<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing Services using the Spring Framework on 10.2 in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98648#M3833</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt; At the moment we use ldap to secure our services but our business requirements have us looking for a more robust alternative&lt;/BLOCKQUOTE&gt;&lt;SPAN&gt; Such as both ldap and container managed security?&amp;nbsp; Or..?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;I have tomcat on a redhat server that is currently running the web adaptor&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;May I ask whether you have just looked into applying security constraints in Tomcat to the URLs you want to secure?&amp;nbsp; The security constraint would lookup users/passwords in whichever realm you configure.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would also suggest that if are going to use container managed security or any security that requires a user to login, enable SSL in your container.&amp;nbsp; It's easy to do&amp;nbsp; with a self signed certificate, or you can buy one.&amp;nbsp; I don't know your intended setup though..&amp;nbsp; is this internal only?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Nov 2013 12:18:24 GMT</pubDate>
    <dc:creator>LeoDonahue</dc:creator>
    <dc:date>2013-11-12T12:18:24Z</dc:date>
    <item>
      <title>Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98647#M3832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm currently trying to use the spring security framework in order to provide the authentication and authorization for my organization's arcgis web services.&amp;nbsp; At the moment we use ldap to secure our services but our business requirements have us looking for a more robust alternative. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have tomcat on a redhat server that is currently running the web adaptor as well as a simple spring security project but I'm missing the part where I can make use of spring to secure the webservices.&amp;nbsp; The web adaptor is running at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://" rel="nofollow" target="_blank"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;web server name&amp;gt;/arcgis/rest/services while the spring security is running at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://" rel="nofollow" target="_blank"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;web server name&amp;gt;/sampleSpringSecurity.&amp;nbsp; The spring security does its job just fine for all paths that fall under sampleSpringSecurity, but that does me no good when it comes to securing the web adaptor.&amp;nbsp; I'm experienced with java but my exposure to spring has been limited and my experience with web adaptors is almost nonexistent.&amp;nbsp; Any suggestions would be greatly appreciated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank You,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Nic&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Nov 2013 19:15:13 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98647#M3832</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2013-11-09T19:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98648#M3833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt; At the moment we use ldap to secure our services but our business requirements have us looking for a more robust alternative&lt;/BLOCKQUOTE&gt;&lt;SPAN&gt; Such as both ldap and container managed security?&amp;nbsp; Or..?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;I have tomcat on a redhat server that is currently running the web adaptor&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;May I ask whether you have just looked into applying security constraints in Tomcat to the URLs you want to secure?&amp;nbsp; The security constraint would lookup users/passwords in whichever realm you configure.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would also suggest that if are going to use container managed security or any security that requires a user to login, enable SSL in your container.&amp;nbsp; It's easy to do&amp;nbsp; with a self signed certificate, or you can buy one.&amp;nbsp; I don't know your intended setup though..&amp;nbsp; is this internal only?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 12:18:24 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98648#M3833</guid>
      <dc:creator>LeoDonahue</dc:creator>
      <dc:date>2013-11-12T12:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98649#M3834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Such as both ldap and container managed security?&amp;nbsp; Or..?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;May I ask whether you have just looked into applying security constraints in Tomcat to the URLs you want to secure?&amp;nbsp; The security constraint would look up users/passwords in whichever realm you configure.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;I would also suggest that if are going to use container managed security or any security that requires a user to login, enable SSL in your container.&amp;nbsp; It's easy to do&amp;nbsp; with a self signed certificate, or you can buy one.&amp;nbsp; I don't know your intended setup though..&amp;nbsp; is this internal only?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for the reply!&amp;nbsp; I'll start out with container managed security.&amp;nbsp; Some of the execs would like to keep their current login information so we might need to add in our ldap configuration at some point but that's for a later date.&amp;nbsp; SSL is definitely a must.&amp;nbsp; I'm just waiting on our IT group to buy the certificates.&amp;nbsp; Ultimately the project will be used by users around the world.&amp;nbsp; I'll have to look into the tomcat security constraints.&amp;nbsp; There's a good chance I'll eventually want to restrict access to methods as well as URLs, which spring has the capability to do.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Over the last few days I've been trying to figure out the best way of securing the services and the two ideas I've come up with are (in order of preference):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;OL&gt;&lt;BR /&gt;&lt;LI&gt;Add the spring configuration directly to the web adaptor war file (arcgis.war) using Maven's &lt;A href="http://maven.apache.org/plugins/maven-war-plugin/overlays.html"&gt;overlay&lt;/A&gt;.&amp;nbsp; Overlay just saves me the trouble of manually adding the spring security project to the war file.&amp;nbsp; I tried the proof of concept yesterday and it worked beautifully.&amp;nbsp; The proof of concept uses the example project, chapter03.06-calendar from the book "Spring Security 3.1".&amp;nbsp; They provided an instant database setup using H2, but once everything was working I tweaked the datasource to use our sql server.&amp;nbsp; Ultimately I'd like to use spring CAS.&lt;/LI&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;LI&gt;Use the spring security service to forward requests to arcgis from the user and return the response.&amp;nbsp; In this case, the user would never have direct access to the arcgis.&amp;nbsp; Ldap would just contain a user, let's say arcgisUser, with access to all services.&amp;nbsp; The spring security project would determine if a user had access to a particular URL.&amp;nbsp; If he did, it would make the request to arcgis along with a token generated using arcgisUser and return the response.&amp;nbsp; Otherwise, the user would receive an error message.&lt;/LI&gt;&lt;BR /&gt;&lt;/OL&gt;&lt;BR /&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Nic&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 15:00:18 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98649#M3834</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2013-11-12T15:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98650#M3835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Where are you going to deploy arcgis.war?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 15:20:47 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98650#M3835</guid>
      <dc:creator>LeoDonahue</dc:creator>
      <dc:date>2013-11-12T15:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98651#M3836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Where are you going to deploy arcgis.war?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've been deploying the web adaptor to a redhat server using the instructions found &lt;/SPAN&gt;&lt;A href="http://resources.arcgis.com/en/help/main/10.2/#/Installing_the_ArcGIS_Web_Adaptor/015500000529000000/"&gt;here&lt;/A&gt;&lt;SPAN&gt;&lt;SPAN&gt;.&amp;nbsp; Our IT department was kind enough to perform the steps in the "Configuring the ArcGIS Web Adaptor." link at the bottom of the setup instructions.&amp;nbsp; The URL we'll expose to our users will be something like: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;{springSecurityProjectName}/arcgis/rest/services.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 15:35:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98651#M3836</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2013-11-12T15:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98652#M3837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;How does Spring Security restrict access to:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://yourserver/arcgis/rest/services"&gt;http://yourserver/arcgis/rest/services&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I know you said you were using maven overlay, but won't that only apply to your SpringSecurityProjectName web app?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Step #6 of that link you posted says follow your Java application server to deploy the arcgis.war.&amp;nbsp; When you do that, the /arcgis path is open to everyone.&amp;nbsp; Right?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 15:49:33 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98652#M3837</guid>
      <dc:creator>LeoDonahue</dc:creator>
      <dc:date>2013-11-12T15:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98653#M3838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;How does Spring Security restrict access to:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://yourserver/arcgis/rest/services" rel="nofollow noopener noreferrer" target="_blank"&gt;http://yourserver/arcgis/rest/services&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;?&lt;BR /&gt;&lt;BR /&gt;I know you said you were using maven overlay, but won't that only apply to your SpringSecurityProjectName web app?&lt;BR /&gt;&lt;BR /&gt;Step #6 of that link you posted says follow your Java application server to deploy the arcgis.war.&amp;nbsp; When you do that, the /arcgis path is open to everyone.&amp;nbsp; Right?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In the security.xml file of the spring security project, I just added&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="lia-code-sample line-numbers language-none"&gt;&amp;lt;intercept-url pattern="/arcgis/**"
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access="hasRole('ROLE_ADMIN')"/&amp;gt; &lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;This is subject to change but it did allow me to prove that visiting &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow noopener noreferrer" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;{myserver}/arcgis requires the user to login.&amp;nbsp; All spring overlay does is allow me to add to the arcgis.war file.&amp;nbsp; The result would be the same if I just took the contents of my spring security war file and manually moved them into the arcgis war file.&amp;nbsp; I originally deployed just the arcgis war file without any security.&amp;nbsp; At that point, the services were exposed to everyone.&amp;nbsp; It was only after merging in the spring security project that I was able to secure the services.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Dec 2021 06:09:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98653#M3838</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2021-12-11T06:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98654#M3839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I see.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I haven't used Spring for anything yet.&amp;nbsp; It looks like it gives you a custom springSecurityFilterChain Filter to secure the URLs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What happens to &lt;/SPAN&gt;&lt;A href="http://yourserver/arcgis"&gt;http://yourserver/arcgis&lt;/A&gt;&lt;SPAN&gt; if your SpringSecurityProjectName web app crashes?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It seems like all this does is move the security configuration from the web container to the Spring Framework?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 16:39:24 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98654#M3839</guid>
      <dc:creator>LeoDonahue</dc:creator>
      <dc:date>2013-11-12T16:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98655#M3840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;I see.&lt;BR /&gt;&lt;BR /&gt;I haven't used Spring for anything yet.&amp;nbsp; It looks like it gives you a custom springSecurityFilterChain Filter to secure the URLs.&lt;BR /&gt;&lt;BR /&gt;What happens to &lt;A href="http://yourserver/arcgis"&gt;http://yourserver/arcgis&lt;/A&gt; if your SpringSecurityProjectName web app crashes?&lt;BR /&gt;&lt;BR /&gt;It seems like all this does is move the security configuration from the web container to the Spring Framework?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;That's an excellent question.&amp;nbsp; The answer to that may very well cause me to use option 2 instead of option 1.&amp;nbsp; I'll post again if I get a definitive answer.&amp;nbsp; My hope would be that since they're running under the same java process, crashing one would crash the other.&amp;nbsp; We'll have some white hat testers come in at some point and I'll offer this up as a potential exploit.&amp;nbsp; Something I could do to ensure bringing down the security service would prevent access to the arcgis services would be to steal part of option two.&amp;nbsp; I would allow users to login using spring security but only the arcgisUser would have access to arcgis services.&amp;nbsp; The spring security application would have the token generated by arcgisUser to access the url.&amp;nbsp; If it crashed, the user would need to login as arcgisUser to gain access to the site (which they wouldn't be able to do).&amp;nbsp; This would involve ensuring the user was never directed to a url containing the token but I believe it's possible.&amp;nbsp; The advantage I've seen to moving the security configuration to the spring framework is that it allows you to provide authorization down to the method level.&amp;nbsp; The spring framework seems pretty powerful but since I'm pretty green I'll abstain from making any claims beyond saying, yes, it allows you to move the security configuration out of the web container.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 16:58:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98655#M3840</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2013-11-12T16:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98656#M3841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Just so I'm on the same page here.&amp;nbsp; You want to secure user access to making requests to your arcgis.war URL.&amp;nbsp; Or are you trying to add security to an application that consumes the arcgis.war?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I ask because you have mentioned using tokens and also securing your web app down to the method level.&amp;nbsp; The method level of your application or the method level of say an ArcGIS Geometry service?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 18:32:07 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98656#M3841</guid>
      <dc:creator>LeoDonahue</dc:creator>
      <dc:date>2013-11-12T18:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98657#M3842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Just so I'm on the same page here.&amp;nbsp; You want to secure user access to making requests to your arcgis.war URL.&amp;nbsp; Or are you trying to add security to an application that consumes the arcgis.war?&lt;BR /&gt;&lt;BR /&gt;I ask because you have mentioned using tokens and also securing your web app down to the method level.&amp;nbsp; The method level of your application or the method level of say an ArcGIS Geometry service?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'll be securing access to arcgis.war URL (web adaptor).&amp;nbsp; I'll probably hold off on the token generation unless the security testing indicates there's a vulnerability.&amp;nbsp; If there is one, I'll use a token generated in arcmanager at &lt;/SPAN&gt;&lt;A href="https://myserver.example.com/arcgis/tokens/generateToken"&gt;https://myserver.example.com/arcgis/tokens/generateToken&lt;/A&gt;&lt;SPAN&gt; and use that token to access the arcgis services.&amp;nbsp; That token will be read by the spring project and applied to the url the user requests, provided that user has access to it.&amp;nbsp; As far as securing methods go, it would probably only be useful for SOEs.&amp;nbsp; I may be wrong though.&amp;nbsp; It might be possible to secure a method within the geometry service.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 19:03:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98657#M3842</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2013-11-12T19:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98658#M3843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm not sure what using Spring Security "and" tokens buys you.&amp;nbsp; They both restrict access to the arcgis web services based on username/password.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You could deploy arcgis.war and enable security on it using ArcGIS Server Manager and get the same effect.&amp;nbsp; The user consuming ArcGIS Server web service would need to authenticate, and at that point, you should be under HTTPS.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is why I asked if you are securing the ArcGIS web service or the application that consumes your ArcGIS web service.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Your app can always generate a token in the background and supply those credentials to a secure ArcGIS web service without the user of your app even knowing.&amp;nbsp; However, I get the feeling that you also want to secure the "app", which is fine - I get it, but I think your solution is trending towards unnecessary complication by fielding requests to arcgis.war via Spring Security.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Spring Security secures your app.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ArcGIS Server and possibly the web container can secure your ArcGIS Web services.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 19:37:36 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98658#M3843</guid>
      <dc:creator>LeoDonahue</dc:creator>
      <dc:date>2013-11-12T19:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98659#M3844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;I'm not sure what using Spring Security "and" tokens buys you.&amp;nbsp; They both restrict access to the arcgis web services based on username/password.&lt;BR /&gt;&lt;BR /&gt;You could deploy arcgis.war and enable security on it using ArcGIS Server Manager and get the same effect.&amp;nbsp; The user consuming ArcGIS Server web service would need to authenticate, and at that point, you should be under HTTPS.&lt;BR /&gt;&lt;BR /&gt;This is why I asked if you are securing the ArcGIS web service or the application that consumes your ArcGIS web service.&lt;BR /&gt;&lt;BR /&gt;Your app can always generate a token in the background and supply those credentials to a secure ArcGIS web service without the user of your app even knowing.&amp;nbsp; However, I get the feeling that you also want to secure the "app", which is fine - I get it, but I think your solution is trending towards unnecessary complication by fielding requests to arcgis.war via Spring Security.&lt;BR /&gt;&lt;BR /&gt;Spring Security secures your app.&lt;BR /&gt;ArcGIS Server and possibly the web container can secure your ArcGIS Web services.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ArcGIS server manager is great but it doesn't meet our business requirements.&amp;nbsp; We'll need to provide a way for hundreds of users external to our company to login to our website.&amp;nbsp; The big catch is that depending on what type of subscription they have with us, they'll be restricted to different areas of the web services.&amp;nbsp; Yes, they could be added to various groups but that requires more manual effort than I want to put forth.&amp;nbsp; This, and other requirements I won't bore you with, rules server manager out as an option.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 19:47:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98659#M3844</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2013-11-12T19:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98660#M3845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;ArcGIS server manager is great but it doesn't meet our business requirements.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;I would "not" suggest using it to define/create users.&amp;nbsp; It can be configured to authenticate users to LDAP or a database.&amp;nbsp; You can always write a front end to let users register under a certain subscription, but that process should be manually reviewed anyway.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 19:57:25 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98660#M3845</guid>
      <dc:creator>LeoDonahue</dc:creator>
      <dc:date>2013-11-12T19:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98661#M3846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Our web adaptor is now secured by spring security rather than LDAP using the ideas posted previously in this thread.&amp;nbsp; Just thought I'd post in case anyone was considering using it.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 21:47:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98661#M3846</guid>
      <dc:creator>NicCampbell</dc:creator>
      <dc:date>2014-01-03T21:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Services using the Spring Framework on 10.2</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98662#M3847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Similarily to you I have an Spring application that communicates to AGS. Application is secured but services are not and they have to.&lt;/P&gt;&lt;P&gt;I thought about some solutions and one of them is that you described as option 1.&lt;/P&gt;&lt;P&gt;As I suppose there is some kind of Single Sign On at least between your application and web adaptor (services)?&lt;/P&gt;&lt;P&gt;Is there a possibility to get your configuration? Or even some instructions?&lt;/P&gt;&lt;P&gt;(unfortunatelly I can't go to link that you wrote in post)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2014 04:29:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/securing-services-using-the-spring-framework-on-10/m-p/98662#M3847</guid>
      <dc:creator>AdamKuran</dc:creator>
      <dc:date>2014-08-07T04:29:20Z</dc:date>
    </item>
  </channel>
</rss>

