nutso Posted May 31, 2007 Posted May 31, 2007 Hi all, Does anyone know how secure Facility CMIS and ePortal are against packet sniffing attacks? I'm not sure about CMIS Admin, but I assume ePortal is pretty vulnerable as it operates over HTTP rather than HTTPS. Am I right in thinking that someone within the school network could potentially sniff out an ePortal username and password pretty easily and then gain access to the data within? If so has anyone been able to counter this? Thanks
Geoff Posted May 31, 2007 Posted May 31, 2007 use IIS Securely I believe that's an oxymoron. However, yes, the answer is to use HTTPS instead of HTTP.
nutso Posted May 31, 2007 Author Posted May 31, 2007 Is it really that simple? Serco don't make any mention of using SSL with eportal and it seems like such a basic security thing that it should be covered. The IIS solution just seemed too basic somehow and the total lack of mention of it on Serco's part made me question whether there was some problem with using that. Is there any word on how secure communications between CMIS Admin and the SQL server are? If Force Protocol Encryption is enabled on SQL Server 2000, is this sufficient?
kylewilliamson Posted May 31, 2007 Posted May 31, 2007 use IIS Securely I believe that's an oxymoron. However, yes, the answer is to use HTTPS instead of HTTP. touche. I believe also you can configure tomcat to operate securely. Please do not ask how to do this.
k-strider Posted May 31, 2007 Posted May 31, 2007 i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work.
plock Posted October 30, 2007 Posted October 30, 2007 i need to test this too, we do use the IIS pass through for external, and internal acces at present. i just need to try it over ssl... but i dont see why it shouldn't work. Any luck? I have installed the SSL Certificate - however I get that the secured page contains secure and non-secure items! Not ideal!
Michael Posted April 7, 2021 Posted April 7, 2021 I'm going to resurrect this discussion, as I have a similar question (now in 2021). Supporting a school using Facility and ePortal, with ePortal operating over SSL and Windows Server up-to-date. As far as I can tell however, there's no password complexity enforcement options in ePortal and the directory structure refers to Tomcat and IIS. IIS security is obviously going to be covered under Windows, but what about Tomcat? I know little about it, but I can see tomcat8.exe is the main executable that ePortal utilises, with the latest version (looking online) being Tomcat 10. The timestamp of tomcat8.exe is September 2019. What do you do if you run a similar setup? And is this at any particular risk? All the relevant firewall rules are in place, yet ePortal (per design) is still accessible over HTTPS publicly.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now