cancel
Showing results for 
Search instead for 
Did you mean: 

User is locked in R/3 but still access the application through portal

Former Member
0 Kudos

We are currently on NW2004s SP10 .

We locked the User A in R/3 SRM backend system and from Enterprise Portal the same User A login and try to access the SRM application in backend . The system is allowing to access which we want to prevent .

The authentication ticket type is "SAP Logon Ticket" . The User A is trying to access ITS services through Portal.

Do we have specific SSO parameter which needs to set in backend SRM application .

Thanks

Chandrashekhar K

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Hi

We have maintained the following profile parameter for SSO in our SRM system . From portal we are accessing the SRM system

login/accept_sso2_ticket 1

login/certificate_request_ca_url https://tcs.mySAP.com/invoke/tc/usercert

login/certificate_request_subject CN=&UNAME, OU=&WPOU, O=mySAP.com User, C=DE

login/create_sso2_ticket 0

login/disable_cpic 0

login/disable_multi_gui_login 0

login/disable_multi_rfc_login 0

login/disable_password_logon 0

login/failed_user_auto_unlock 0

login/fails_to_session_end 3

login/fails_to_user_lock 3

login/isolate_rfc_system_calls 0

login/min_password_diff 1

login/min_password_digits 0

login/min_password_letters 0

login/min_password_lng 6

login/min_password_specials 0

login/multi_login_users HP

login/no_automatic_user_sapstar 1

login/password_change_for_SSO 0

login/password_charset 1

login/password_expiration_time 60

login/password_logon_usergroup

login/password_max_new_valid 0

login/password_max_reset_valid 0

login/system_client 400

login/ticket_expiration_time 60

login/ticket_only_by_https 0

login/ticket_only_to_host 0

login/ticketcache_entries_max 1000

login/ticketcache_off 0

login/update_logon_timestamp m

Please suggest as to change any parameter value . We want to restrict the user to access SRM system from portal if he is locked int e SRM system.

Thanks

brad_landry2
Active Contributor
0 Kudos

Hi,

verify your R/3 password policies :

There is a rule that allow connection with locked acccount.

http://help.sap.com/saphelp_erp2005vp/helpdata/en/22/41c43ac23cef2fe10000000a114084/frameset.htm

Brad