<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IIS Allow Unlisted File Name Extensions in Esri Software Security &amp; Privacy Questions</title>
    <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1054168#M126</link>
    <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;&amp;nbsp;thank you for the list of file name extensions and all your help so far. Unfortunately adding your list of allowed file types did not resolve my problem where GIS services (e.g. map, feature, etc.) are not working with "allow unlisted file name extensions" disabled in IIS.&lt;/P&gt;&lt;P&gt;I think it's because many of the requests to a GIS service don't really have a file extension. Here is an example:&lt;/P&gt;&lt;P&gt;&lt;A href="https://gisweb.columbus.gov/arctest/rest/info?f=json" target="_blank"&gt;https://gisweb.columbus.gov/arctest/rest/info?f=json&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if "extensionless" requests like that are blocked when unlisted file types are disallowed? If so, is there a solution?&lt;/P&gt;&lt;P&gt;I've seen suggestions online to include a wildcard ("*") as one of the allowed file types, but to me that would defeat the purpose of disabling the setting in the first place.&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 12:42:15 GMT</pubDate>
    <dc:creator>MattFancher1</dc:creator>
    <dc:date>2021-05-04T12:42:15Z</dc:date>
    <item>
      <title>IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053889#M120</link>
      <description>&lt;P&gt;Does Esri maintain a list of file name extensions that must be allowed in order for GIS services (e.g. map, feature, geocode, etc.) to function properly? My organization now requires certain IIS hardening settings to improve security. One requirement is to disable "allow unlisted file name extensions" under request filtering in IIS manager. Unfortunately that breaks all our GIS services. My hope is that adding additional file name extensions to what is already allowed will fix the problem. Any advice?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 17:40:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053889#M120</guid>
      <dc:creator>MattFancher1</dc:creator>
      <dc:date>2021-05-03T17:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053934#M122</link>
      <description>&lt;P&gt;According to&amp;nbsp;&lt;EM&gt;&lt;A href="https://support.esri.com/en/technical-article/000021912" target="_self"&gt;Problem: Unable to connect to basic functionality in Portal for ArcGIS&lt;/A&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Portal for ArcGIS and its underlying processes use many custom file extensions. Access to these file extensions is limited when the 'Allow unlisted file name extensions', 'Allow unlisted verbs', and 'Allow high-bit characters' options are disabled in the Request Filtering section of IIS Manager. Group policy dictates&amp;nbsp;the enabled/disabled&amp;nbsp;settings in IIS Manager, and they may be disabled for security purposes.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I believe, unfortunately, disallowing unlisted file name extensions in IIS could be discouraged for now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You may check &lt;A href="https://trust.arcgis.com/en/security/arcgis-server-best-practices.htm" target="_self"&gt;ArcGIS Enterprise Implementation Guidance&lt;/A&gt; for&amp;nbsp;best practices (security) when deploying ArcGIS Enterprise.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 19:37:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053934#M122</guid>
      <dc:creator>JayantaPoddar</dc:creator>
      <dc:date>2021-05-03T19:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053940#M123</link>
      <description>&lt;P&gt;I dislike this kB. It will be ignored by those who require web server hardening. A better resource would include a list of custom extensions that can be allowed rather than a statement saying essentially "don't harden your web server".&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 19:29:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053940#M123</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2021-05-03T19:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053942#M124</link>
      <description>&lt;P&gt;That's true.&lt;/P&gt;&lt;P&gt;Does Esri have any resource that would list out the extensions (* some files might not have any extension at all) that would ensure ArcGIS Enterprise works through the IIS hardening?&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 19:39:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053942#M124</guid>
      <dc:creator>JayantaPoddar</dc:creator>
      <dc:date>2021-05-03T19:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053948#M125</link>
      <description>&lt;P&gt;Yes, I provided it to OP via PM. Its in a raw format and not yet ready for public. It is current as to 10.8.1.&lt;/P&gt;&lt;P&gt;It was compiled of this list:&lt;/P&gt;&lt;P&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/use/supported-items.htm" target="_blank"&gt;https://enterprise.arcgis.com/en/portal/latest/use/supported-items.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;plus the output of this command:&lt;/P&gt;&lt;P&gt;&lt;A href="https://devblogs.microsoft.com/scripting/hey-scripting-guy-how-can-i-use-windows-powershell-to-pick-out-the-unique-file-extensions-used-in-a-collection-of-files/" target="_blank"&gt;https://devblogs.microsoft.com/scripting/hey-scripting-guy-how-can-i-use-windows-powershell-to-pick-out-the-unique-file-extensions-used-in-a-collection-of-files/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then filtered for extensions that should not be allowed (eg: executables, config files, etc.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 19:48:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1053948#M125</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2021-05-03T19:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1054168#M126</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;&amp;nbsp;thank you for the list of file name extensions and all your help so far. Unfortunately adding your list of allowed file types did not resolve my problem where GIS services (e.g. map, feature, etc.) are not working with "allow unlisted file name extensions" disabled in IIS.&lt;/P&gt;&lt;P&gt;I think it's because many of the requests to a GIS service don't really have a file extension. Here is an example:&lt;/P&gt;&lt;P&gt;&lt;A href="https://gisweb.columbus.gov/arctest/rest/info?f=json" target="_blank"&gt;https://gisweb.columbus.gov/arctest/rest/info?f=json&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if "extensionless" requests like that are blocked when unlisted file types are disallowed? If so, is there a solution?&lt;/P&gt;&lt;P&gt;I've seen suggestions online to include a wildcard ("*") as one of the allowed file types, but to me that would defeat the purpose of disabling the setting in the first place.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 12:42:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1054168#M126</guid>
      <dc:creator>MattFancher1</dc:creator>
      <dc:date>2021-05-04T12:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1104430#M135</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/460753"&gt;@Matt&lt;/a&gt;was this ever resolved?&amp;nbsp; I'm interested to learn if you were ever successful with this.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 15:38:24 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1104430#M135</guid>
      <dc:creator>BonnieCecil</dc:creator>
      <dc:date>2021-10-04T15:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1104448#M136</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/105222"&gt;@BonnieCecil&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;&amp;nbsp;sent me a list of file extension exceptions that are need if you want to run Portal with "allow unlisted file extensions" disabled. That was a bit overkill for my purpose.&amp;nbsp; I'm just running stand-alone ArcGIS Server. All I really needed was to add "." for the extensionless requests and ".css" so the REST service directly displayed correctly. Later I had to add a few more exceptions due to outputs from print services (e.g. ".pdf", ".png", ".svg", ".jpg", etc). That was about it for me. I won't swear that is comprehensive, but it's been working in production for us for a few months.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 15:06:18 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1104448#M136</guid>
      <dc:creator>MattFancher1</dc:creator>
      <dc:date>2021-10-05T15:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: IIS Allow Unlisted File Name Extensions</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1105037#M137</link>
      <description>&lt;P&gt;Thank you - that information is helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 00:25:00 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/iis-allow-unlisted-file-name-extensions/m-p/1105037#M137</guid>
      <dc:creator>BonnieCecil</dc:creator>
      <dc:date>2021-10-06T00:25:00Z</dc:date>
    </item>
  </channel>
</rss>

