Sapjsf locks ABAP service user psswd: M  ***LOG US1= Login, Wrong Password

I have a PI system and a number of ABAP systems connecting to this.
I have defined a service user in PI for each ABAP system - SY_SID_999 (where SID is the SAP System ID and 999 is the client).  Various connections (e.g., RFC, ABAP proxy) use these userid and I rely on the user name to identify the source of the activity within PI.
I was forced to change the password of one of these userids and, subsequently,  to update connection details in RFCs etc within the source system.  All went well for these connections.
Now, however, at 25 minutes past the hour, I get the following error in the PI system's developer trace
M  ***LOG US1=> Login, Wrong Password (SY_SID_999 ) [sign.c       4545]
and the SM21 log says
10:25:47 DIA  000 100 SAPJSF                  US  1 User SY_SID_999 locked due to incorrect logon
SU01 change records show no changes to SY_SID_999 from the time I unlock it until 25 minutes past the hour when this error occurs. 
The SM19 security audit log in the PI system has errors:
12.08.2009     10:08:18     SAPJSF     localhost          SAPMSSY1     Logon Failed (Reason = 53, Type = U)
Type=U means "user switch (internal call)" according to the documentation.
Reason 53 means "Too many failed password logon attempts"
These errors occur in bunches but without a consistent repetition interval.  For example, there were 8 at 10:04:56/57 then 2 at 10:08:18 then a string of success messages as follows:
12.08.2009     10:08:18     SAPJSF     localhost          SAPMSSY1     Logon Successful (Type=U)
Then, at 10:25...
12.08.2009     10:25:47     SAPJSF     localhost          SAPMSSY1     User SY_SID_999 Locked in Client 100 After Erroneous Password Checks
12.08.2009     10:25:47     SAPJSF     localhost          SAPMSSY1     Logon Failed (Reason = 1, Type = U)
If I do not unlock the SY_SID_999 userid in the PI ABAP system, there will be no further errors in SM21 but if I do, at 25 minutes past the hour after the error pattern will repeat.
I have set the rfc/logon_error_log parameter to 3 in PI ABAP to trigger a short dump.
Internal notes from the short dump do not identify the who, what or where of the sign-on attempt...
Internal notes
    The termination was triggered in function "ab_xsignon"
    of the SAP kernel, in line 2725 of the module
     "//bas/710_REL/src/krn/rfc/absignon.c#4".
    The internal operation just processed is "CALY".
    Internal mode was started at 20090812112528.
    Caller system......: " "
    Caller.............: " "
    Caller client......: " "
    RFC user ID........: " "
    RFC client.........: 100
    Login return code..: 20
    Transaction code...: " "
    (Note: In releases < 4.0, no information on the caller is available)
The source system represented by the SY_SID_999 userid is an ABAP ONLY stack so has no sapjsf userid.  (For the record, SY_SID_999 doesn't exist in client 999 of SID either - it's defined in the PI system to do work on behalf of SID client 999.)
So the question, after all that, is:
How do I identify the source of this password error?

Thanks Michael
I did get a short dump during the testing process and it indicates that the failed RFC logon attempt originates from within the PI system.  My implementation partner was rather careless in the assignment of userids to connections so, while this userid should only be used for connections originating from the SID, I cannot guarantee that.
I've been into both my PI system and the ABAP system (which doesn't have a sapjsf userid so should not be the offending party) and run an SQL select script to find all RFC destinations which contain the string "SID" or "sid" in any of the RFCOPTIONx fields.  I've carefully checked out each of these RFC destinations and, in SID they contain the SY_SID_999 userid and, when that's unlocked in PI, the connection and authorisation tests succeed.  That rules out upper/lower case issues and pretty much eliminates these legitimate RFC destinations from the suspect list.  The RFC destinations identified in the PI system by the SQL search contain "SID" because they name that as their target system; these definitions don't reference the SY_SID_999 userid at all.
All the evidence I can find points very strongly to some process running as SAPJSF in the Java stack of the PI (dual stack) system calling something on the ABAP side and trying to connect as SY_SID_999.  Trouble is I can't find it.  In fact, I'm don't even know where to start looking to find a job running in the Java stack - on the ABAP side I'd head for SM37 but what to use on the Java side?

Similar Messages

  • LOG US1= Login, Wrong Password

    Hi all,
    While trying to connect to PI system from ECC system using HTTP RFC SAPISU, I am getting user name password prompt. However, I have already maintained correct user name and password in RFC destination.
    I also tried to login with this user name and password in PI system and I could login. Another thing I could observe is whenever I execute test connection for RFC SAPISU, system tries to login to PI system with invalid user name and password. And after 5 attempts user gets locked. Kindly help me resoling this issue.
    Thanks and regards,
    Meghan

    I am getting user name password prompt. However, I have already maintained correct user name and password in RFC destination.
    Check user name and password is correct. Also check connection type is maintained as trusted.

  • ABAP Service Users  not working - important

    Hi,
    I installed finally BPC 75 NW, and I cannto get ito the application for the 1° time because I have several issues.... I get the error "The user ID, password  cannot be authenticated. Make sure you entered valid credentials".
    On Server Mgr. i get 2 errors " Sap server connection : database connection"  and "ms message queue:  queue name:  .private$BPCstatusmessagequeue".
    I have done eveything in order to solve this... but... after a lot of research I found a note where it is suggested to uninstall, however I still want to change some parameters as described in the installation guide, I hope you can please help me to clear this:
    Manual, page 43, installation for NW.
    - ABAP service users can be locked as a result of the install.
    - Check and unlock users, use SU01, press Ctrl + F5  (done, not a problem)
    - Check that COM + Components exist (done)
    - Check interfaces (this means changes in Pooling & Recycling?)
    - Check that librfc32.dll is set up appropiately (I had the problem during install where i needed to reassign this dll, now is not an issue  unless there is something else to check that i am not aware of)
    - IIS Port (80 by default right?)
    - ServerConfiguration.config for the correct username and system info (cant find this file)
    - Registry Entries on 32 and 64 bits (how can I do this)
    - Check C:windowssytem32driversetchosts file to ensure that a fully qualified domain and IP resolution exists (what exactly do i need to check)
    On server mgr also I have for  COM+ components " domain system administrator with which i installed  & password"   is this right?
    Thanx in advance, it is really important.
    Velázquez

    Hi,
    Thanx for the feedback !! really appreciate it. Here is the response:
    The COM components are ok, as well as the MSMQ and every other component you mentioned (also reinstalled it). I reactivated all "dictionary" to the 3 users created in ABAP, changed role to communication, and give SAP_ALL permission.
    In the machine, changed the Default web site to port 81 (to let BPC website take port 80)
    Reinstalled  NET 2.0, set all components for BPC website to Net 2.0
    Created the 3 abap users in domain and gave in both systems  the same password.
    Entered in the machine as the administrator user (also administrator in Netweaver) and started the installation without trouble.
    After that, tried to run the server diagnostic but this user was lacking permits, so I added the 3 users (abap) in the local machine as administrators, in a  new group called BPC (only giving the administrator role). Entered now in the machine as BPC_SYSADMIN and ran the Server Diagnostic without trouble.
    After doing this, I now am facing an issue trying to add users to the 1° appset... choosing the domain users... however someone mentioned that this is related to the NET tier, is it better to reinstall this tier completely or at least try with NET 1.1, but im just about to find out.
    Thanx again for the response.
    Velázquez

  • After my friend locked me out of my iPhone with too many wrong passwords I restored my iPhone and now it is showing that picture of a cable leading towards itunes and itunes says the sim is not supported but it is the original sim. How do I fix this?

    After my friend locked me out of my iPhone with too many wrong password attempts I restored my iPhone via recovery mode and now it is showing that picture of a cable leading towards itunes, and itunes says the sim is not supported but it is the original sim. How do I fix this?

    Something went wrong with the update, this can and does happen with every version of iOS.
    There is nothing wrong with the update.
    Simply restore the device via iTunes on the computer.
    If iTunes is stating it will take hours to update, that indicates an extremely slow Internet connection and is likely the reason the OTA update failed.

  • FRM-92101 when user tries to log on with invalid password

    Hi,
    We have the following issue.
    When users try to log on to our webforms applications with correct user name and password everything works fine.
    When they try to logon and use (by accident) an incorrect password they do not get the expected ORA-1017 invalid username/password; logon denied but a FRM-92101 - There was a failure in the Forms Server during startup ....
    Any help is appreciated!

    B.t.w. the application.log on the Oracle Application Server shows the error text:
    java.io.IOException: FRM-93000: unexpected internal error.
    Details: No HTTP headers received from runform
    at oracle.forms.servlet.ListenerServlet.forwardResponseFromRunform(Unknown Source)
    at oracle.forms.servlet.ListenerServlet.doPost(Unknown Source)
    at javax.servlet.http.HttpServlet.service(HttpServlet.java:760)
    at javax.servlet.http.HttpServlet.service(HttpServlet.java:853)
    at com.evermind[Oracle Application Server Containers for J2EE 10g (10.1.2.0.2)].server.http.ServletRequestDispatcher.invoke(ServletRequestDispatcher.java:824)
    at com.evermind[Oracle Application Server Containers for J2EE 10g (10.1.2.0.2)].server.http.ServletRequestDispatcher.forwardInternal(ServletRequestDispatcher.java:330)
    at com.evermind[Oracle Application Server Containers for J2EE 10g (10.1.2.0.2)].server.http.HttpRequestHandler.processRequest(HttpRequestHandler.java:830)
    at com.evermind[Oracle Application Server Containers for J2EE 10g (10.1.2.0.2)].server.http.AJPRequestHandler.run(AJPRequestHandler.java:224)
    at com.evermind[Oracle Application Server Containers for J2EE 10g (10.1.2.0.2)].server.http.AJPRequestHandler.run(AJPRequestHandler.java:133)
    at com.evermind[Oracle Application Server Containers for J2EE 10g (10.1.2.0.2)].util.ReleasableResourcePooledExecutor$MyWorker.run(ReleasableResourcePooledExecutor.java:192)
    at java.lang.Thread.run(Thread.java:534).

  • I have locked myself out of my ipod by entering the wrong password to many times now it tells me to plug it in to the computer and go to itunes when i do that itunes says it cant connect because the ipod is locked im lost at what to do about this anybody

    i have locked my self out of my ipod by entering the wrong password to many times now it tells me to plug it in to the computer and log into itunes when i do itunes tells me it cant open my ipod because its locked does anyone know how to fix this?

    IPhone, iPad, iPod touch: Wrong passcode results in red disabled screen
    Please Get the iPod Touch User Manual for iOS 5

  • Log in issue (Wrong password?)

    I'm having an issue login in on iTunes Store.
    I have on my network three computers a Mac Pro with Mac OS X Leopard, MacBook with Mac OS X Leopard and a Windows based PC with Windows XP. All of them run iTunes 8.1
    The main music library is on the Mac Pro and the other two computers access to the music by the network, to the shared library of the Mac Pro.
    Now I want to deauthorize the MacBook to replace the hard drive (not a hard disk drive issue, just I get a bigger one) and reinstall OS X. When I try to deauthorize the MacBook iTunes don't log in, it says that the password I used is wrong. When I try to connect to the store, it sais the same thing. I tried to log in from the Mac Pro, Windows PC and iPhone and it work right, so I guess that issue is on the MacBook, not in the iTunes Store account.
    Does anyone know how to solve that?

    I just took my new Macbook out of the box today. I went to sign in/authorize it through my existing itunes account. I got the same error messages mentioned by many of you. I then tried to download a song from my Ipod touch to see if the password would be valid there; however, it did not work there either. I followed the instructions for changing the password twice. It still did not work. Here is the weird part -- I logged in successfully from my old Dell laptop. It seems others are having a similar problem, but is there some way to determine if Itunes is the source of the problem? A number to call? I am new to troubleshooting with Mac. Thanks.

  • Desktop Administrator Locked by another user

    Lately I have been having a problem making changes to workflow on my primary UCCX 7.0(1)SR3 server. I open desktop administrator and click on "Side A", then login to the desktop administrator site, but each time I get a popup saying that CDA is locked by another user. Am I doing something wrong?

    Hi,
    There is a bug opened for this but we are still trying to get a clean set of logs to provide to the development team for root cause.
    If the problem is still happening, can you please open a TAC case and complete the following:
    1. Se the WebAdmin debug level to DEBUG and set the files to 10
    2. Set the LRMServer debug level to TRACE and set the files to 10
    Try to login to the WebAdmin and get the message that another user is logged in. Wait 15 minutes. Try to navigate to another page like the Enterprise Data Fields page and see if the 'Save' button is activated or if you still get that message.
    Collect the following:
    1. WebAdmin*.dbg from C:\Program Files\Cisco\Desktop\log
    2. LRMServer*.dbg from the same location
    3. WebAdmin*.dbg from C:\Program Files\wfavvid\tomcat_appadmin\logs
    Turn the Threshold=OFF for the LRMServer after the test.

  • Changing the password for PI service users

    Hi,
    Based on the SLD configuration document, i have changed the SLDAPIUSER to PIAPPLUSER while configuring SLD.
    I have the following queries:
    1. When i executed sldcheck transaction, business systems are not displayed even though we maintained the business systems in SLD. When i access sldapicust transaction, the user name i gave was PIAPPLUSER. is there any connection between this transaction and the SLD.... That is will the system check for the user provided in sldapicust transaction with that of SLD side?
    2. When will the business systems be displayed in sldcheck?
    I have specified PIAPPLUSER in SLDAPICUST transaction. We are not able to login to R/3 using PIAPPLUSER id. Is this the reason we are not able to see the business systems in Sldcheck transaction?
    I have configured LCRSAPRFC and SAPSLDAPI RFC connection and it is working fine...
    3. Can we log on with PI service users like PIAPPLUSER, SLDAPIUSER, PIAPPLUSER  in R/3 side....? We are able to login with PISUPER, PIDIRUSER users...Can we change the password for service users?
    4. After changing the passwords for service users in su01as well as in exchage profile, do we need to restart the J2EE engine? If so is it enough that we can restart from SMICM transaction-> Administration ->J2ee Instance(local) -> Restart or we need to restart from MMC
    Kindly help me... Your response highly appreciated....
    Thanks,
    Madhukar

    Madhukar,
    1)Check the password for PIAPPLUSER.
    2)As long as PIAPPLUSER is service user ,you cannot log in.If you want to check the password then change the user type to Dialog then log in.But remember that you revert back to service user once your work is done.
    3) We cannot login with service users but if you want to log in then change the user type to Dialog from SU01.
    4)No need restart the J2EE Engine after changing the passwords.
    Thanks
    Kalyan

  • User can't log in / Server can't create new users

    I recently updated to OS X Server 10.5.5. Now one of my users can't log in. Wrong username or password the system says. I've reset the password but it doesn't help.
    When creating a new user I get this error:
    "The server reported the error '-14120' while trying to create the user."
    How can I fix this?

    Well, to move the stuff, make a New Account, log into a different admin account & get BatchMod, it's much better/easier than the Finder for recursive Permission changes...
    http://www.lagentesoft.com/batchmod/index.html
    Now careful with BatchMod, it's crazy powerful, but easier than Command Line.
    Oh, this bad user isn't using FileVault I hope???
    OK, once BatchMod is loaded, you can drag the whole bad user's folder to it's icon and set the Ownership/permissions to the new replacement user, check Apply to Enclosed items, go.
    Oh, if you have room you might make a copy of that User's folder first & use the copy.
    Then open the bad User's folder, Select All, drag to new replacement User's folder.

  • Lightroom 5 to Behance Publish Service doesn't recognize Creative Cloud login

    I'm trying to publish to my Behance service which I have access to via Creative Cloud. When I try to set up the publish service in Lightroom 5 it gives a wrong password error when I enter the Creativer Cloud name and password. I can log in to Behance with those credentials and have already set up a simple page.

    Sarahktrapp1,
    Quoting you (May 6) in another thread titled "I cannot link Lightroom CC to my Behance account".
    Unfortunately, a recent change made to the Lightroom integration has caused this feature to be inaccessible to some users.
    The feature should continue to work as normal for those who had previously used it, but new users won’t be able to authenticate.
    The Lightroom team is working hard to fix this as soon as possible, but it will be inaccessible for a number of weeks, so we suggest that you use Behance directly in order to share your work there. Simply login to Behance with your Adobe ID, and add a Project or WIP directly to your portfolio instead.
    Note that the other Creative Cloud integrations (Photoshop, InDesign, and Illustrator) will continue to work as normal - more instructions on how to use those here.
    Thank you so much for your patience.
    So apparently, you know why we can't login from Lightroom with valid credentials and you asked us to wait for a fix. The initial post in this thread reports the very same problem but you are giving us a different answer. Has this problem been fixed? Is it another problem with the same symptoms? I guess it's time to clear up the confusion.
    Thanks.

  • I locked myself out of my ipod touch for 60 mins then actually typed the wrong password in again.  Now it is telling me to "connect to itunes".  I am unsure how to do this.  I am unable to use my ipod at all now. Please help.

    Hi,
    Due to my brother locking me out of my ipod touch I had to wait an hour to log in again.  Unfortunately when I did this, I, again put in the wrong password twice more, each time locking me out for a further 60 minutes.  On my 3rd attempt to log in the wrong password was entered again.  This time though instead of logging me out for another 60mins it now tells me to "connect to itunes" but I have no idea how to do this and I am now unable to use my ipod.  Please help.

    See Here  >  http://support.apple.com/kb/HT1212

  • Locked service user XIAPPLUSER on XI 3.0

    Hello,
    one of our Service user gets locked from time to time.
    It is the service user XIAPPLUSER.
    I already have activated the Audit on the system. But the only helpful
    logs I can find in SM20 are telling me:
    "13:55:13 DIA 04 889 SAPJSF
    172.19.1.140 BU1 Password check failed for user XIAPPLUSER in"
    The granularity on this doesnt increase when I set the filter in SM19
    to display "All" events instead of display "only critical" events.
    So I cannot know from where the login attemps arise.
    Can anyone tell me about any other log file etc where I could dig deeper into attemps to login to the system?
    Which exact purpose does this XIAPPLUSER have? from which XI Components
    to which other components does he normaly interact?
    Thanks and regards
    Nesimi

    Hi,
    XIAPPLUSER is usually used by XI to login to the Application systems.
    Depending on the config, it may also be used by the application systems to log into XI. You can check this by checking the user configured in transactions SLDAPICUST, sxmb_adm->Integration Engine Configuration and also the sm59 destination for the Integration Server.
    Hope this helps.
    Cheers
    Manish

  • PI 7.0 service users are locked

    Hi guys,
    We have PI7.0 installed and configured properly.
    We created a custom product and software component version in SLD and when we are trying to import it in IR we get "Unable to read software component versions from System Landscape Directory". Just to let you know PI is on one host and SLD on another.
    It is obvious that something is wrong with users in the communication between IB and SLD.
    We have tried everything:
    1) notes 764176, 768148, 720717, 741214, found on relevant posts.
    2) Exchange profile checks, we added extra roles to PIREPUSER, we replaced PIREPUSER in Exchange Profile with PISUPER, creating all PI service users with user roles in ABAP part of SLD etc... When I changed something in ABAP part, I performed "assign roles to user groups" in VA of Java part.
    However, I noticed that in SLD's UME in Java some of the PI service users are locked and I am unable to unlck them, since when I try to do so with user j2ee_admin, I get "There was an error. Please contact administrator"
    Any ideas??
    Evaggelos

    Thanks to both guys. I will award points.
    The problem was caused due to some PI users that were locked on the J2EE part of XI, and therefore they could not connect to the SLD. I unlocked them through VA 's, Security Provider service.
    Evaggelos

  • Can't log in with valid password, can't boot from disk, can't access disk utility, in single user mode can't reset password as appears locked in caps mode with '?' for forward slash, can anyone help?

    Can't log in with valid password, can't boot from disk, can't access disk utility, in single user mode can't reset password as appears locked in caps mode with '?' for forward slash, can anyone help?

    Which keyboard layout you were using? German, French ... I suppose your layout is reset to the default: US and you are unable to find the "?" or "/" ...
    Please have a look into the keyboard viewer, to see how the layout of your keyboard is actually.
    marek

Maybe you are looking for