1.3.5.8.1.1.  DSGVO

The DSGVO contains rules on the protection of individuals with regard to the processing of personal data.

CADENAS processes user-related data such as name, computer name, time, etc. according to the used software processes and functions.

In the following, detailed information is subdivided into singe use cases.

1.3.5.8.1.1.1. General possibilities of data query

In general, all Windows users and groups can be displayed under PARTadmin -> Rights management [Rights administration] category -> User databases tab page on the Windows tab page. As a rule, the PARTadmin module is only available to the administration and access to GDPR-relevant files is regulated via the Windows rights management.

Other AD attributes can also be queried in PARTadmin -> Rights management [Rights administration] category -> User databases tab -> LDAP tab. However, filters must be configured accordingly.

1.3.5.8.1.1.2. Data query via Dashboard

For AppServer administration, the PARTapplicationServer dashboard can be opened via PARTadmin -> AppServer Client [AppServer client] category -> Diagnostics [Diagnostic] dialog area by clicking on Show server status [Show server state].

Show server state Show server state

Show server state

You will find the following subcategories on the System information tab page:

  • Licenses:

    • Licenses

    • Active licenses

    • Content of configuration file

    • Content of log file

      • Floating environment

    • License product preselection (USER)

    • License product preselection (SETUP)

  • Catalogs

    • Installed catalogs

  • Network information

    • Local IP addresses

    • Used proxies

  • File system mounts

    • Installed file systems

  • OpenGL information

[Note]Note

Without a login, only the Services and Web modules [Web-Modules] tabs are visible under Server status.

In order to have access to all information, the logged-in user (administrator) must have the Appserver administrator (appserver-admin) right.

The assignment takes place in PARTadmin > Category Application Server > Rights management [Rights administration] > Rights assignment [Assign rights] tab > Profiles.

Profiles Profiles

Profiles

1.3.5.8.1.1.3. Data processing during login

Data is saved according to the configuration under PARTadmin -> Rights management [Rights administration] category -> Rights assignment [Assign rights] tab page:

ERP -> Roll set [Role set]

ERP -> Roll set [Role set]

  • Mapping of user ID to PARTsolutions ERP role and profile

  • Mapping of group ID to PARTsolutions ERP role and profile

  • Neither if all users have the same role and profile

  • Neither if users have different roles and profiles (see example below)

In the following you can see an example how a user-related and a neutral login may look like.

  1. User-related login:

    As soon as the Active option is activated on the Windows tab page under PARTadmin -> Rights management [Rights administration] category -> User databases tab page, a user-related login can be carried out.

    -> When logging in with the Windows user, user ID, group, group membership and domain are registered.

    -> The Windows username is displayed at different places of the software, for example in the status line.

    Username in status line

    Username in status line

    The user-related login may happen manually or automatically.

    Database login

    Database login

  2. Neutral login:

    The following scenario will exemplarily show how to set up a neutral, meaning not user-related login:

    1. Deactivate the Windows option in PARTadmin -> Rights management [Rights administration] category -> User databases tab page

      Windows disabled

      Windows disabled

    2. Activate the ERP (plinkusers) option in PARTadmin -> Rights management [Rights administration] category -> User databases tab page and create users.

      ERP (plinkusers) activated

      ERP (plinkusers) activated

    3. These users you have to get assigned a role set.

      -> Now when calling an application (e.g. PARTdataManager) the user authentication with a created ERP user and password can happen.

      Use currently logged in operating system user

      Use currently logged in operating system user

      With an incorrect entry a respective message is displayed.

      Invalid username or password!

      Invalid username or password!

      -> In PARTdataManager, role set (and role) is displayed in the status line (no Windows user).

      An alternative solution for working with a neutral database login is to use a group name as the Windows login. (This solution is only GDPR-compliant if the group has more than one user)

      Another alternative besides the group name is to assign the configuration "Default/Logged in". This then applies for all users, which are not assigned in any other way.

1.3.5.8.1.1.4. Data processing when accessing ERP database

A database password must be saved to access the ERP database.

The entry is made under PARTadmin -> Category ERP environment -> Database connection.

DB [DB User] user/DB [DB Password] password [DB User] or DBO [DBO user] user/DBO [DBO Password] password [DBO user] are stored in encrypted form.

The password is saved in the configuration file plinkusers.cfg.

"Database connection [Database connection] " category -> " Available database connections " dialog area

"Database connection [Database connection] " category -> " Available database connections " dialog area

User-related data can also be saved during data processing, such as the creation of an ERP number or changes to roles and rights.

  • When adding an ERP number the following entries are set in the LOGTABLE, among others:

    • Login name of user which performed the change.

    • Computer name of client

    • Program name

    • Time

    • ERP number of created data set

    Call via PARTlinkManager -> tab page "Extras [Extras] " -> "Database [Database] " -> "Edit additional tables [Edit additional tables] "

    Call via PARTlinkManager -> tab page "Extras [Extras] " -> "Database [Database] " -> "Edit additional tables [Edit additional tables] "

  • CAD environment: Date creation in the CAD environment (CAD attributes)

    Concerning the attributes transferred to the CAD only the ones written in the LOGTABLE are stored on the part of CADENAS.

  • PLM environment (PLM login)

1.3.5.8.1.1.5.  Catalog Online update

PARTadmin -> Category Catalog update -> Online

Email and password are stored in partupdate.cfg.

Each CIP download is allocated to a user. Username and also IP are stored.

Catalog Online update

Catalog Online update

Authenticate user

Authenticate user

1.3.5.8.1.1.6. Logging

Logging can be used for analysis purposes.

In the Logging settings [Log settings] dialog, part of the Settings dialog page, which you can open from PARTsolutions and eCATALOGsolutions modules via Tools [Extras] menu -> Settings [Preferences], you can define the log level. The user name, for example, is also logged during the login process in modules.

Log settings Log settings

Log settings

The logging data is output in the output file at $Temp\psol_logs\cadenas_error.log.

cadenas_error.log

cadenas_error.log

The display in the GUI takes place in the log window [Log window] of the respective module.

Example PARTdataManager: Log window Log window

Example PARTdataManager: Log window

1.3.5.8.1.1.7.  License server

GDPR-relevant information regarding license servers can be found on the Section 1.4.4.4, “ Security " tab page ”. This point is also relevant without ERP.