Prove Seeded Application Account Passwords are Changed for Audit

We have been asked by our external auditors for the following information:
"Provide proof that the passwords for all seeded application users have been changed from the default password. (ie SYSADMIN, WIZARD, GUEST, AUTOINSTALL)"
I ran the query select * from FND_USER where created_by = 1 to get the list of seeded application users:
ANONYMOUS
AUTOINSTALL
CONCURRENT MANAGER
FEEDER SYSTEM
INTIAL SETUP
APPSMGR
SYSADMIN
WIZARD
PORTAL30
PORTAL30_SSO
All of the above accounts have been end-dated except for the GUEST and SYSADMIN account. However the auditors still want me to prove that the passwords for all seeded accounts, including those that have been end-dated, have been changed from the default password.
I know that I can use the following command to test the passwords:
select fnd_web_sec.validate_login('GUEST','GUEST') from dual;
I know the default passwords for SYSADMIN and GUEST but I do not know what the default passwords are for all the other accounts to use in the above command. I have searched Metalink and this forum and I am not able to find the default passwords for the seeded accounts such as AUTOINSTALL, WIZARD, etc.
I would appreciate it if someone could provide this information or point me in the right direction.
Thanks.

Hi,
The best security practice it to disable these account (except for SYSADMIN, and GUEST and some other accounts), and this is exactly what you did. So, auditors should not bother you about the password change as long as those accounts are disabled.
I am not sure about the default password of those accounts but I assume it is same as the username.
Note: 418767.1 - What Is The Impact Of Disabling Oracle Seeded Users.?
https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=418767.1
Note: 189367.1 - Best Practices for Securing the E-Business Suite
https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=189367.1
Regards,
Hussein

Similar Messages

  • How to find the when the password is changed for a system User

    Hi to all,
    We have a test database where our application connects to system user. The application runs more than a month without any issues, But suddenly my system and sys password gets changed. I wonder how this would happen. I have checked with DBA_USERS to check whether the account gets locked, But the account is in the Open state.
    I need to find out when the password gets changed for these users and who changed it? Is there any possible to trace it or we need to enable the auditing to find it in future.
    Kindly let me know the possible ways.
    Regards,
    Vijayaraghavan K

    Vijayaraghavan Krishnan wrote:
    Hi to all,
    We have a test database where our application connects to system user. The application runs more than a month without any issues, But suddenly my system and sys password gets changed. I wonder how this would happen. I have checked with DBA_USERS to check whether the account gets locked, But the account is in the Open state.
    I need to find out when the password gets changed for these users and who changed it? Is there any possible to trace it or we need to enable the auditing to find it in future.
    Kindly let me know the possible ways.
    Regards,
    Vijayaraghavan KThe only way to implement an Oracle Audit

  • Password  'peop1e' change for Connect ID people

    I'm doing the Impact analysis for connect id 'PEOPLE' account password being changed annually to achieve SOX compliance. Can somebody explain to me what are the impact if this will be implemented, where to do the changes, what are the effect if the changes take place and what are the things that needs to consider before doing the changes?

    Not a huge deal to change. But in my opinion not necessary for SOX. The id only has read access to 3 tables. It can't cause any damage, that's the beauty of the connect id.

  • List of GL accounts that are Open for manual postings

    Hi,
    I am trying to download a list of all the GL accounts that are open for manual postings.  Meaning in FS00 the check box "Post Automatically Only" is not ticked.  Also I would like the list to include the Field status group associated with the GL account.  Does anyone know how i can find this?  I looked through the tables SKA1, SKAT and did not find it there.  When I get the technical information for the account, it says Structure "GLACCOUNT_SCREEN_CCODE" and field "XINTB."  Any ideas?
    Thanks,
    Rashad

    Hi,
    Post automatically only and FSG are company code specific. so you should be checking that in relevant table SKB1 which has companycode specific details.
    Regards
    Shivappriya

  • IMac keeps asking for user account password when changing Airport

    Whenever I change anything in Airport (switching networks mainly) my iMac constantly prompts me to submit my user account password. All other macs don't do that. Any clues?

    Suggest that if you haven't already taken the next steps....open System Preferences > Network > AirPort and delete the current wireless connection by highlighting the name of the network, then clicking the - (minus) button at the bottom of the connection list. Click OK and then Apply.
    Open Macintosh HD > Applications > Utilities > KeyChain Access and locate the name of the wireless network, then highlight and delete that entry.
    Restart your Mac to see if that will allow you to start fresh.
    If still no luck, I'm afraid it's getting down to a re-installation of the operating system on the Mac.
    Message was edited by: Bob Timmons

  • My email password and my verizon account password are the same? Are you SERIOUS?

    The other day I did something I never do, actually log into my verizon account.  I hate the verizon interface, I'd rather stick pins in my eyes than use it, but every now and then I have to use it to handle a bill.  So, of course the password that I remembered setting on it didn't work.  So I jumped through the hoops to reset the password, conducted my business, and left the site, hopefully not to return for a year at least.
    Lo and behold, the next time I tried to access my email (which I use Thunderbird for, and don't tell me it's not a supported client, it works fine, and no I'm not going to use Verizon's webmail interface), it won't accept my email password.  Now, this password HAD always been distinct from my verizon account password.  But...telling myself, "Oh no they didn't," I tried using the new password that I'd set for my online account.  Surprise!  It let me into my email!
    Now, this morning, neither the new password nor my old email password are being accepted.
    So, I have two questions, apart from the existential "why does Verizon feel the need to torture its customers like this":
    1)Are they SERIOUSLY requiring you to have the SAME password for your email AND your My Verizon Account?
    2)If, as I hope and pray, the answer to 1 is "hellz no", how can I change just my EMAIL password?
    Anticipating a reply of, "No, it's just one password, because we've decided that's MORE secure, and your whole problem is that you're using Thunderbird, because ummmm somehow Thunderbird renders passwords into ancient Greek before it submits them and so it won't work, but of course some dull-normal client like Outlook WILL work, and don't ask me the details because I'm really not very technical, but apparently I'm technical enough to tell you that your client is no good"...

    Yes, the passwords are the same now. Verizon made a big push a while back to give customers a single login. They merged everyone's accounts, not because it is more secure, but because they think customers will find it easier. No, there is no way to change just your email password.
    And no, there is absolutely nothing wrong with using Thunderbird. Many of us have it configured for verizon.net addresses, and it works just fine.
    Wish I had a better answer for you...
    If a forum member gives an answer you like, give them the Kudos they deserve. If a member gives you the answer to your question, mark the answer as Accepted Solution so others can see the solution to the problem.
    "All knowledge is worth having."

  • On Windows Server 2008, local account passwords are reset when the server is rebooted. Why, and how do we fix?

    We are running a commercial application on a Windows 2008 Server. After reboot, we cannot access the application because two services fail to start. The reason they fail to start is that the passwords to the local user accounts tied to those services have
    either been deleted or reset to a different value. In order to restart the application, we must reset the passwords of these two local accounts, then stop and restart all the application's services.  According to the application's maker, the accounts
    must be local.
    My colleague believes the passwords are being deleted or reset as a result of a global domain policy.  Is this likely?
    Assuming my colleague is correct, is there anything we can do locally to prevent these passwords from being deleted or reset when the server reboots?  If not, what is the most granular change we can ask our AD adminstrators to make to the policy, so
    that these local accounts are not touched at reboot.
    Thanks.

    Hello,
    have you configured the accounts to have the permission "Log on as a service"? I have seen that this is not given to the account and therefore the service fails to start.
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  

  • Can someone explain the difference in what Passwords are required for Apple sites?

    It seems that every time I want to login to MobileMe, or the Apps store or this Forum site my passwords rarely work and I end up resetting the one I'm trying to use.
    I do keep track of my passwords.   So, I'm wondering if each site I listed needs a different password.  Plus, I continually get errors in my MacMail.  It shows an error that needs a password for my IMAP... can't remember exactly what it says...
    I hope that's enough info for someone to help me out.... thx

    Hi..
    It seems that every time I want to login to MobileMe, or the Apps store or this Forum site my passwords rarely work and I end up resetting the one I'm trying to use.
    Might be corrupted keychains. Your passwords are stored in Keychain Access.
    Launch Keychain Access located in /Applications/Utilities
    Select Passwords on the left.
    Type   mobileme   in the search field top right corner of the window.
    Now right or control click that keychain then click Delete.
    Now type  daw   in the search field.  (that's your access to the Apple forums),
    Right or control click the daw.apple.com keychain then click Delete.
    Now from the Keychain Access menu bar top of your screen click Keychain Access > Keychain First Aid. Enter your admin password then click Verify, if necessary, click Repair.
    Now launch the App Store. From that menu bar top of your screen click Store > Sign In
    Enter your Apple ID and current password. Click Yes when prompted to save that data to a new keychain.
    Do the same for MobileMe and the Apple forums.

  • I have two apple ID passwords and two devices when I try to use my account/password it asks for the other account that I don't have the password to. Can update or buy anything. Can you help ?

    I have one computer and one iTunes library and two devices hooked up to it. But I have to apple IDs a different one for each of the two devices. When I try to buy or update something using my account and password it asks for the other account password so I can buy or update anything. I can log into this website using my accountant it recagnizes me but i still can't get it to work on the App Store . I don't know I'f this matters but I just updated to iOS 6 and then tried it and it wouldn't work. Before I updated it , when I would try to get an app or something it would still  ask me for the other password , but if I pushed cancel then it would ask me do mine and then it would work , but it doesn't do that anymore. If I push cancel it just cancels and does nothing. I hope you can give me some suggestions, I really need your help:)

    Check the AppleCare number for your country here:
    http://support.apple.com/kb/HE57
    Call them up, and let them know you would like to be transferred to the Account Security Team.

  • I cannot retrieve sync data to my newly updated firefox 4.0 browser. I have tried resetting my account password and changing computer name.

    Hi, I am having trouble getting sync to work on my ff4.0 updated browser.
    After the upgrade, I noticed that the history was not working. Therefore I disabled the device and set it up again. I even changed account's password. But I left the sync key in tact.
    After setting up the sync options, it sent me to a page that tells me that it was set up successfully for second time. I repeatedly clicked on "Sync now" but I was unable to get my sync data.(without any error message) Afterwards, I restarted my browser and tried "sync now" repeatedly again to no avail. Does anyone know what went wrong? Thanks in advance

    It sounds like to me you're trying to sync using the computer.
    Try these things and see if it helps before you try your next syncing session. If none of the things below work then you might consider trying to sync using iCloud only.
    Try a Restart. 
    Press and hold the Sleep/Wake button for a few seconds until the red "slide to power off" slider appears, and then slide the slider. Press and hold the Sleep/Wake button until the Apple logo appears.
     Resetting your settings
    You can also try resetting all settings. Settings>General>Reset>Reset All Settings. You will have to enter all of your device settings again.... All of the settings in the settings app will have to be re-entered. You won't lose any data, but it takes time to enter all of the settings again.
    Resetting your device
    Press and hold the Sleep/Wake button and the Home button together for at least ten seconds, until the Apple logo appears. Apple recommends this only if you are unable to restart it.
    Or if this doesn't work and nobody else on the blog doesn't have a better idea you can contact Apple. 
    Here is a link to their contacts with most of the information below. 
    http://www.apple.com/contact/

  • Floor Plan Manager Webdynpro Java Application : Error Message area change

    Hello Experts,
                             We have a Java Webdynpro Application inside the  ESS business package ,delivered by SAP .
    Is there anyway we can control the Error message area at the top of the Java webdynpro applications using the configuration controller without changing the source code for a particular Java webdynpro application???
    I like to bold the error messsage and change the text color in the SAP Portal.
    If not possible using the configuration controller, what are steps that we need follow to do this change.
    Any help will be appreciated.
    Thanks,
    Greetson

    This cannot be done through personalization or any configuration.
    If you want to change look and feel of error message then assuming these are personal information applications....you will be required to make changes to ess~per DC in NWDI or application specific DC in NWDI.
    Still I believe...in web dynpro java....it will not be possible to change look and feel of standard error message area

  • TS3276 email account passwords are constantly requested

    I am using OS Lion and Mail and have 6 different email accounts running. All accounts work but periodically and I cant see an obvious pattern, various accounts ask me to input again the password for the account. I do this and always check the box to retain the password in the chain. But the password request will be made again at least once.
    Has anyone experienced such a problem and is there an obvious reason and fix for this?
    Thanks.

    I'm having the same issue. It started a couple weeks ago when I changed the password of one of my iMap accounts. I've repaired permissions, deleted the keychain password items associated with the problem account and even deleted com.apple.mail.plist located in my home directory->library->preferences. None of these actions has solved the problem. I've searched the rest of the Internet but haven't found any suggestions for actions other than those already tried. This particular email account works fine with another client on my Android phone and via webmail so having an incorrect password isn't the problem.
    Do you know of any files containing cached information that can be safely trashed?
    As I type this it occurs to me that I didn't empty my trash after deleting the com.apple.mail.plist file. I'll try that now.
    Snow Leopard on iMac 10.6.8
    5 Email Accounts

  • Security Hole? disk image passwords are cached for a short time!

    Here's my experiment:
    1. Make a password-protected (128-bit AES) disk image (dmg or sparseimage), and do not save the password in the keychain.
    2. Load the image (you'll be prompted for the password).
    3. When virtual disk appears, eject it.
    4. Repeat steps 2 & 3 rapidly until the disk loads without first prompting for the password.
    Once this happens, it will (often) load again even after 10 or 30 seconds (or more?) without a password prompt..
    I don't see how this could be happening unless the password accepted by the prompt is saved somewhere.
    Why should it be? Where? Is there a bug?
    And why should it be saved as long as ten seonds or more after the disk is ejected??
    I'm running Mac OS X 10.6.8 on a year-old MacBook Pro

    Hi All
    I have been following this up for you and would like to confirm that the software specified in the Hub 2.0a is secure against the attack you mention here.
    Thx
    Kerry
    Retired BTCare Community Manager - StephanieG and SeanD are your new Community Managers
    If you like a post, or want to say thanks for a helpful answer, please click on the Ratings star on the left-hand side of the post.
    If someone answers your question correctly please let other members know by clicking on ’Mark as Accepted Solution’.

  • GL account to be changed for a return by using AUART

    Can someone please advice on how I can go about doing this. I looked at the help and the substitutions and found that to add AUART to KOMKCV it needs to be in VBRK and the substitutions have BKPF and BSEG so I am still trying to find a way to do this. Experts I need your advice on this.
    Rob

    hi,
    Yes you can have the G/L account differentiated based on the plant...
    SPRO >> MM >> Valuation and account determination >> account determination >>account determination w/o wizard >>  grp together valuation area /define valuation classes...
    Material group specially plays a big role when there is account assignment and no MMR present...
    SPRO >> MM >> Purhcasing >> material master >> account assignment w/o material master and its assignments ...
    When you group together as per valuation area...here valuation area will have a same key as plant...
    check ..
    Regards
    Priyanka.P
    Edited by: Priyanka Paltanwale on Jun 12, 2009 5:35 AM

  • ADF View Objects and Recording changes for Auditing Purposes

    Hello,
    I am a new to the JDeveloper paradigm and currently working on a J2EE web pilot project. I was wondering if I could get some some ideas on how I could implement auditing in an application. Basically when a user modifies some entries on the screen, I would like to make a note of what the record was like before commiting to the database. An administrator could then see, what changes the record has been through over a period of time.
    I was thinking of using XMLTypes with the database. Does Jdeveloper handle oracle XMLType fields, or would I be looking at something along the lines of a CLOB? At this point, I would rather not implement this functionality using database triggers. Any alternate suggestions would be appreciated.
    Regards
    Anora April…
    Jdeveloper 10.1.2 (1811)
    Oracle DB 10g 10.1.2

    Hi,
    I am also interested in a best-practice note from oracle.
    Currently we store history in seperate history tables for columns that changed. All this implemented in our BaseEoImpl overriding the EntityImpl.prepareForDML().
    Thanks

Maybe you are looking for

  • Importing finished DV short as a whole project

    i am attempting to import a finished short film (11 minutes) in order to then save as an mPEG to save to my iPOD. unfortunately imovie will only accept the project in 4.24 second chunks. how can i get imovieHD to accept all 11 minutes at once? and th

  • How do I remove a small box on my vector that I didn't add?

    I've been working on a downloaded vector, but when I opened up it up in Ai a black square appeared in the center.  (this did not appear on another computer).  The square is now pink, has a "1" in the upper lefthand corner, and a jagged line in anothe

  • Cannot specify non-default KDC port using system property krb5.kdc

    For testing / debug it's very useful to be able to run the KDC on a non-default port. This can be specified in Kerberos config file by appending the port number to the KDC host name, delimited with a colon. The java.security.krb5.kdc property can be

  • Which Windows version for MacBook Air?

    I need to run an existing PC data base program on my new MacBook Air. I have been told I need to buy and install a previously unregistered copy of Windows and a Windows compatible antivirus program. My question is will the new Windows 8.1 be the best

  • First Time Sign On detection facility

    Hi All, I have one query regarding First Time Sign On detection facility. Its something as poping up of TERMS for users to mark it as 'I AGREE' before First Sign on on UI. How can we achieve this on WEBSHOP. TIA