<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Update Token Service Url in Server Info in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367837#M14230</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Note that the above doc is dated - likely for 10.3. At 10.4+, HTTP and HTTPS are enabled by default.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Mar 2018 18:54:34 GMT</pubDate>
    <dc:creator>RandallWilliams</dc:creator>
    <dc:date>2018-03-30T18:54:34Z</dc:date>
    <item>
      <title>Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367830#M14223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I've upgraded ArcGIS Server 10.5.1 to 10.6 and it appears that token service Url switched from http to https...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.esri.com/legacyfs/online/399821_pastedImage_110.png" style="width: 620px; height: 414px;" /&gt;&lt;/P&gt;&lt;P&gt;I don't find the way to&amp;nbsp;restore to http: I have updatedvia rest admin&amp;nbsp; the json to Enable Token&amp;nbsp;in http (see link&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A class="link-titled" href="http://enterprise.arcgis.com/en/server/latest/administer/windows/enable-token-acquisition-through-an-http-get-request.htm" title="http://enterprise.arcgis.com/en/server/latest/administer/windows/enable-token-acquisition-through-an-http-get-request.htm"&gt;Enable token acquisition through an HTTP GET request—ArcGIS Server Administration (Windows) | ArcGIS Enterprise&lt;/A&gt;&amp;nbsp;) restarted services and server but with no results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every help will be appreciated&lt;/P&gt;&lt;P&gt;Damiano&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 13:24:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367830#M14223</guid>
      <dc:creator>DamianoMontrasio</dc:creator>
      <dc:date>2018-03-26T13:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367831#M14224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You really shouldn't be generating tokens over http, as that sends your credentials over plain-text and aren't encrypted. Is there a reason you want that URL to be http?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 16:50:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367831#M14224</guid>
      <dc:creator>JonathanQuinn</dc:creator>
      <dc:date>2018-03-29T16:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367832#M14225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To second what Jonathan said, why would you want tokens over http?&amp;nbsp;Plain-text defeats the purpose of securing the service at all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 18:41:22 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367832#M14225</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2018-03-29T18:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367833#M14226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A plain-text token request is a &lt;EM&gt;non sequitor&lt;/EM&gt;. There was a bug in ArcGIS pre-10.2.2 which&amp;nbsp;enabled&amp;nbsp;it by default, but&amp;nbsp;this has always been inherently insecure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;A href="http://enterprise.arcgis.com/en/server/latest/administer/linux/enable-token-acquisition-through-an-http-get-request.htm"&gt;documentation&lt;/A&gt; indicates that is may be possible, but it's still an awful idea to allow such access:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;DIV class=""&gt;&lt;H5 class=""&gt;Caution:&lt;/H5&gt;&lt;P&gt;Although using a GET request is a convenient method of acquiring a token, a user's credentials are provided as part of the URL and may be stored in browser history or in network components. It's recommended that you update your applications so that tokens are not acquired through a GET request.&lt;/P&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- V&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 19:01:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367833#M14226</guid>
      <dc:creator>VinceAngelo</dc:creator>
      <dc:date>2018-03-29T19:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367834#M14227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answers!&lt;/P&gt;&lt;P&gt;The scenario is that a server application installed on the same machine as the ArcGIS Server and therefore the risks are lower. In any case, waiting to enable the https I would like to understand if the procedure described here&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.esri.com/external-link.jspa?url=http%3A%2F%2Fenterprise.arcgis.com%2Fen%2Fserver%2Flatest%2Fadminister%2Fwindows%2Fenable-token-acquisition-through-an-http-get-request.htm" rel="nofollow" style="color: #000000; background-color: #ffffff; border: 0px; text-decoration: underline; padding: 0px calc(12px + 0.35ex) 0px 0px;" target="_blank"&gt;Enable token acquisition through an HTTP GET request—ArcGIS Server Administration (Windows) | ArcGIS Enterprise&lt;/A&gt; is still valid for 10.6 installation.&lt;/P&gt;&lt;P&gt;I have not found other ways to bring the Token Service URL back into Http.&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;Damiano&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 08:27:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367834#M14227</guid>
      <dc:creator>DamianoMontrasio</dc:creator>
      <dc:date>2018-03-30T08:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367835#M14228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you&lt;EM&gt; tried&lt;/EM&gt; the documented procedure?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Asking folks who are are&lt;STRONG&gt; strongly recommending&lt;/STRONG&gt; you&lt;EM&gt;&lt;STRONG&gt; don't use this feature&lt;/STRONG&gt;&lt;/EM&gt; to test it for you isn't likely to bear fruit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- V&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 18:40:32 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367835#M14228</guid>
      <dc:creator>VinceAngelo</dc:creator>
      <dc:date>2018-03-30T18:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367836#M14229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FAQ: How does ArcGIS Server token authentication work?&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.esri.com/en/technical-article/000011851"&gt;https://support.esri.com/en/technical-article/000011851&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All Esri clients and APIs send usernames and passwords over https (encrypted) if it is enabled. If it's not enabled, then usernames/passwords may be sent as clear text over the network. &lt;STRONG&gt;To prevent this, it is strongly recommended that https be enabled in ArcGIS Server when using GIS-tier authentication&lt;/STRONG&gt;. It is not enabled by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tokens can be acquired through either an HTTP GET or an HTTP POST. Using a POST is always more secure. GET requests may leave usernames/passwords in network equipment history and in the browser history. Esri APIs and products use POST when acquiring tokens. However for the convenience of people writing scripts, tokens can be acquired via GET requests. &lt;STRONG&gt;Esri recommends against obtaining tokens via GET requests in secure environments&lt;/STRONG&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 18:52:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367836#M14229</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2018-03-30T18:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Update Token Service Url in Server Info</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367837#M14230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Note that the above doc is dated - likely for 10.3. At 10.4+, HTTP and HTTPS are enabled by default.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 18:54:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/update-token-service-url-in-server-info/m-p/367837#M14230</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2018-03-30T18:54:34Z</dc:date>
    </item>
  </channel>
</rss>

