background image

Security Best Practices for the iFolder Client

3

no

vd

ocx (

E

NU)

  

01

 F

ebr
ua

ry 
200
6

19

3

Security Best Practices for the 
iFolder Client

This section provides specific instructions on how to install, configure, and maintain the iFolder

TM

 

client for Novell

®

 iFolder

®

 3.

x

 in the most secure way possible.

Section 3.1, “Configuring Client-Side Firewalls for iFolder Communications,” on page 19

Section 3.2, “Configuring Client-Side Virus Scanners for iFolder Communications,” on 
page 19

Section 3.3, “Configuring a Web Browser to Use SSL 3.0,” on page 19

3.1  Configuring Client-Side Firewalls for iFolder 

Communications

If users deploy a client-side firewall, they must set the firewall to allow the iFolder client to 
communicate locally (on the same computer) with Mono XSP Server. iFolder communicates to 
Mono

®

 XSP Web services, which communicates, in turn, with the iFolder enterprise server via 

HTTP BASIC or SSL, as governed by the system settings for the iFolder enterprise server. The user 
can allow iFolder to choose a local dynamic port for local iFolder traffic, or configure a local static 
port for iFolder to use for that purpose. For information, see “

Configuring Local Firewall Settings 

for iFolder Traffic

” in the 

iFolder User Guide for Novell iFolder 3.x

.

3.2  Configuring Client-Side Virus Scanners for 

iFolder Communications

Because iFolder is a cross-platform distributed solution, there is a possibility of a virus infection on 
one platform migrating across the iFolder server to other platforms, and vice versa. You should 
enforce client-based virus scanning to prevent viruses from entering the corporate network. 

Scanning the 

..\simias\WorkArea\

 directory for viruses causes problems with 

synchronization if a virus is detected on download. The 

..\simias\WorkArea\

 directory is 

where iFolder stages files for download from the server. Users should set their virus scanners to 
avoid scanning the 

..\simias\WorkArea

 directory. Scanners can detect the virus when iFolder 

moves the infected file from the staging area to the target iFolder. For information, see “

Configuring 

Local Virus Scanner Settings for iFolder Traffic

” in the 

iFolder User Guide for Novell iFolder 3.x

.

3.3  Configuring a Web Browser to Use SSL 3.0

Novell iFolder 3.

x

 servers expect users to connect to the enterprise server account and the Web 

access server with SSL 3.0 connections. Both the client and browser connections use the browser’s 
settings for SSL. If Microsoft* IE is installed on your system, the iFolder client uses those settings 
over any other browser configuration for the client. Make sure the IE browser settings and other 
browsers you use to connect to iFolder servers are configured to use SSL 3.0.

Summary of Contents for iFOLDER 3.x

Page 1: ...Novell w w w n o v e l l c o m novdocx ENU 01 February 2006 Novell iFolder 3 x Security Administrator Guide iFolder 3 x A u g u s t 1 5 2 0 0 6 S E C U R I T Y A D M I N I S T R A T O R G U I D E...

Page 2: ...export or import deliverables You agree not to export or re export to entities on the current U S export exclusion lists or to any embargoed or terrorist countries as specified in the U S export laws...

Page 3: ...ademarks For a list of Novell trademarks see the Novell Trademark and Service Mark list http www novell com company legal trademarks tmlist html Third Party Materials All third party trademarks are th...

Page 4: ...novdocx ENU 01 February 2006...

Page 5: ...Securing the iFolder Proxy User Password 14 2 13 Using Synchronize Now to Remove Users Effective Immediately 15 2 14 Controlling Access to the iFolder Data Store 15 2 15 Controlling Access to the iFol...

Page 6: ...6 Novell iFolder 3 x Security Administrator Guide novdocx ENU 01 February 2006...

Page 7: ...version of the Novell iFolder 3 x Security Administrator Guide visit the Novell iFolder 3 x documentation Web site http www novell com documentation ifolder3 index html For emerging issues with Novel...

Page 8: ...n a cross reference path A trademark symbol TM etc denotes a Novell trademark An asterisk denotes a third party trademark When a single pathname can be written with a backslash for some platforms or a...

Page 9: ...ecure SSL for server to LDAP server communications iManager Novell iFolder 3 System LDAP Settings Port Is Secure Select Yes to enable SSL deselect Yes No to disable SSL Yes SSL enabled Yes SSL enabled...

Page 10: ...iFolder Admin users User specified None Users with limited administrator rights such as for a specific iFolder server Port for iManager to server communications iManager Novell iFolder 3 select any ta...

Page 11: ...page 14 Section 2 11 Ensuring Privilege Separation for the iFolder Proxy User on page 14 Section 2 12 Securing the iFolder Proxy User Password on page 14 Section 2 13 Using Synchronize Now to Remove U...

Page 12: ...tion 4 3 Securing Communications with a VPN If SSL Is Disabled on page 21 2 4 Using SSL for Enterprise Server Web Access Server Communications By default the iFolder enterprise server is configured to...

Page 13: ...Medium security cipher suites such as RC4 and RSA Remove from consideration any ciphers that do not authenticate such as Anonymous Diffie Hellman ADH ciphers Disable the Low Export and Null cipher sui...

Page 14: ...server after configuring the iFolder enterprise server and before the iFolder service is started for the first time The restart of Apache is forced at the end of the configuration process which starts...

Page 15: ...list is periodically updated based on the LDAP synchronization interval Whenever you remove users from a LDAP Search DN or remove contexts from the Search DN list you should synchronize the list imme...

Page 16: ...Virus Scanner Settings for iFolder Traffic in the iFolder User Guide for Novell iFolder 3 x 2 19 Backing Up the iFolder Server Backup of iFolder user data and configuration data should be performed r...

Page 17: ...Security Best Practices for Novell iFolder 3 x 17 novdocx ENU 01 February 2006 conditions and are handled by a company whose reputation rests on its ability to handle your media properly...

Page 18: ...18 Novell iFolder 3 x Security Administrator Guide novdocx ENU 01 February 2006...

Page 19: ...older 3 x 3 2 Configuring Client Side Virus Scanners for iFolder Communications Because iFolder is a cross platform distributed solution there is a possibility of a virus infection on one platform mig...

Page 20: ...20 Novell iFolder 3 x Security Administrator Guide novdocx ENU 01 February 2006...

Page 21: ...uder 4 3 Securing Communications with a VPN If SSL Is Disabled We recommend configuring Novell iFolder 3 x to use SSL HTTPS connections for all data exchanges between its different components because...

Page 22: ...sing MAC address filtering is practical for small networks but it is a time consuming administrative effort for large networks Use an anonymous Service Set Identifier SSID by turning off the SSID broa...

Page 23: ...Within a dated entry changes are grouped and sequenced according to where they appear in the document itself Each change entry provides a link to the related topic and a brief description of the chang...

Reviews: