on 01-06-2014 12:29 PM
Hello,
Due to security reasons, I need to disable the usage of SAP Management Console.
Do you know an easy way to do it ?
I have read in 1439348 - Extended security settings for sapstartsrv that one possible way is to restrict the network access, by restricting the remote access via the network to ports 5XX13 / 5XX14 of the sapstartsrv agents to a minimum level required for operation.
This sounds quite dangerous, and I have no example to double check.
Have you ever did this ? Do you know any easier methods, maybe ?
Thanks in advance,
J.
I don't think it is possible to uninstall the MMC tool as it is one of the tools from Microsoft.
Also I don't think it is possible to disable MMC.
You may try to bring in some restrictions based on these.
Control MMC Usage by Using Domain-Wide Group Policy
Control MMC Usage by Using Local Group Policy
Regards
RB
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Reagan,
We might also restrict access to this interface by configuring the "service/protectedwebmethods" profile parameter. I found this in note 927637
"
After you implement a current sapstartsrv or kernel patch (640 patch 337, 700 patch 263, 701 patch 101, 710 patch 208, 711 patch 93, 720 patch 45), you can activate the new default configuration. To do this, set the following in the default profile:
service/protectedwebmethods = SDEFAULT and restart all sapstartsrv to activate the changes. "
By SDEFAULT almost all methods are protected, except of GetProcessList and GetSystemInstanceList.
In DEFAULT - only Start/Stop, RestartInstance (all methods that affect instance state).
What do you think about this idea ? Would it have impact on something else ?
Thanks
Jordan
Hello Jordan
I have never done this so I cannot give you a concrete answer.
The note is speaking about setting a parameter.
If I were in your place I would first try the solutions mentioned in the SAP notes 1439348 and 927637 on a test system and then check whether the SAP systems are running fine before I set them on the production servers.
Based on the information from those SAP notes it should be fine.
Regards
RB
Hi Jordan
You can uninstall the SAP MMC Snap-in from control panel.
Regards
Sriram
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
76 | |
9 | |
8 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.