MACROMEDIA BREEZE-SECURITY Manual Download Page 10

10

Security and Macromedia Breeze

Best Practices 

Below is a checklist of best practices that will assist you in securing Breeze.

Firewall Your Servers

  It is highly recommended to place Macromedia Breeze behind a 

firewall, especially if you are intending for Breeze to be used on the Internet. By not placing 
Breeze behind a firewall, you are leaving your server open for attacks. Even worse, your 
sensitive information is unsecured and open for theft. All servers should sit behind a firewall, 
which includes Breeze Application servers, Breeze Live servers and the database server.

Run the Bare Minimum of Services

  You should only run the bare minimum services you 

need for Breeze. This means that you should not run applications like a domain controller, a 
web server or an FTP server on the same computer as Breeze. By reducing the number of 
applications and services running on the computer hosting Breeze, you can minimize the 
chances that an exploit in another application can be used to compromise your Breeze server.

Perform OS Security Updates

  On Windows and other platforms, customers need to check 

for platform security holes and apply required patches. Some of these issues are eliminated by a 
good firewall. In general we recommend customers keep their Breeze systems patched with all 
security updates approved by Microsoft or other appropriate platform vendor. 

Perform Database Security Updates

  Since your database may be another targeted 

component of the Breeze solution, you need to check for database server security holes and 
apply required patches. Like the operating system, some of these issues are eliminated by a 
good firewall, but you should also keep up to date with the latest patches.

Physical Security

  Customers who store sensitive information on their servers should be 

aware of the physical security of their systems. Breeze relies on the safety of the host system 
against intruders, so servers should be kept secured where private and confidential data is at 
risk. Breeze is designed to take advantage of native environmental features like file system 
encryption where available if configured by the user. 

Use Strong Passwords

  Breeze users are protected by passwords. We recommend that users, 

and particularly administrators, choose strong passwords to keep their data safe. Breeze 
enterprise installations often utilize external databases which may also require strong 
password protection. 

Perform Security Audits

  We recommend users audit their systems periodically to ensure 

that all security features installed by the user are still operating as expected. For example, 
firewalls are easily tested using a port scanner for validation. Ongoing security checks help 
guard against user error that can lead to misconfiguration over time. 

Summary of Contents for BREEZE-SECURITY

Page 1: ...Security and Macromedia Breeze ...

Page 2: ...ictions including internationally Other product names logos designs titles words or phrases mentioned within this publication may be trademarks servicemarks or tradenames of Macromedia Inc or other entities and may be registered in certain jurisdictions including internationally This guide contains links to third party websites that are not under the control of Macromedia and Macromedia is not res...

Page 3: ... Overview 5 Security Levels 6 Infrastructure Security 6 Solutions for a Secure Infrastructure 7 Application Level Security 9 Physical Security 9 Best Practices 10 Recommended Security Resources and References 11 ...

Page 4: ...4 Contents ...

Page 5: ...anywhere anytime By its very nature any application that is run over a network especially the Internet has security risks associated with it Macromedia Breeze is no different However these security threats can be minimized if careful consideration is taken towards implementing a security design for Macromedia Breeze There are three levels of security that should be considered for Macromedia Breeze...

Page 6: ...channels for private communication These ports must be protected from outside users Breeze s design requires the environment to provide security for these communications It is highly recommended that sensitive ports should be placed behind a firewall that separates them from non trusted machines Below is a list of ports that are used by Macromedia Inbound ports from the internet 80 443 1935 Outbou...

Page 7: ...cure location Databases should be installed in the secure zone of your corporate intranet and never directly connected to the Internet Back up all data regularly and store copies in a secure off site location The Microsoft security web site contains information that applies to both securing SQL Server 2000 and the Breeze built in database www microsoft com sql techinfo administration 2000 security...

Page 8: ...tion Guide 4 Verify that Breeze is working After installing Breeze you should verify that Breeze is working properly both from the Internet and from your local network See the Breeze Installation Guide for more information 5 Test your firewall Now that you have your firewall installed and configured you should verify that your firewall is working correctly Test the firewall by attempting to use th...

Page 9: ...enrollee notifications and setting up course reminders They can also view content and course reports Meeting Administrators Members of the Meeting Administrators are able to perform all functions associated with creating meetings including setting up a meeting inviting participants sending invitations and viewing reports In addition to adding users to groups to grant them rights to use features in...

Page 10: ...atched with all security updates approved by Microsoft or other appropriate platform vendor Perform Database Security Updates Since your database may be another targeted component of the Breeze solution you need to check for database server security holes and apply required patches Like the operating system some of these issues are eliminated by a good firewall but you should also keep up to date ...

Page 11: ... information on this site also applies to the Breeze built in database engine Tools Freeware NMap www insecure org nmap index html A powerful port scanning program that tells you what ports a system is listening on It is freely available under the GNU Public License GPL Note Please note that the effectiveness of any security measure is determined by various factors including but not limited to the...

Page 12: ...12 Security and Macromedia Breeze ...

Reviews: