<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ArcGIS Server and Portal Security in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-and-portal-security/m-p/419449#M16285</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been thinking and reading a lot about ArcGIS for Server security lately.&amp;nbsp; My current dev server has the web adapter up and running, the rest services directory turned off, and SSL enabled.&amp;nbsp; Currently users connect independently (not through Portal) though Flex Viewer apps and security is handled by domain user at the IIS (Web Tier) Level.&amp;nbsp; Users do not have direct access to the SQL DB, nor can they login through ArcMap (most dont even have it).&amp;nbsp; When installing ArcGIS Portal and Federating the server I seem to have lost all ability to access ArcGIS Manager and now all service securities are run through Portal which seems to not function quite as well as through Manager.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is what security holes am I leaving open?&amp;nbsp; What access point have I left vulnerable?&amp;nbsp; If I mark all services as 'public' and have the rest directory turned off, with no username access to portal, through ArcMap, or though SQL what potential hazards could I be facing?&amp;nbsp; It is also worth mentioning that all of this is only accessible through our internet and will not be on the internet.&amp;nbsp; Another thought...&amp;nbsp; What are your opinions of SSL in an intranet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and I look forward to your responses! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Aug 2015 15:35:53 GMT</pubDate>
    <dc:creator>PhilipSlater</dc:creator>
    <dc:date>2015-08-07T15:35:53Z</dc:date>
    <item>
      <title>ArcGIS Server and Portal Security</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-and-portal-security/m-p/419449#M16285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been thinking and reading a lot about ArcGIS for Server security lately.&amp;nbsp; My current dev server has the web adapter up and running, the rest services directory turned off, and SSL enabled.&amp;nbsp; Currently users connect independently (not through Portal) though Flex Viewer apps and security is handled by domain user at the IIS (Web Tier) Level.&amp;nbsp; Users do not have direct access to the SQL DB, nor can they login through ArcMap (most dont even have it).&amp;nbsp; When installing ArcGIS Portal and Federating the server I seem to have lost all ability to access ArcGIS Manager and now all service securities are run through Portal which seems to not function quite as well as through Manager.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is what security holes am I leaving open?&amp;nbsp; What access point have I left vulnerable?&amp;nbsp; If I mark all services as 'public' and have the rest directory turned off, with no username access to portal, through ArcMap, or though SQL what potential hazards could I be facing?&amp;nbsp; It is also worth mentioning that all of this is only accessible through our internet and will not be on the internet.&amp;nbsp; Another thought...&amp;nbsp; What are your opinions of SSL in an intranet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and I look forward to your responses! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Aug 2015 15:35:53 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-server-and-portal-security/m-p/419449#M16285</guid>
      <dc:creator>PhilipSlater</dc:creator>
      <dc:date>2015-08-07T15:35:53Z</dc:date>
    </item>
  </channel>
</rss>

