Jump to content

Recommended Posts

Posted

Hi all,

 

Does anyone know how secure Facility CMIS and ePortal are against packet sniffing attacks? I'm not sure about CMIS Admin, but I assume ePortal is pretty vulnerable as it operates over HTTP rather than HTTPS.

 

Am I right in thinking that someone within the school network could potentially sniff out an ePortal username and password pretty easily and then gain access to the data within? If so has anyone been able to counter this?

 

Thanks

Posted

Is it really that simple? Serco don't make any mention of using SSL with eportal and it seems like such a basic security thing that it should be covered. The IIS solution just seemed too basic somehow and the total lack of mention of it on Serco's part made me question whether there was some problem with using that.

 

Is there any word on how secure communications between CMIS Admin and the SQL server are? If Force Protocol Encryption is enabled on SQL Server 2000, is this sufficient?

Posted
use IIS Securely

 

I believe that's an oxymoron. However, yes, the answer is to use HTTPS instead of HTTP.

 

touche.

 

I believe also you can configure tomcat to operate securely. Please do not ask how to do this.

Posted
i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work.
  • 4 months later...
Posted
i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work.

 

Any luck? I have installed the SSL Certificate - however I get that the secured page contains secure and non-secure items! Not ideal! :p

  • 13 years later...
Posted

I'm going to resurrect this discussion, as I have a similar question (now in 2021).

 

Supporting a school using Facility and ePortal, with ePortal operating over SSL and Windows Server up-to-date. As far as I can tell however, there's no password complexity enforcement options in ePortal and the directory structure refers to Tomcat and IIS.

 

IIS security is obviously going to be covered under Windows, but what about Tomcat? I know little about it, but I can see tomcat8.exe is the main executable that ePortal utilises, with the latest version (looking online) being Tomcat 10. The timestamp of tomcat8.exe is September 2019.

 

What do you do if you run a similar setup? And is this at any particular risk? All the relevant firewall rules are in place, yet ePortal (per design) is still accessible over HTTPS publicly.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...