Server unlocks locked users automatically - why ?

Hello,
I am using WLS 6.1 SP1
I have set Lockout Enable option to TRUE in Password tab of security.
I also have set
Lockout Threshold = 3
Lockout Duration=999999
Lockout ResetDureation= 5
and rest are default.
After invalid login in a span of 5 minutes, server locks the user.
I can see the status on the console server->Monitoring->Security tab
Total User Unlocked = 0
Locked Users = 1
But if try to login again with same (locked) user with or without correct
password,
the server unlocks user. Next attempt with correct password, user will be
successfully authenticated.
If you see in the console for server->Monitoring->Security tab,
Total User Unlocked = 1
Locked Users = 0
I have not used any unlock command.
Is there is anything wrong in the configuration or web.xml ?
Thanks
Deepak

Hello,
I found out one problem - Looks like a BUG
If Lockout Duration = 999999 then Server unlocks locked user automatically
during next login attempt
with correct or incorrect password.
This looks like a bug becuase
--- Value 999999 is the maximum value allowed and it accepts this value.
In the documentation, this value represented in terms of Seconds as the unit
of measurement
whereas actaully the <Lock Notice> is displayed in terms as 999'999 Minutes.
I tried with value 99999 (5 digits), it works !!!
Regards
Deepak
"Deepak Rampoore" <[email protected]> wrote in message
news:3C43A75F@mail...
Hello,
I am using WLS 6.1 SP1
I have set Lockout Enable option to TRUE in Password tab of security.
I also have set
Lockout Threshold = 3
Lockout Duration=999999
Lockout ResetDureation= 5
and rest are default.
After invalid login in a span of 5 minutes, server locks the user.
I can see the status on the console server->Monitoring->Security tab
Total User Unlocked = 0
Locked Users = 1
But if try to login again with same (locked) user with or without correct
password,
the server unlocks user. Next attempt with correct password, user will be
successfully authenticated.
If you see in the console for server->Monitoring->Security tab,
Total User Unlocked = 1
Locked Users = 0
I have not used any unlock command.
Is there is anything wrong in the configuration or web.xml ?
Thanks
Deepak

Similar Messages

  • User Management API for unlocking/locking users

    Hello All,
    I am trying to develop an application where in a person should input the user id and check if the user is currently locked or unlocked. And also if it is locked, he should be able to unlock it. I want to know that, is there any UME API available for fetching the lock/unlock status and modifying it? I tried using IUsermaint but it does not returns the lock status. Any input on this? or may be a code snippet?
    Thanks in advance.
    Ameya

    The setLocked() method mentioned above takes 2 parameters, a boolean and an int.
    public void setLocked(boolean lock, int reason)
    boolean parameter indicates whether to lock or unlock user. In above snippet, I have given it as false which is to unlock user. To lock the users, mention the parameter as true.
    int parameter is to specify the lock/unlock reason.
    Check javadocs for more details
    http://help.sap.com/javadocs/nw04s/current/se/com/sap/security/api/IUserAccount.html
    Regards,
    Yoga

  • Unlock user automatically after given time

    Hi,
    I have a requirement where I need to unlock the user automatically after 2 hours once his account gets locked(after 3 unsuccessfull attempts).Do we have this feature Out of the box or we need to write a scheduler for this.
    Regards,
    Edited by: 851992 on Apr 13, 2011 4:54 AM

    Hello,
    If you are using Oracle Access Manager in the setup, then this is feature available out of the box.
    -Mahendra.

  • Unlock specified users which locked due to incorrect logon automatically

    Hi experts, All users will be locked if he logon incorrectly 3 times in our system now and unlocked in the midnight.
    Can I unlock some specified users automatically in specified time I set or is there any method to exclude these specified users to be locked even logon incorrectly 3 times ?
    Best wishes,
    Evan

    >
    Rao Evan wrote:
    > Hi Alex, thank you for your reply,  it seems there is no normal method to do it. Maybe I need ABAPer to help solve it.
    >
    > Best wishes,
    >
    > Evan
    Hi Evan,
    Alex is right: it's worth to clarify (with the auditors) which system behavior is desired before taking any action (in terms of coding). Let me guess: those "special" users are belonging to the "upper management" user group ... - they just don't like the feeling of being "locked out" (even if it was their own fault not to memorize the password). Unfortenately, exactly those users are critical and potentially subject of password attacks (since they are equipped with powerful authorizations).
    Maybe it would sense to convince the management to invest in smardcards (at least for that special user group). Using a non-password based user authentication mechanism eliminates the risk of undesired password locks - without imposing other (even greater) risks.
    If you still want to implement such automatic unlocking (despite the advice given above) you should write your own tiny ABAP report which then submits function calls to BAPI_USER_UNLOCK and schedule a periodic background job for that report.
    Cheers, Wolfgang

  • IdM User automatically locking ABAP account after setting new password

    Hi Experts
    We are currently facing a problem, where it seems that the idmuser used when provisioning to ABAP is setting a value 128 (locked due to wrong logon) almost simultaneously as setting the new password on the user. I have found the information under SU01 and changes on the user account.
    I cannot find anywhere in IdM that the value 128 is set to the "islocked" attribute. When provisioning new passwords, we do'nt even try to set the "islocked" attribute. We do unlocking/locking in separate tasks - and NEVER us the value 128.
    Does anyone have a good explanation as to why/how this can happen?
    Kind regards
    Heidi Kronvold

    Did you resolve this?  I have a similar (though not identical) problem in that the user gets no password assigned when provisioning.  Even users that already exist in that system get their password removed which effectively disables the password not allowing the user to login.  I am using 100% out of the box SAP provisioning framework.

  • Automate unlocking a user account

    automate unlocking a user account by users themselves in case of the following
    1. User accounts that get locked on entering a wrong password
    2. User accounts that are locked due to "Inactivity End date"
    2. can we write a script, to change the password of a user ? are there any functions or API avaialable ?

    Are you referring to the application users? If yes, then you could use FND_USER_PKG API or FNDCPASS (FNDCPASS can only change the password).
    Please see old threads for similar discussion -- http://forums.oracle.com/forums/search.jspa?threadID=&q=FND_USER_PKG&objID=c3&dateRange=all&userID=&numResults=15&rankBy=10001
    Thanks,
    Hussein

  • How to find list of locked users & unlock them?

    Hello,
    Is there any method in portal to find the list of locked users? and unlock them.
    we can unlock single user at a time. 
    but if we want to unlock a group of users (for Ex:- 20 locked users), how can we unlock al the 20 locked users?
    Thanks in advance,
    Vila.

    Hi Vila,
    Go to user administration -> Identity management
    Click on advanced search. Go to account information tab. Check the use account locked field and then click on search. This will give you a list of all the users whose accounts are locked.
    Select all the users whose accounts you want to unlock, and then click unlock.
    Regards,
    Ankit

  • When Starting OC4J, why the report server doesn't start automatically? !!

    Dear All,
    I have DS 10g on my system and I start the OC4J when I have to run either forms or reports.
    But when I attend to start the do the following command from the form:
    WEB.SHOWDOCUMENT(..../getjobid<jobid>?server=<servername>...), I have an error: FRM-41213: Unable to connect to the report server <servername>.
    I noticed that if I run the following URL:http://<server>:.../reports/rwservlet, it gives me a list of command, but the server still not running..But if I add any command to the above URL like for example "getserverinfo" or "showjobs" then the server is started. Now, and after the command, if we return back and we run the report from the form, the report will run successfully.
    The question WHY??
    Regards,
    Joe
    Message was edited by: Joe
    Joe Farah

    Hello,
    That's the way it works ...
    http://download-uk.oracle.com/docs/cd/B14099_17/bi.1012/b14048/pbr_strt.htm
    2.1.3.1 Starting the In-process Server (Windows and UNIX)
    If you are using Reports Server as an in-process server (the default configuration), sending a run report request starts the in-process server; however, if you are sending a request through a command line, the servlet must be invoked first using either the run report URL or the Web command URL. When you have successfully started the servlet, this also means you have successfully started the in-process server.
    If you use "Oracle Application Server", the "in-process" reports server will be started automatically by opmn ...
    Regards

  • Locking and unlocking mass users

    Hello
    How can we lock and unlock mass users?
    Edited by: Mohammed Siddiqui on Jul 16, 2008 2:37 PM

    Hi Siddique,
    Follow the below link
    Re: locking users while implementing support packs
    Regards
    Zam

  • Trying to unlock the user, message says " user xyz is still locked"

    Hi,
    I am trying to unlock a user locked due to incorrect logins, the message "user xyz is still locked" comes up and user is not unlocked. I don't remember seeing this message earlier. SAP 4.7.
    Any ideas/suggestions, please.
    Thanks in advance
    Ravi

    Hi
    Are you using CUA ? in that case you might need to unlock the user on the central system, Furthermore check transaction SCUL
    Regards
    Morten Nielsen

  • Hoe to unlock the locked user SAPUSER ????

    when i was working with Tcode S002, that is for authorization overview, there i found a Tcode to lock/unlock the user. when i lock the only one existing user SAPUSER, incidently power cut off. now the problem is that, i m not able to log on in my SAP. so how to resolve the problem. plz help immediately??
    is there any other way to logon the system instead of SAPUSER?
    note: i have only one client 800 and one user SAPUSER..

    Hai,
    Check the below link.....
    Re: Want help to unlock SAP* user
    You can activate SAP* in your system.
    If user sap* doesn't exist in your client you can logon with sap* password pass
    To activate user SAP* you have to set at operative system level in your instance profile the parameter login/no_automatic_user_sapstar to 0 then restart the system.
    If the user already exist and you not remember password, delete the user from database (if oracle):
    sqlplus /nolog
    connect / as sysdba
    DELETE * from sapsr3.usr02 where bname='sap*' and mandt=<your client>;
    commit;
    After this you can login with the SAP* user in 800 client and unlock your user.
    Regards,
    Yoganand.V
    Edited by: Yoganand Vedagiri on Feb 13, 2009 6:54 PM
    Edited by: Yoganand Vedagiri on Feb 13, 2009 6:56 PM

  • Why iPad mini retina smart unlock/lock function not working when I using 3rd party cover with magnetic

    I recently bought a leather case from store with smArt unlock/lock function with magnetic. I try to use it on my iPad mini retina when I try to close and open it doesn't work. I already on my smart unlock function inside setting. May I know where is the magnetic area  of iPad mini retina ?

    The "Lock/Unlock" feature is enabled by installing a compatible Smart Cover/Case (or third-party equivalent) with an embedded magnet in the correct position in the cover. Are you using a real Apple product? If not, the cover/case you are using may not have the magnet in the right place or may not even have one at all.
    If you ARE using a real Apple Smart Cover/Case and you have an Apple Store nearby, have them check both the case and cover you are using. You may have a bad magnectic switch on the iPad or a faulty cover/case.
    I also remember reading here of a Smart Case/Cover which had the magnet installed upside-down and was repelling rather than attracting. You might want to take the cover off and flip it to verify this...you'll have to slide the cover around in different positions on the right-hand bezel on the iPad to see if you can activate the magnet.

  • Screen saver unlock/lock times....

    I'm looking for a way to track when folks unlock/lock their screen savers. Is there a program or log file that can assist me here? I need to be able to do this so I can track when users are unlocking/locking their machines. Most users don't logout of their machine, so the screen saver is my best option I think. They are running 10.9.2.
    Suggestions are welcome for tracking times other than this route as well.
    Thanks in advance,

    My grandmother is 85 years old.  The Ipad we bought her is primarily used for receiving emails with pictures from us, which are then displayed in the slide show of the screen saver.
    Last night my genious brother decided for some reason to upgrade her Ipad to IOS7.  I have no idea why he did that,  but he rendered the Ipad useless for her use.
    In the time since the last message was posted on this thread, has anyone found any workaround,  app or anything that can be of help.  Did anyone downgrade to IOS6 successfully?
    Please note anything other than the an automatic slideshow including new pictures would not be useful.
    I am at a loss and desparately need a solution for this one.

  • How to find the Locked User Account in OBIEE Admin Console

    We have recently implemented OBIEE and we are in Learning mode. An user complained that his user account is locked, since he tried to login several times with wrong password. Apparently we unlocked his account successfully. Is there any way to find which user accounts are locked? This may be really helpful for
    Thanks in advance.

    Looks like using wlst code can get the list
    Check this
    http://weblogic-wonders.com/weblogic/2010/11/12/userlockout-feature-of-weblogic-server/
    If you customize above code with the below, can get the list of locked users on console
    ul= connection.invoke(ulr, "isLockedOut", new Object[] { username },new String[] { "java.lang.String" }).toString();
    System.out.println("Rezultat isUserLocked " + ul);
    pls mark correct/helpful if helps
    Edited by: veeravalli on Oct 18, 2012 11:51 AM

  • Start SQL Server in single user mode with parameter -m doesn't work well

    C:\Windows\system32>net start mssqlserver /m "Microsoft SQL Server Management St
    udio - Query"
    The SQL Server (MSSQLSERVER) service is starting.
    The SQL Server (MSSQLSERVER) service was started successfully.
    C:\Windows\system32>sqlcmd -S . -e
    1> go
    1> select @@servername;
    2> go
    select @@servername;
    myserver
    (1 rows affected)
    1>
    As you can see, I'm still able to connect with sqlcmd prompt to SQL Server. According production doc of SQL Server 2014, it should not be conncting by sqlcmd. it shall only be connected by SSMS.
    below the original doc on msdn:
    Start SQL Server in Single-User Mode
    Provide Feedback
    Under certain circumstances, you may have to start an instance of SQL Server
    in single-user mode by using the startup option -m. For
    example, you may want to change server configuration options or recover a
    damaged master database or other system database. Both actions require starting
    an instance of SQL Server in single-user mode.
    Starting SQL Server in single-user mode enables any member of the computer's
    local Administrators group to connect to the instance of SQL Server as a member
    of the sysadmin fixed server role. For more information, see Connect to
    SQL Server When System Administrators Are Locked
    Out.
    When you start an instance of SQL Server in single-user mode, note the
    following:
    Only one user can connect to the server.
    The CHECKPOINT process is not executed. By default, it is executed
    automatically at startup.
    Note
    Stop the SQL Server Agent service before connecting to an instance of SQL
    Server in single-user mode; otherwise, the SQL Server Agent service uses the
    connection, thereby blocking it.
    When you start an instance of SQL Server in single-user mode, SQL Server
    Management Studio can connect to SQL Server. Object Explorer in Management
    Studio might fail because it requires more than one connection for some
    operations. To manage SQL Server in single-user mode, execute Transact-SQL
    statements by connecting only through the Query Editor in Management Studio, or
    use the
    sqlcmd utility.
    When you use the -m option with sqlcmd or
    Management Studio, you can limit the connections to a specified client
    application. For example, -m"sqlcmd" limits connections to a
    single connection and that connection must identify itself as the
    sqlcmd client program. Use this option when you are starting
    SQL Server in single-user mode and an unknown client application is taking the
    only available connection. To connect through the Query Editor in Management
    Studio, use -m"Microsoft SQL Server Management Studio - Query".
    Shawn

    Hi Shawn Xiao,
    For starting SQL Server instance in single user mode, we can add –m; parameter in SQL Server Configuration Manager, also we can run CMD with ‘Run as administrator’ and input the following statement.
    NET START MSSQLSERVER /m
    I do a test in SQL Server 2014 Express version, after starting SQL with Single User Mode, SQL Server will only accept one connection. If you connect to SQL Server with a user account, the following error will occur.
    Login failed for user ‘domain\username’. Reason: Server is in single user mode. Only one administrator can connect at this time.
    However, in your situation, you can connect to SQL Server and run T-SQL statement successfully, it can be due to connection with the administrator account in your sqlcmd.
    For more information, you can review the following article.
    http://zarez.net/?p=117
    Regards,
    Sofiya Li
    Sofiya Li
    TechNet Community Support

Maybe you are looking for