• No results found

Securing ArcGIS Server Services: First Steps

N/A
N/A
Protected

Academic year: 2021

Share "Securing ArcGIS Server Services: First Steps"

Copied!
37
0
0

Loading.... (view fulltext now)

Full text

(1)

Securing ArcGIS Server Services:

First Steps

Michael Sarhan – Esri

[email protected]

February 9–10, 2015 | Washington, DC

(2)

Agenda

Review

Basic Security Workflow

ArcGIS Server Roles and Identity Stores

Authentication

Authorization: Securing Web Services

Encryption and SSL

(3)

Review: ArcGIS for Server Architecture

ArcGIS account (OS level)

ArcGIS Server site

GIS Server

Service directories

Manager

Server Administrator API

http://6080 Primary Site Administrator (PSA) Data Server directories Configuration store

(4)

Simple Security Workflow

Set up Authentication Method Authorize Access to Services Manage Encryption Set up Users and

(5)

User → Valid login to access

Role → Grouping of users

- 3 types

1. Administrators – Full admin control

2. Publishers – Publish web services

3. Users – View web services

Identity store → Defines your users and roles

- User store + Role store

ArcGIS for Server Access

Per

mission

s

(6)

Identity store

Where are your users coming from?

- Determines which type of identity store you should use

Intranet → Windows Active Directory or LDAPInternet → Built-in or custom

ArcGIS for Server: User considerations

Organizations IT network

External

Internal

(7)

How much control do I have on my ArcGIS Server site?

- Managed by me, within my Dept? or - Managed by my organization’s IT Dept

May affect where you define your roles

ArcGIS for Server: Role considerations

Built-in identity store Enterprise identity store LDAP A

(8)

Identity Store → Defines your users and roles3 different options

1. Built-in (default)

2. Register with an enterprise identity store - Windows Active Directory

- LDAP

3. “Mixed mode”

- Users from enterprise identity store - Roles from built-in store

ArcGIS for Server: Identity Store

Identity store

A

(9)

Show users and roles Server and Portal

Authentication

Demo

(10)
(11)

Simple Security Workflow

Set up Authentication Method Authorize Access to Services Manage Encryption Set up Users and

(12)

Authentication → Check and verify user identity2 options

1. GIS Tier

- Uses tokens to authenticate

2. Web Tier

- Uses HTTP authentication

- E.g., Basic, Digest, Integrated Windows, Client certificates (PKI), and Custom

Authentication Tier/Method

A

(13)

Enables ArcGIS Server to work with 3rd party web server - E.g., IIS, Web Sphere, etc.

Leverage web server features

Provides more flexibility to control site access

Conceptually like a reverse proxy

ArcGIS for Server – Web Adaptor

GIS Server Web Server Web Adaptor http://80 http://6080 GIS site

(14)

ArcGIS Server site

+ Identity store

+ 3rd party web server

+ Web Adaptor

Review 2: ArcGIS Server Architecture

Other components of a Server site

GIS Server Server directories Configuration store A Identity store Web Server Web Adaptor

(15)

GIS Server checks credentials

Token → Unique identifier sent from Server to client to identify an interaction session

GIS Tier Authentication

GIS Server Server directories Configuration store Identity store Web Server Web Adaptor 1. Credentials sent

to GIS server 3. Esri token

sent back to client

Client

2. Checked with ID store

A

(16)

Web server checks credentials

Must use Web Adaptor

HTTP authentication

Web Tier Authentication

GIS Server Server directories Configuration store Web Server Web Adaptor Identity store 3. Role sent to GIS server 1. Credentials

checked with ID store

2. Role sent to Web Adaptor

A

Client

(17)

GIS Tier vs. Web Tier Authentication

GIS Tier / Token Web Tier / HTTP Auth

Default Yes No

Public / anonymous possible

Yes Yes

Clients Supporting Esri All, including OGC

Requirements Enable SSL Web Adaptor(s) required

Basic – require SSL Digest – special setup IWA – Windows only

(18)

Show IIS configuration of Web Adaptor

Show how to set-up authentication in wizard

Authentication

Demo

(19)
(20)
(21)

Simple Security Workflow

Set up Authentication Method Authorize Access to Services Manage Encryption Set up Users and

(22)
(23)

Set permissions for roles on folders and services

- Administrators/Publishers grant permissions

All new services are public by default

- Anonymous access

Securing GIS Web Services

(24)

Show securing a web service

Show accessing a secured service in a client application

Authorization

Demo

(25)
(26)

Simple Security Workflow

Set up Authentication Method Authorize Access to Services Manage Encryption Set up Users and

(27)
(28)

Should you be using HTTPS?

Yes!

Hypertext Transfer Protocol Secure (HTTPS)

(29)
(30)

Review

Basic Security Workflow

ArcGIS Server Roles and Identity Stores

Authentication

Authorization: Securing Web Services

Encryption and SSL

Summary

(31)

Other Security Sessions

ArcGIS Security Authorization Advancements

- Monday, February, 9, 3:00 – 4:00 pm, Room 103A - Tuesday, February, 10, 11:00 – 12:00 pm, Room 103A

Securing Your ArcGIS Server Services: Advanced

- Tuesday February ,10 5:15 – 6:15 pm, Room 101

Securing Your ArcGIS Server Services: First Steps

- Monday February, 9, 1:45 – 2:45 pm, Room 102A

(32)
(33)

Don’t forget to complete

a session evaluation form!

February 9–10, 2015 | Washington, DC

(34)

Print your customized

Certificate of Attendance!

Printing stations located on L St. Bridge, next to registration

February 9–10, 2015 | Washington, DC

(35)

GIS Solutions EXPO, Hall D

Monday, 12:30pm – 6:30pm Tuesday, 10:45 AM–4:00 PM

• Exhibitors

• Hands-On Learning Lab

• Technical & Extended Support

• Demo Theater

• Esri Showcase

February 9–10, 2015 | Washington, DC

(36)

Networking Reception:

National Museum of American History

Tuesday, 6:30 PM–9:30 PM

Bus Pickup located on L Street

February 9–10, 2015 | Washington, DC

(37)

Interested in diving

deeper into Esri technology?

Add a day to your Fed GIS experience and register to attend the Esri DevSummit Washington DC. Stop by the registration counter to sign up.

February 9–10, 2015 | Washington, DC

References

Related documents

In order to set up RSA Key Manager to handle encryption keys for PowerPath, the RSA Key Manager Security Administrator begins by setting up the authentication credentials for

In terms of security at the stored location itself, Data Electronics have not encountered a security breach since opening the Kilcarbery Park centre in 2001 and this is accredited

It is usually used to read or modify settings of a large set of objects, using IceWarp Server's API to directly access the IceWarp Email Server engine, e.g.. to list what users

After setup, you can use the Server Admin utility to set up replication services, manage Kerberos authentication and password policies, and monitor Open Directory access and

Once the RightFax fax server has received the recipient’s extension information via DTMF tones, it can forward the fax message via email to the recipients email address. Using the

 If you check the Upload Attachments box, but set it for 0 MB, actual attachments will not be uploaded but LINKS WILL be uploaded with email on match, and you will be able to click

Select the billing date for the Express Email Marketing credit you want to use, and then click Activate Account.. The Express Email Marketing End-User License Agreement opens in a

In order to access Tenant Screening Services, first-time users must be set up by their Security Designate.. Once set up, the user will receive a notification that he or she has