Hello Martin,
If we are implementing it using parameters for custom launchers, this password is sent by the secret server to the client machine and processed by the application running locally. Unless a new method has emerged that I am unaware of, individuals monitoring the traffic can see the password.
We tested this with a SAP GUI custom launcher and were able to capture the password on the end-user's machine. From this perspective, using RDS appears to be much more secure.
------------------------------
mertcan kasap
------------------------------