<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Securing Services in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services/m-p/432459#M16692</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If using the Web Adaptor is it really necessary to "secure" the published services?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;customer will only consume services via the REST, so in my mind it seems a bit of overkill to secure the published services on top of running the web adaptor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users = Domain A&lt;/P&gt;&lt;P&gt;ESRI = Domain B (this is by design and cannot be moved to Domain A)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;what would be the cleanest way to secure services....if they even nee to be secured at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Sep 2016 16:37:20 GMT</pubDate>
    <dc:creator>DaveTenney</dc:creator>
    <dc:date>2016-09-15T16:37:20Z</dc:date>
    <item>
      <title>Securing Services</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services/m-p/432459#M16692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If using the Web Adaptor is it really necessary to "secure" the published services?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;customer will only consume services via the REST, so in my mind it seems a bit of overkill to secure the published services on top of running the web adaptor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users = Domain A&lt;/P&gt;&lt;P&gt;ESRI = Domain B (this is by design and cannot be moved to Domain A)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;what would be the cleanest way to secure services....if they even nee to be secured at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2016 16:37:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services/m-p/432459#M16692</guid>
      <dc:creator>DaveTenney</dc:creator>
      <dc:date>2016-09-15T16:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services/m-p/432460#M16693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple reasons I want to secure services using ArcGIS Server secure folders (beyond web adaptor) come to mind:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;we don't have the server/network resources to allow other "consumers" to include our REST in their apps., and&lt;/LI&gt;&lt;LI&gt;some variations of our services are public, while others have more fields/data that are for internal use only.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm sure there are other reasons.&amp;nbsp; If all your services are public and you aren't concerned about #1, then you may not need security.&amp;nbsp; However, even if using the web adaptor and you don't openly publish your end point, a couple minutes with Fiddler or other developer tools can usually find this info.&amp;nbsp; However, if you have security (&lt;A class="link-titled" href="http://server.arcgis.com/en/server/latest/administer/linux/configuring-arcgis-server-security.htm" title="http://server.arcgis.com/en/server/latest/administer/linux/configuring-arcgis-server-security.htm"&gt;Configuring ArcGIS Server security—Documentation (10.4) | ArcGIS for Server&lt;/A&gt;&amp;nbsp; ) and a &lt;A href="https://github.com/Esri/resource-proxy"&gt;proxy&lt;/A&gt;, you can prevent others from using the services within their own.&amp;nbsp; Again, that might not be a concern, but something to keep in mind.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to check out &lt;A class="link-titled" href="http://doc.arcgis.com/en/trust/security/security-overview.htm" title="http://doc.arcgis.com/en/trust/security/security-overview.htm"&gt;ArcGIS Security—Trust ArcGIS | ArcGIS&lt;/A&gt; since it has info on security for many of the products/platforms.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, just as a note, make sure your patches are up to date, including the one mentioned here:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://blogs.esri.com/esri/arcgis/2016/05/20/arcgis-server-security-patch-released-2016-u2/" title="https://blogs.esri.com/esri/arcgis/2016/05/20/arcgis-server-security-patch-released-2016-u2/"&gt;ArcGIS Server Security Patch (2016 Update2) | ArcGIS Blog&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2016 17:41:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services/m-p/432460#M16693</guid>
      <dc:creator>RebeccaStrauch__GISP</dc:creator>
      <dc:date>2016-09-15T17:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services/m-p/432461#M16694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if arcgis server services are not secure, one can simply hit up the Specific Port - side stepping&amp;nbsp;the web adaptor and still get access to services.&lt;/P&gt;&lt;P&gt;Once you web tier auth, other than admin / manager, you must go through the web adaptor. or you will get a 403&amp;nbsp;&lt;/P&gt;&lt;P&gt;also handy through the web adaptor is the manager / publisher accounts are auto logged in... no need for Digging up KeePass credentials.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2016 22:32:21 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services/m-p/432461#M16694</guid>
      <dc:creator>MichaelRobb</dc:creator>
      <dc:date>2016-09-19T22:32:21Z</dc:date>
    </item>
  </channel>
</rss>

