<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing Geoevent REST inputs in ArcGIS GeoEvent Server Questions</title>
    <link>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300294#M1245</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="font-family: sans-serif; color: #3d3d3d; font-size: 11.5pt;"&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;&lt;A href="https://community.esri.com/migrated-users/295700"&gt;James Madden&lt;/A&gt; –&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;Nothing we are discussing here will be included in the 10.8 release due out next week (Jan 20th). The product team continues to actively consider options for additional security and refactoring the product&amp;nbsp;to implement features like authentication for REST requests or moving GeoEvent Server's open REST endpoints to its administrative API.&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;I cannot say, however, which future release such work would target.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;–&amp;nbsp;RJ&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jan 2020 22:31:44 GMT</pubDate>
    <dc:creator>RJSunderman</dc:creator>
    <dc:date>2020-01-15T22:31:44Z</dc:date>
    <item>
      <title>Securing Geoevent REST inputs</title>
      <link>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300289#M1240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured some geojson inputs in Geoevent Server 10.6 and have noticed that I am able to POST requests to these endpoints without supplying any authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e. I can POST an event to&amp;nbsp;&lt;A href="https://outlook.office365.com/owa/?realm=novasystems.com&amp;amp;exsvurl=1&amp;amp;ll-cc=2057&amp;amp;modurl=0&amp;amp;path=/mail/sentitems/rp" rel="noopener noreferrer" target="_blank"&gt;https://&amp;lt;host&amp;gt;:6143/geoevent/rest/receiver/geojson-device-location&lt;/A&gt;&amp;nbsp;without providing any authentication and the request is processed ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a bug or by design?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 00:08:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300289#M1240</guid>
      <dc:creator>MatthewLangley</dc:creator>
      <dc:date>2018-05-16T00:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Geoevent REST inputs</title>
      <link>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300290#M1241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Hello Matthew,&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;I want to first apologize for the wait time you have experienced with your post. To answer your question I can say what you are seeing is the out-of-the-box behavior, however, there is an enhancement for this topic.&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;[ENH-000125501: Provide additional security controls for the GeoEvent Server REST endpoints]&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Kind regards,&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2019 20:20:05 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300290#M1241</guid>
      <dc:creator>DanWade</dc:creator>
      <dc:date>2019-09-24T20:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Geoevent REST inputs</title>
      <link>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300291#M1242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan, can you provide a link to a document describing the enhancement you mentioned?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2020 16:17:11 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300291#M1242</guid>
      <dc:creator>JamesMadden1</dc:creator>
      <dc:date>2020-01-13T16:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Geoevent REST inputs</title>
      <link>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300292#M1243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="font-family: sans-serif; color: #3d3d3d; font-size: 11.5pt;"&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;Hello &lt;A href="https://community.esri.com/migrated-users/295700"&gt;James Madden&lt;/A&gt; –&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;Yes. By design GeoEvent Server REST receiver inputs allow an unauthenticated client / server to send POST requests to a running inbound connector. Recent releases ensure that such requests occur over HTTPS (not HTTP).&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;We have not considered&amp;nbsp;this particularly troubling for several reasons. Production systems usually secure their servers with an authenticating proxy and ACLs. If they want to grant access to a specific data provider, they configure a tunnel through their firewall for that specific provider. Also, any data sent must pass through an inbound adapter which uses a strict GeoEvent Definition to interpret the data. The event definition cannot be modified without authenticating with the administrative API, so potentially malicious code will not survive adaption to create an event record which can actually be processed – malicious code or data will be discarded as unrecognized by the inbound adapter.&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;Over time, some users have voiced concern that information about a GeoEvent Server's configuration can be obtained by an unauthenticated user, via public REST endpoints, if they are able to reach a server machine via the machine's fully-qualified domain name and port. That's why production servers are secured using authenticating proxies and firewalls.&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;&lt;A href="https://community.esri.com/migrated-users/2715"&gt;Dan Wade&lt;/A&gt;‌ has referenced an effort the product team is considering to move&amp;nbsp;many endpoints reachable today via &lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;host.domain:6143/geoevent/rest&lt;/SPAN&gt; by moving the endpoints beneath&amp;nbsp;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;host.domain:6143/geoevent/admin&lt;/SPAN&gt; so that authentication is required to reach them. There is some hesitation to secure the REST receiver endpoints. You cannot POST malicious XML, SQL, etc. to a GeoEvent Server receiver – the receiver's inbound adapter will not recognize the data's structure / schema and will discard the data.&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;&lt;SPAN style="font-family: sans-serif;"&gt;&lt;SPAN style="font-size: 11.5pt;"&gt;In your opinion, should an external&amp;nbsp;client / server application be required to authenticate before being allowed to send a POST request to a GeoEvent Server input? Given that communication is secured using HTTPS, access to the server can be secured using an authenticating proxy and firewall, and adaption requires a predefined and &lt;/SPAN&gt;&lt;SPAN style="font-size: 15.3333px;"&gt;recognizable&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt;"&gt;&amp;nbsp;data structure / schema ... we don't want to unnecessarily inhibit inbound data flow.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;– RJ&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2020 01:15:25 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300292#M1243</guid>
      <dc:creator>RJSunderman</dc:creator>
      <dc:date>2020-01-15T01:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Geoevent REST inputs</title>
      <link>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300293#M1244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RJ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp; We have GeoEvent Server installed on a box that is only available on our internal network.&amp;nbsp; I recall reading where ESRI recommends that architecture for GeoEvent.&amp;nbsp; That said, we would still like to require authentication internally but I am not sure how that would impact the data flow.&amp;nbsp; I imagine an extra level of processing might slow things down a bit.&amp;nbsp; I guess we could always hit the service's "add feature" endpoint directly from ArcGIS Server, if authentication is an absolute requirement.&amp;nbsp; Do you expect ESRI to add authentication options into future releases?&amp;nbsp; We are planning to migrate to 10.7 in the coming months.&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2020 15:42:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300293#M1244</guid>
      <dc:creator>JamesMadden1</dc:creator>
      <dc:date>2020-01-15T15:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Securing Geoevent REST inputs</title>
      <link>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300294#M1245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="font-family: sans-serif; color: #3d3d3d; font-size: 11.5pt;"&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;&lt;A href="https://community.esri.com/migrated-users/295700"&gt;James Madden&lt;/A&gt; –&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;Nothing we are discussing here will be included in the 10.8 release due out next week (Jan 20th). The product team continues to actively consider options for additional security and refactoring the product&amp;nbsp;to implement features like authentication for REST requests or moving GeoEvent Server's open REST endpoints to its administrative API.&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;I cannot say, however, which future release such work would target.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 8.0pt 0in 8.0pt 0in;"&gt;–&amp;nbsp;RJ&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2020 22:31:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-geoevent-server-questions/securing-geoevent-rest-inputs/m-p/300294#M1245</guid>
      <dc:creator>RJSunderman</dc:creator>
      <dc:date>2020-01-15T22:31:44Z</dc:date>
    </item>
  </channel>
</rss>

