Managing an iFolder Web Access Server
159
no
vd
ocx
(e
n)
13
Ma
y 20
09
/>
If the
webaccess/Web.config
values exceed the values in
web/web.config
for the enterprise
server, you must also increase the sizes of runtime parameters in that file.
13.5 Securing Web Access Server
Communications
This section describes how to configure SSL traffic between the iFolder Web Access server and
other components. HTTPS (SSL) encrypts information transmitted over shared IP networks and the
Internet. It helps protect your sensitive information from data interception or tampering.
Section 13.5.1, “Using SSL for Secure Communications,” on page 159
Section 13.5.2, “Configuring the SSL Cipher Suites for the Apache Server,” on page 159
Section 13.5.3, “Configuring the Web Access Server for SSL Communications with the
Enterprise Server,” on page 160
Section 13.5.4, “Configuring the Web Access Server for SSL Communications with Web
Browsers,” on page 161
Section 13.5.5, “Configuring an SSL Certificate for the Web Access Server,” on page 161
For information on how to configure SSL traffic on the iFolder enterprise server, see
Section 9.11,
“Securing Enterprise Server Communications,” on page 117
.
13.5.1 Using SSL for Secure Communications
In a default deployment, the iFolder 3.7 Web Access server uses SSL 3.0 for secure communications
between components as shown in the following table.
For more information about SSL 3.0, see
Section 9.11.1, “Using SSL for Secure Communications,”
on page 118
.
13.5.2 Configuring the SSL Cipher Suites for the Apache
Server
To restrict connections to SSL 3.0 and to ensure strong encryption, we strongly recommend the
following configuration for the Apache server’s SSL cipher suite settings.
Use only High and Medium security cipher suites, such as RC4 and RSA.
Remove from consideration any ciphers that do not authenticate, such as Anonymous Diffie-
Hellman (ADH) ciphers.
Use SSL 3.0, and disable SSL 2.0.
Disable the Low, Export, and Null cipher suites.
iFolder Component
Enterprise Server
LDAP Server
Client
Web Browser
Web Access Server
Yes
Yes
No
Yes
Содержание IFOLDER 3.7 - SECURITY ADMINISTRATION
Страница 12: ...12 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 24: ...24 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 38: ...38 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 98: ...98 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 100: ...100 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 102: ...102 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 162: ...162 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 168: ...168 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 172: ...172 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 182: ...182 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 184: ...184 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 196: ...196 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 202: ...202 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Страница 216: ...216 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...