<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use reverse proxy with secured service on 10.4 in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427276#M16496</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot, that solved my issue with the wrong Url in the GetTokenServiceURLResponse and in the WFS Capabilities file!&lt;/P&gt;&lt;P&gt;I can not use both MapService and WFSService in QGIS with Basic Authentication, only ArcMap / ArcCatalog are noth happy with it. When tracint the http requests I can now see that GetTokenServiceURLResponse returns the correct url to the token service:&lt;/P&gt;&lt;P&gt;&lt;A class="jivelink11" href="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/" title="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/"&gt;https://&lt;/A&gt;&lt;A href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2F" rel="nofollow" target="_blank"&gt;/&lt;/A&gt;&lt;A class="jivelink11" href="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/" title="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/"&gt;&lt;SPAN&gt;&amp;lt;external url to gis server&amp;gt;/&amp;lt;web adaptor name&amp;gt;&lt;/SPAN&gt;/tokens/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But next it does a POST call to this Url and I get&lt;/P&gt;&lt;P&gt;{"error":{"code":401,"message":"You are not authorized to access this information","details":"Invalid credentials"}}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is basic authentication not supported with ArcCatalog?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bye, Nicole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Aug 2019 14:13:58 GMT</pubDate>
    <dc:creator>NicoleSulzberger</dc:creator>
    <dc:date>2019-08-09T14:13:58Z</dc:date>
    <item>
      <title>Use reverse proxy with secured service on 10.4</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427274#M16494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using a reverse proxy with ArcGIS Server 10.4. and a WebAdaptor.&lt;/P&gt;&lt;P&gt;The Proxy server sets the X-Forwarded Host, and we set the WebContextURL in the system properties. With this configuration, access to our MapService&amp;nbsp;over the REST interface works well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"WebContextURL": "https://&amp;lt;external url to gis server&amp;gt;/&amp;lt;web adaptor name&amp;gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when I try to access these services with ArcMap (SOAP interface), ArcMap cannot login. In the response&amp;nbsp;GetTokenServiceURLResponse of the service I can see that the&amp;nbsp;TokenServiceURL property is wrong:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://https/arcgispublic/tokens/" title="https://https/arcgispublic/tokens/"&gt;https://https/&amp;lt;web adaptor name&amp;gt;/tokens/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;?xml version="1.0" encoding="utf-8" ?&amp;gt;&amp;lt;soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:tns="http://www.esri.com/schemas/ArcGIS/10.4"&amp;gt;&amp;lt;soap:Body&amp;gt;&amp;lt;tns:GetTokenServiceURLResponse&amp;gt;&lt;BR /&gt;&amp;lt;TokenServiceURL&amp;gt;&lt;A href="https://https/arcgispublic/tokens/" style="color: #2989c5; text-decoration: none;" title="https://https/arcgispublic/tokens/"&gt;https://https/&amp;lt;web adaptor name&amp;gt;/tokens/&lt;/A&gt;&amp;lt;/TokenServiceURL&amp;gt;&amp;lt;/tns:GetTokenServiceURLResponse&amp;gt;&amp;lt;/soap:Body&amp;gt;&amp;lt;/soap:Envelope&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I check the capabilities file of the WFS interface, I can see the same error in the url:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="" style="color: #000000; font-size: 13px;"&gt;&lt;SPAN class=""&gt;&amp;lt;ows:Operation&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;name="GetCapabilities"&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" style="color: #000000; font-size: 13px; margin-left: 1em;"&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class="" style="background: url(&amp;quot; margin-left: -10px;"&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;lt;ows:DCP&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" style="margin-left: 1em;"&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class="" style="background: url(&amp;quot; margin-left: -10px;"&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;lt;ows:HTTP&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="" style="margin-left: 1em;"&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&amp;lt;ows:Get&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;xlink:href&lt;/SPAN&gt;="&lt;SPAN class=""&gt;https://https:/&lt;A href="https://https/arcgispublic/tokens/" style="color: #2989c5; text-decoration: none;" title="https://https/arcgispublic/tokens/"&gt;&amp;lt;web adaptor name&amp;gt;&lt;/A&gt;/services/public/&amp;lt;ServiceName&amp;gt;/MapServer/WFSServer?&lt;/SPAN&gt;"&lt;/SPAN&gt;/&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&amp;lt;ows:Post&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;xlink:href&lt;/SPAN&gt;="&lt;SPAN class=""&gt;https://https:/&lt;A href="https://https/arcgispublic/tokens/" style="color: #2989c5; text-decoration: none;" title="https://https/arcgispublic/tokens/"&gt;&amp;lt;web adaptor name&amp;gt;&lt;/A&gt;/services/public/&lt;SPAN&gt;&amp;lt;ServiceName&amp;gt;&lt;/SPAN&gt;/MapServer/WFSServer&lt;/SPAN&gt;"&lt;/SPAN&gt;/&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&amp;lt;/ows:HTTP&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&amp;lt;/ows:DCP&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN class=""&gt;I can fix the capabilities file with an external capabilities file if there is no other solution. But the problem with accessing protected services wont go away with that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Without the&amp;nbsp;&lt;SPAN style="color: #3d3d3d;"&gt;X-Forwarded Host setting the REST interface did not work either, so I think this setting is fine like it is.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;bye, Nicole&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2019 08:37:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427274#M16494</guid>
      <dc:creator>NicoleSulzberger</dc:creator>
      <dc:date>2019-08-06T08:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Use reverse proxy with secured service on 10.4</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427275#M16495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicole,&lt;/P&gt;&lt;P&gt;I would double-check the "X-Forwarded-Host" header being sent by your reverse proxy.&amp;nbsp; That should just be the&amp;nbsp;fully-qualified domain name of your web server (ex reverseproxy.domain.com).&amp;nbsp; If that header includes the protocol "https://" as well, it won't work and would produce token service urls and GetCapabilities files similar to what you are seeing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2019 17:01:16 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427275#M16495</guid>
      <dc:creator>JeffSmith</dc:creator>
      <dc:date>2019-08-06T17:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Use reverse proxy with secured service on 10.4</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427276#M16496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot, that solved my issue with the wrong Url in the GetTokenServiceURLResponse and in the WFS Capabilities file!&lt;/P&gt;&lt;P&gt;I can not use both MapService and WFSService in QGIS with Basic Authentication, only ArcMap / ArcCatalog are noth happy with it. When tracint the http requests I can now see that GetTokenServiceURLResponse returns the correct url to the token service:&lt;/P&gt;&lt;P&gt;&lt;A class="jivelink11" href="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/" title="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/"&gt;https://&lt;/A&gt;&lt;A href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2F" rel="nofollow" target="_blank"&gt;/&lt;/A&gt;&lt;A class="jivelink11" href="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/" title="https://ws.geodienste-storme-r.bafu.admin.ch/arcgispublic/tokens/&amp;lt;/"&gt;&lt;SPAN&gt;&amp;lt;external url to gis server&amp;gt;/&amp;lt;web adaptor name&amp;gt;&lt;/SPAN&gt;/tokens/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But next it does a POST call to this Url and I get&lt;/P&gt;&lt;P&gt;{"error":{"code":401,"message":"You are not authorized to access this information","details":"Invalid credentials"}}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is basic authentication not supported with ArcCatalog?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bye, Nicole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2019 14:13:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427276#M16496</guid>
      <dc:creator>NicoleSulzberger</dc:creator>
      <dc:date>2019-08-09T14:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Use reverse proxy with secured service on 10.4</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427277#M16497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicole,&lt;/P&gt;&lt;P&gt;Yes, both ArcMap and ArcCatalog should work fine with basic authentication.&amp;nbsp; Is ArcGIS Server configured to expect basic authentication (ie web-tier authentication)?&amp;nbsp; An easy check should be to access the rest/info page:&lt;/P&gt;&lt;P&gt;&lt;A href="https://&amp;lt;external"&gt;https://&lt;/A&gt;externalurl.domain.com/server_wa/rest/info&lt;/P&gt;&lt;P&gt;Under authentication information, one of the parameters is "Is Token Based Security".&amp;nbsp; Is this true or false?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2019 20:27:05 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427277#M16497</guid>
      <dc:creator>JeffSmith</dc:creator>
      <dc:date>2019-08-12T20:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Use reverse proxy with secured service on 10.4</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427278#M16498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for the hint! When checking&amp;nbsp;&lt;A href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2F%3Cexternal" rel="nofollow" style="color: #287433; background-color: #ffffff; border: 0px; text-decoration: none; padding: 0px calc(12px + 0.35ex) 0px 0px;" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN style="background-color: #ffffff;"&gt;externalurl.domain.com/server_wa/rest/info I have seen that token based security was enabled. As I was trying a lot of things on the ArcGIS Server experiencing&amp;nbsp;the issue with basic authentication I have enabled security on the ArcGIS Server "by mistake". We dont need this as all our services are public.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;I have now disabled security again by:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;- Stopping ArcGIS Windows Service&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;- edit&amp;nbsp;.\arcgisserver\config-store\security\security-config.json, set&amp;nbsp;&amp;nbsp;"securityEnabled": false,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;- restart ArcGIS Server Windows services&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;A class="link-titled" href="https://gis.stackexchange.com/questions/62226/problem-to-disable-the-security-in-server-dat-file" title="https://gis.stackexchange.com/questions/62226/problem-to-disable-the-security-in-server-dat-file"&gt;problem to Disable the security in server.dat file - Geographic Information Systems Stack Exchange&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;I guess I could have used the REST interface to do that?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;Now it works as expected. On my web adaptor in IIS I have enabled Windows authentication, so the users are challenged for user name and password, but after logging in they can use all sevices. &lt;IMG src="https://community.esri.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;bye, Nicole&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2019 09:42:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/use-reverse-proxy-with-secured-service-on-10-4/m-p/427278#M16498</guid>
      <dc:creator>NicoleSulzberger</dc:creator>
      <dc:date>2019-08-13T09:42:01Z</dc:date>
    </item>
  </channel>
</rss>

