • TS2755 i need to know how to block someone from sending me txt/imessges and calling me. they have a iphone too so i have been told the only way to block them is to turn off my imessages and only recieve regular txt messages. is there another way to block

    how do u block someone from sending imessages and txt and calling ur phone when they have a iphone also. I have been told the only way is to turn off my imessages and recieve regular text messages.. is there another way?? i have searched for apps and cant find one. neeed help!!!

    There are no apps and that is not a feature of iOS.
    iMessages are handled by Apple's own system, and there is no way to block a specific sender.
    SMS messages and voice calls are handled by your cell service provider, so you need to ask them what blocking (if any) features they offer.  If the texts are just spam, you should be able to report them to your carrier and they can block that sender.  Other blocking options will vary from carrier to carrier, so call yours and ask them what they can do.

  • How can I delete or disable my remembered password and Gmail for Blogger.

    Firefox remembers my old details for Blogger, but I deleted that Gmail address, so when I go to Blogger, instead of defaulting to the old emails address, I get a message saying my account is disabled and I cannot get to the homepage so I can sign in as my new email. How can I reset my remembered password and Gmail for this site?

    THANK YOU SOOOOOOOOOO MUCH! I was trying without success to delete a 'saved' password, and couldn't do it for the life of me...Your easy instructions were so very helpful, and I thank you from me to you!!!

  • How to block all authomatic updates of firefox itself and plugins and also requests to update??

    I would like to have a stable browser with the extensions I selected. I like Firefox for being highly customizable and for a huge choice of extensions written by volunteers not working for Mozilla.
    Since none of support seems to be able to understand the problem (or is instructed not to understand), I feel that I need precede my request by an explanation, which is inevitably fairly long. I need to explain why the standard suggestions by support are not acceptable.
    Unfortunately, every new version of Mozilla made the visual customization of the GUI (i.e. a complete theme; probably, they were called skins before) used by me not working. The versions 18 and higher are compatible with only one (complete) theme suitable for me. For me, you reduced the choice to just two options: the default GUI, which I personally cannot stand at all, and one more. And the second one may disappear at any time. I was under impression that the people at Mozilla do understand that different people may have different tastes (and that this is good), in contrast with the people at Google who are, apparently, do not. It turned out that I was wrong.
    Still, it was possible to check the option "do not install upgrades" and keep the version you liked. Then Mozilla changed this and the updates started to be installed without consent of the user. This is something far beyond my comprehension. The option "do not install" turned into an outright deception. I doubt that this is legal even if this is hidden in the small print somewhere.
    The Mozilla support was not helpful at all with this type of problems and took a cavalier approach to all who asked: “We know better what you need”. Fortunately, somebody posted a solution, or, rather, a hack allowing to get rid of automatic upgrades. Note that this hack is for moderately advanced users only, and, being a hack, it may not work with future versions.
    More or less simultaneously the problem with plug-ins appeared. The first major sign was the impossibility to watch the YouTube videos. The other plug-ins followed. Now I am unable to open without a hassle a PDF document downloaded even from a government site, not to say about reputable libraries (and the files were created by libraries themselves by scanning, or by Google), or files created by my friends whom I definitely trust much more than Mozilla.
    Again, Mozilla support is of no help at all. Moreover, they post derogatory remarks about users complaining about these issues and trying to intimidate them. The support may go as far as to suggest upgrading Firefox to version 23 as a solution to the problem of keeping version 3 without constant hassles. This is an insult. Moreover, when I posted a couple of remarks in the thread https://support.mozilla.org/en-US/questions/971139#answer-498622, the thread was almost immediately closed by Tylerdowner, top 10 contributor, administrator, moderator. This is a serious abuse, but the buttons to report this disappeared. How he got his titles? This guy is guilty of abuse and should be banned from all forums.
    Dear Tylerdowner, the-edmeister and others. Please, try to understand a couple of basic ideas.
    First, my computer is my computer, and you have absolutely no right to change it without my consent. I will take of its security myself. The owners of other computers will take care of their security themselves. There are a lot of tools dealing with security; and I don’t know anybody without at least one. This is the first basic principle.
    The second idea has nothing to do with my privacy and Mozilla’s invasion of my privacy. It is not hard to realize that Mozilla is not the only software I am using, and even not the only browser. You do not control the rest. No matter what you do, the computer may be infected in other ways. If your browser is not allowing me to watch a video, I copy-paste the URL in another one and watch it there, and this is not the only other way to watch it. Even if your concerns about the security are sincere (I don’t believe that they are; they are too mechanical and repetitive), blocking something in Mozilla is futile. The result of your behavior will be the abandonment of Mozilla by more and more users, the process already going on.
    Finally, here are my requests.
    1. I and other users need a simple extension for Firefox written by Mozilla (not by
    volunteers) and allowing to disable all updates in one-two clicks and disable all monitoring of plug-ins and anything else which may be present in the user’s computer. Of course, there should be an option to reenable these features. It should be a couple of buttons in the Options window, or in a separate pop-up window and have simple GUI. Of course, it should work as described, which is not the case for the Options window now. No hacks, no changes in about:config, no renaming or moving of files, etc. I appreciate everybody who made such suggestions. One of them allowed me to get rid of updates without my consent. It remains to see if the suggestion in the mentioned thread can solve my problem with plug-ins; as of now, it works for me only partially. But such thing should be done by Mozilla.
    2. It would be great if the software engineers at Mozilla will learn (relearn?) the concept of the backward compatibility. More specifically, the Mozilla should prepare every new release or update in such a way that all (I mean this literally, all) extensions and themes posted on the Mozilla site will be still working after the update. The volunteers don’t have time to keep up with the constant updates, and many authors of very good extensions already stopped to support them.
    3. Do not release a new version if you are not sure that it is bugs-free. Then there will be no need in updates between the versions (by a version I mean Firefox numbered by an integer without dots). Perhaps, this is incompatible with the current release schedule. The abandoning of this crazy schedule is the easiest thing to do; only a desire to do this is needed.

    Dear feer56,
    First, I have to repeat: every new Firefox version was not compatible with many old themes. I do realize that I am, probably, especially unlucky – my favorite theme was always disabled. Still, it is not an accident that Mozilla tried to eliminate the complete themes completely and replace them by some pictures: the list of themes turned into a cemetery of not compatible themes. I just checked: out of 496 complete themes no more than 40 are compatible with Firefox 22. I don’t have any newer version.
    Please, do not attribute to me the idea of including all the themes into the basic browser download. I did not suggest anything like this. I suggested caring about the backward compatibility.
    Of course, I followed your steps 1-5 quite a while ago. But in Summer of 2012 Mozilla started to ignore these preferences. Firefox downloaded new version in the background, and next time you open the browser, it upgrades itself before you even realize what is going on. There was no way to interrupt this process. Even if firefox.exe was terminated through the tasks manager in Windows, it first completed the update, and only then closed.
    I never saw any step by step instructions to deal with this problem. I just searched the Mozilla site for “disable automatic updates, and the first two pages of results deal with <b>enabling</b> updates. Eventually, one gets to disabling at https://support.mozilla.org/en-US/questions/966835?esab=a&s=disable+automathic+updates&r=18&as=s . One of the top 10 contributors suggests switching to Firefox for IT professionals, and then deal with this problem only once a year. Or to follow steps 1-5 above. In the case it will not work, he suggests looking at an irrelevant article. He should know and I am sure that he knows that the problem is not with not saving preferences by a mistake; the problem is that Firefox ignores them now by design. Eventually this was admitted by somebody.
    Changing about:config is not an easy task. The meaning of most entries is unclear, the modifications suggested by somebody turned out to be not sufficient. This is also a task for IT professionals.
    I said nothing about the competence of Tyler. He is arrogant; this is a completely different matter. He may use his competence at some place where he will not need to interact with customers.
    “If you do not like what Mozilla is doing and rather be tracked and rather be followed, please use Google Chrome. We're all here to help you.”
    Do you mean that it is better to be tracked by Mozilla than by Google? As I learned yesterday, Firefox compares daily the software installed on my computer with a blacklist on Mozilla servers. This is tracking. And there is option to opt-out, there is not even a warning.
    If you care about your customer not being followed, include an option blocking the Google-analytics into the browser itself. Irrespectively of privacy, Google-analytics prevents many pages from loading completely: it takes too long to perform all these Google-zero-by-zero pixel dances.
    Then you say that the volunteers working on the core code deserve much more respect than volunteers working on extensions. I am not sure that this is the case. I don’t see that the core is noticeably better than for other browsers. The fact that Mozilla wasn’t able to solve during 10 years the main problem of Firefox, namely the buffer overflow, and then stopped even to acknowledge its existence, is very disappointing. In contrast, a lot of extension is very useful.
    I know about the testing process only what Mozilla tells to the public. And Mozilla tries to blame the short period between the releases for new bugs introduced in each new release.
    What was your idea in suggesting me to read that article? Do you think that it contains some valid excuse to the lie in the Options window, for example?
    But the article is useful, thanks. It tells me that there is no hope here and I should look for another browser. In the meantime I should block Firefox from accessing the Mozilla site completely. It looks like very soon I indeed will be an IT professional.
    I have absolutely no interest in mobile devices and don’t see how they could be useful for me. And no matter what the projects are, the market share of Firefox is going down.
    Best wishes.

  • CM: how to block the last new sales order only and not all of them?

    Hi,
    We are testing the FSCM-CM and try to figure out this:
    We have for a customer a number of open sales orders that are all below the credit limit.
    Now someone creaetes a new order and with that amount the limit is exceeded.
    The system reaction is that all open orders are blocked.
    How can we set the system that only the last one is blocked?
    Thanks in advance
    Hein

    Hein,
    I dont think there is any standard function which specially points to the last order. System will consider all the orders in which the customer is involved. I think, the above post suggest the of number of days but not the last order. Try to play with the attributes of system messages and I am sure you will get a clue from it..
    Reward if helpful..
    Thanks,
    Srib

  • How to block for data sync between web cloud and each PC.I want control for all user's pc as administrator.

    I already blocked as below url.
    Sync/Store/Share Core Creative Cloud
    https://creative.adobe.com/api/assets
    https://creative.adobe.com/api/collections
    hptts://creative.adobe.com/api/share
    But one of user create file on C:\Users\Administrator\Creative Cloud Files it is sync with web cloud and another pc.
    I saw  sync on or off function in set up tap.
    but I want block sync for all users as administrator.

    Moving the discussion to File Hosting, Syncing, and Collaboration.
    Thanks,
    Atul Saini

  • How can I make my Outlook sync with ical and address book on more than one mac?

    It currently syncs with my iMac through 'this computer' folder, but i dont have outlook on my macbook, so basically... how can i make my outlook automatically convert/sync to icloud enabled folders?
    Not too confusing i hope.

    Outlook won't work with iCloud. On your Mac.

  • How do i find out what my router password and user name is to set up a public ip camera

    i have purchased a wonderful ip camera and intend to use it to monitor my house while away.  works great at home on wireless devices however i am trying to access it when not at home and not on a wireless network. i understand i have to set up port forwarding but there is no manual with my verizon supplies router(surprise surprise) and i have no clue what the default username and passord aare to access my router! i have tried the recommended admin/password default they SAY is supposed to work with my acitiontec router....someone PLEASE help.  i have tried every possible way to obtain the info needed...its a shame verizon isn't very adept at their own equipment.

    It will use a lot of data, but based on what he said, it shouldn't matter: he has an actiontec router and is trying to reach the router admin page to forward ports.
    @LILSTAR34: you're in the wrong place, Verizon Wireless is the cell phone company, you need Verizon Telecom (www.verizon.com) for help with your landline. I don't know the default info for your actiontec router, I know for most consumer routers that *I* have played with, you can log into 192.168.1.1 using a default username/password of "root", "admin", or some variation thereof. If this doesn't work, you'd have to find out what the default information is for your router, probably by calling customer service (1 800 837 4966) until you get someone who understands your question and looks up the information you need.
    Incidentally, this is why I always advocate buying your own router instead of renting one from the ISP: this info is readily available on the internet for any half-decent consumer router (linksys, netgear, d-link, etc).

  • How can I access my iCloud with no password and my email "me" isn't working.

    I've lost my password and my e-mail is asking for that password. So I'm unable to request a new password. Is there a way to solve this problem?

    If you know the answers to your security questions, or if using two-step verification you have your recovery key, you can reset it as explained here: http://support.apple.com/kb/HT5787.  If you don't, you'll have to contact iTune store support: https://ssl.apple.com/emea/support/itunes/contact.html.

  • ASA and ACS 5 multiple VPN profiles for one user

    Hi there
    I have a question about ACS 5.3 and ASA VPN profile authorization. I am not sure if it is possible to allow one single user for a set of VPN profiles on ASA, let's make an example:
    ACS 5.3 group hierarchy:
    - VPN users global
    -- VPN users A
    -- VPN users B
    ASA VPN profiles:
    - VPN profile A
    - VPN profile B
    - VPN profile Z
    VPN authorizations:
    1. VPN users global should have access to VPN profiles A, B and Z (here we create an authorization profile with no class an no lock attributes, so the group is allowed for all VPN profiles)
    2. VPN users A should have access to VPN profile A (here we create a authorization profile with class and lock attributes for profile A)
    3. VPN users B should have access to VPN profiles B and Z (is this possible and how does the authorization profile have to look like?)
    Thanks a lot in advance and best regards
    Dominic

    Hi Dominic,
    first of all, let's clarify that on the ASA you have tunnel-groups (named connection profiles in ASDM) and group-policies. These often, but not always, have a one-to-one mapping.
    The Tunnel-Group (TG) is either selected by the user (either from a drop down list or by entering a specifiv group-url), or automatically selected by a certificate map (i.e. based on a certain field in the user cert, the user is mapped to one TG or another). The TG mainly specifies what kind of authentication is used.
    The Group-Policy (GP) by default is the one specified in the TG, but it can be overridden by e.g. Radius.
    So from the ASA's standpoint itself your posibilities are rather limited: the ASA will just apply whatever group-policy you push from Radius (in IETF attribute 25 aka "Class"), and in addition it will deny access to a user if the TG he selected does not match the value of the group-lock attribute. Group-lock can only contain one TG name, so you cannot do something like "allow both B and Z".
    In other words you can not achieve your goal if the Radius server has a "static" set of attributes per user.
    However, as of ASA 8.4.3 the ASA now sends 2 vendor-specific attributes in the Access-Request:
    vendor ID = 3076, attribute 146 is "Tunnel Group Name" (string).
    vendor ID = 3076, attribute 150 is "Client Type" (integer)
    0 = No Client specified  1 = Cisco VPN Client (IKEv1)  2 = AnyConnect Client SSL VPN  3 = Clientless SSL VPN  4 = Cut-Through-Proxy  5 = L2TP/IPsec SSL VPN  6 = AnyConnect Client IPsec VPN (IKEv2)
    So if you can configure the Radius server to "dynamically" permit/deny access based on the TG attribute I suppose you could achieve what you want.
    If/how ACS can do this, I personally don't know; I suggest you ask in the AAA forum if you need help with that part.
    hth
    Herbert

  • How to remove the link between Profile name and corp net account after their disassociation

    Hi there,
      How do I  remove the link between Profile name and corp net account after their disassociation ?
    I would like to make remove the link between 'Viv Lingaiah' and
    [email protected] Also, I would like to keep 'Viv Lingaiah' and associate with my outlook id and corpnet account.

    Logon to your live account here
    https://account.live.com/summarypage.aspx then under aliases you can add an alias and promote it to primary.
    Regards, Dave Patrick ....
    Microsoft Certified Professional
    Microsoft MVP [Windows]
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

  • My phone was stolen and i dont know how to block it though i have the serial number and IMEI number

    My phone was stolen and i dont know how to block it though i have the serial and IMEI number....

    If you've set up Find My iPhone, here's how to use it:
    http://support.apple.com/kb/PH2580
    Whether you set it up or not, notify the authorities, giving them your serial number.  Notify your cellular carrier as well.

  • How to block project status in CJ20n

    Dear All,
    I am facing one scenario,and also gone through lots of sap notes and many research work, But did not find the accurate answer to resolve this issue.
    My Issue is how to block Project Status in CJ20N like lock and  Unlock etc. Because in our organisation if i assign the authorization for Cj20n, then every user got the access of this and they mis use it.
    So i want to restrict users at this point . Please guide me through this on early manner.
    Early step by step response will be appreciable.

    Dear Renu,
    Your question seems to be confusing. I got a conclusion that either you want to lock/unlock the project or just simple not allowing users to access CJ20N transaction.
    For your information. Following is the reply for both queries:-
    1. To lock/unlock project, please select project definition and go to Edit>Status>Lock/Unlock-->Master Data.
    2. For not allowing every user to access CJ20N, please refer to BASIS guys in your organization.
    Please revert me back if you have doubt or If I am thinking in another way.
    Many Thanks,
    Amit
    Edited by: A.Rajoria on Feb 28, 2011 7:43 AM

  • Admin totally forgot the password and i've no idea where to reset the password or how to remove the admin so that I can be the admin, but first thing, still the same. PASSWORD -.-

    I've no idea how to reset the old password in my macbook pro. Because this is my father gave it to me then even he also forgot the password too! Please I need help! T.T If not I cant download software in this computer. how?
    Because even him also forgot which password, and all the password he gave me wasn't log in. Ive no idea what to do already so I've ask community~
    Where to totally set a new admin without delete the old admin password?
    Can't remember the Old password so how to create a new and delete this?
    I need to download something but it keep asking me put in the password but i don't know it and want to delete it.. how?
    Please help~~~ Thank you everyone

    Reset the password.
    For Snow Leopard and earlier:
    http://support.apple.com/kb/HT1274?viewlocale=en_US&locale=en_US
    For Lion and later:
    https://discussions.apple.com/docs/DOC-4101

Maybe you are looking for

  • Implement Best Practice in existing system

    Hi, I am trying to figure out the smartest way to implement best practice. The only problem is that it is to be implemented in an existing landscape containing a Finance solution. We will implement IM&C which mainly comes with complete new configurat

  • Portlet Url writing with a Weblogic Server as WSRP Producer

    Hi there, I’m having problem to find out which API I have to use to make my producer write the URL using the consumer’s urlTemplate. I have a basic Struts portlet with two forward (to a JSP) actions, I need to find a way to use the urlTemplate fr

  • Aspect Ratio - Anamorphicizer

    i have troubles with burning my fcp (version 6.0.6) project. my workflow is this: i make my movie in fcp, export it as a quicktime reference movie, drag it onto anamorphicizer, import it into idvd and save as image file. worked perfectly well a hundr

  • Using Excel as  Datasource in Crystal Reports 8.5

    I have never used Excel as a source for Crystal data and I am having a bit of an issue I believe. I have an Excel file on my desktop that I am using as the datasource. Eventually it will be out on a network drive. I set up all my reports as blank rep

  • Simulating Summary / drill down columns in OBIEE without actually changing Subject Area/Repository

    Hi, I have a  requirement where I need to group certain columns and simulate drill down (expansion and collapse) for them without doing any changes in Subject Area / Repository. We have measure columns revenues and a two geography columns Continent (