MIS Systems Thread, CMIS/ePortal security question in Technical; Hi all,
Does anyone know how secure Facility CMIS and ePortal are against packet sniffing attacks? I'm not sure about ...
-
31st May 2007, 12:21 PM #1
- Rep Power
- 13
CMIS/ePortal security question
Hi all,
Does anyone know how secure Facility CMIS and ePortal are against packet sniffing attacks? I'm not sure about CMIS Admin, but I assume ePortal is pretty vulnerable as it operates over HTTP rather than HTTPS.
Am I right in thinking that someone within the school network could potentially sniff out an ePortal username and password pretty easily and then gain access to the data within? If so has anyone been able to counter this?
Thanks
-
-
IDG Tech News
-
31st May 2007, 01:24 PM #2 Re: CMIS/ePortal security question
I imagine you could use IIS Securely...
-
-
31st May 2007, 01:27 PM #3 Re: CMIS/ePortal security question
I believe that's an oxymoron. However, yes, the answer is to use HTTPS instead of HTTP.
-
-
31st May 2007, 04:40 PM #4
- Rep Power
- 13
Re: CMIS/ePortal security question
Is it really that simple? Serco don't make any mention of using SSL with eportal and it seems like such a basic security thing that it should be covered. The IIS solution just seemed too basic somehow and the total lack of mention of it on Serco's part made me question whether there was some problem with using that.
Is there any word on how secure communications between CMIS Admin and the SQL server are? If Force Protocol Encryption is enabled on SQL Server 2000, is this sufficient?
-
-
31st May 2007, 10:46 PM #5 Re: CMIS/ePortal security question

Originally Posted by
Geoff I believe that's an oxymoron. However, yes, the answer is to use HTTPS instead of HTTP.
touche.
I believe also you can configure tomcat to operate securely. Please do not ask how to do this.
-
-
31st May 2007, 10:56 PM #6 Re: CMIS/ePortal security question
i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work.
-
-
30th October 2007, 12:26 PM #7
- Rep Power
- 16
Re: CMIS/ePortal security question

Originally Posted by
k-strider i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work.
Any luck? I have installed the SSL Certificate - however I get that the secured page contains secure and non-secure items! Not ideal! :P
-
SHARE: 
Similar Threads
-
By stitch in forum MIS Systems
Replies: 18
Last Post: 9th October 2007, 09:27 PM
-
By daveyboy in forum MIS Systems
Replies: 2
Last Post: 9th October 2007, 07:13 PM
-
By markberry in forum MIS Systems
Replies: 12
Last Post: 26th March 2007, 11:27 PM
-
By tosca925 in forum Educational Software
Replies: 5
Last Post: 11th January 2006, 09:08 AM
-
By SpuffMonkey in forum Educational Software
Replies: 10
Last Post: 20th December 2005, 10:55 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules