+ Post New Thread
Results 1 to 7 of 7
MIS Systems Thread, CMIS/ePortal security question in Technical; Hi all, Does anyone know how secure Facility CMIS and ePortal are against packet sniffing attacks? I'm not sure about ...
  1. #1

    Join Date
    May 2007
    Location
    Southampton
    Posts
    93
    Thank Post
    7
    Thanked 4 Times in 4 Posts
    Rep Power
    15

    CMIS/ePortal security question

    Hi all,

    Does anyone know how secure Facility CMIS and ePortal are against packet sniffing attacks? I'm not sure about CMIS Admin, but I assume ePortal is pretty vulnerable as it operates over HTTP rather than HTTPS.

    Am I right in thinking that someone within the school network could potentially sniff out an ePortal username and password pretty easily and then gain access to the data within? If so has anyone been able to counter this?

    Thanks

  2. #2

    Join Date
    Jan 2007
    Posts
    423
    Thank Post
    7
    Thanked 30 Times in 26 Posts
    Rep Power
    21

    Re: CMIS/ePortal security question

    I imagine you could use IIS Securely...

  3. #3

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,803
    Thank Post
    110
    Thanked 583 Times in 504 Posts
    Blog Entries
    1
    Rep Power
    224

    Re: CMIS/ePortal security question

    use IIS Securely
    I believe that's an oxymoron. However, yes, the answer is to use HTTPS instead of HTTP.

  4. #4

    Join Date
    May 2007
    Location
    Southampton
    Posts
    93
    Thank Post
    7
    Thanked 4 Times in 4 Posts
    Rep Power
    15

    Re: CMIS/ePortal security question

    Is it really that simple? Serco don't make any mention of using SSL with eportal and it seems like such a basic security thing that it should be covered. The IIS solution just seemed too basic somehow and the total lack of mention of it on Serco's part made me question whether there was some problem with using that.

    Is there any word on how secure communications between CMIS Admin and the SQL server are? If Force Protocol Encryption is enabled on SQL Server 2000, is this sufficient?

  5. #5

    Join Date
    Jan 2007
    Posts
    423
    Thank Post
    7
    Thanked 30 Times in 26 Posts
    Rep Power
    21

    Re: CMIS/ePortal security question

    Quote Originally Posted by Geoff
    use IIS Securely
    I believe that's an oxymoron. However, yes, the answer is to use HTTPS instead of HTTP.
    touche.

    I believe also you can configure tomcat to operate securely. Please do not ask how to do this.

  6. #6
    k-strider's Avatar
    Join Date
    Oct 2006
    Location
    Gloucester
    Posts
    357
    Thank Post
    7
    Thanked 40 Times in 30 Posts
    Rep Power
    23

    Re: CMIS/ePortal security question

    i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work.

  7. #7

    Join Date
    Nov 2006
    Location
    Reading, UK
    Posts
    487
    Thank Post
    30
    Thanked 14 Times in 8 Posts
    Rep Power
    18

    Re: CMIS/ePortal security question

    Quote Originally Posted by k-strider
    i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work.
    Any luck? I have installed the SSL Certificate - however I get that the secured page contains secure and non-secure items! Not ideal! :P

SHARE:
+ Post New Thread

Similar Threads

  1. CMIS / EPortal Advice
    By stitch in forum MIS Systems
    Replies: 18
    Last Post: 9th October 2007, 09:27 PM
  2. ePortal / Facility / CMIS
    By daveyboy in forum MIS Systems
    Replies: 2
    Last Post: 9th October 2007, 07:13 PM
  3. CMIS ePortal Single Sign-on
    By markberry in forum MIS Systems
    Replies: 12
    Last Post: 26th March 2007, 11:27 PM
  4. Hel with CMIs/ePortal upgrade please.
    By tosca925 in forum Educational Software
    Replies: 5
    Last Post: 11th January 2006, 09:08 AM
  5. CMIS/Eportal - hardware???
    By SpuffMonkey in forum Educational Software
    Replies: 10
    Last Post: 20th December 2005, 10:55 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •