
Managing an iFolder Web Access Server
159
no
vd
ocx
(e
n)
13
Ma
y 20
09
/>
If the
webaccess/Web.config
values exceed the values in
web/web.config
for the enterprise
server, you must also increase the sizes of runtime parameters in that file.
13.5 Securing Web Access Server
Communications
This section describes how to configure SSL traffic between the iFolder Web Access server and
other components. HTTPS (SSL) encrypts information transmitted over shared IP networks and the
Internet. It helps protect your sensitive information from data interception or tampering.
Section 13.5.1, “Using SSL for Secure Communications,” on page 159
Section 13.5.2, “Configuring the SSL Cipher Suites for the Apache Server,” on page 159
Section 13.5.3, “Configuring the Web Access Server for SSL Communications with the
Enterprise Server,” on page 160
Section 13.5.4, “Configuring the Web Access Server for SSL Communications with Web
Browsers,” on page 161
Section 13.5.5, “Configuring an SSL Certificate for the Web Access Server,” on page 161
For information on how to configure SSL traffic on the iFolder enterprise server, see
Section 9.11,
“Securing Enterprise Server Communications,” on page 117
.
13.5.1 Using SSL for Secure Communications
In a default deployment, the iFolder 3.7 Web Access server uses SSL 3.0 for secure communications
between components as shown in the following table.
For more information about SSL 3.0, see
Section 9.11.1, “Using SSL for Secure Communications,”
on page 118
.
13.5.2 Configuring the SSL Cipher Suites for the Apache
Server
To restrict connections to SSL 3.0 and to ensure strong encryption, we strongly recommend the
following configuration for the Apache server’s SSL cipher suite settings.
Use only High and Medium security cipher suites, such as RC4 and RSA.
Remove from consideration any ciphers that do not authenticate, such as Anonymous Diffie-
Hellman (ADH) ciphers.
Use SSL 3.0, and disable SSL 2.0.
Disable the Low, Export, and Null cipher suites.
iFolder Component
Enterprise Server
LDAP Server
Client
Web Browser
Web Access Server
Yes
Yes
No
Yes
Summary of Contents for IFOLDER 3.7 - SECURITY ADMINISTRATION
Page 12: ...12 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 24: ...24 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 38: ...38 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 98: ...98 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 100: ...100 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 102: ...102 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 162: ...162 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 168: ...168 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 172: ...172 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 182: ...182 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 184: ...184 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 196: ...196 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 202: ...202 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 216: ...216 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...