<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PLEASE READ: Important Message Regarding Security in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/please-read-important-message-regarding-security/m-p/230711#M183841</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Another way to solve this security loophole is via an Apache HTTP server in front of the Alfresco installation (Tomcat).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;Location "/alfresco/jbpm/deployprocess" &amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny from all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/Location&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I always install and configure a separate Apache server which connects to Alfresco on tomcat via mod_proxy_ajp (binary protocol). Normally I even disable the HTTP connector on port 8080. And I also configure Apache to serve the static files using Aliasses on the static directories.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/images !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/css !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/scripts !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/swf !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/yui !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco ajp://localhost:8009/alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPassReverse /alfresco ajp://localhost:8009/alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/images "/opt/alfresco/tomcat/webapps/alfresco/images"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/css "/opt/alfresco/tomcat/webapps/alfresco/css"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/scripts "/opt/alfresco/webapps/alfresco/scripts"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/swf "/opt/alfresco/webapps/alfresco/swf"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/yui "/opt/alfresco/webapps/alfresco/yui"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Advantages:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Tomcat does not have to serve static files. Apache does that a lot better and faster&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Use port 80 by default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Using a rewrite rule, I can add /alfresco automatically.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- A lot more secure to offer your end users an Apache interface and keep the Tomcat interface including the management console separate. Only open port 80 (and 443) in the firewall.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Very easy to implement SSL on Apache&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In short, just use a Web Server for what it's built and use the Application Server to serve the application, and nothing more.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Implementing this security fix took me only one minute and no restart of Alfresco was required. Even more, the Alfresco war is still original.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Aug 2010 12:28:23 GMT</pubDate>
    <dc:creator>heydenb</dc:creator>
    <dc:date>2010-08-04T12:28:23Z</dc:date>
    <item>
      <title>PLEASE READ: Important Message Regarding Security</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-read-important-message-regarding-security/m-p/230710#M183840</link>
      <description>All-Thanks to Jeff Potts at Metaversant ( http://www.metaversant.com), Alfresco has become aware of a potential security loophole where the jBPM process deployer servlet runs without authentication. This means that a valid user may deploy a workflow that grants them admin access or similar. However,</description>
      <pubDate>Fri, 23 Jul 2010 13:54:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-read-important-message-regarding-security/m-p/230710#M183840</guid>
      <dc:creator>nancyg</dc:creator>
      <dc:date>2010-07-23T13:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: PLEASE READ: Important Message Regarding Security</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-read-important-message-regarding-security/m-p/230711#M183841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Another way to solve this security loophole is via an Apache HTTP server in front of the Alfresco installation (Tomcat).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;Location "/alfresco/jbpm/deployprocess" &amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny from all&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/Location&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I always install and configure a separate Apache server which connects to Alfresco on tomcat via mod_proxy_ajp (binary protocol). Normally I even disable the HTTP connector on port 8080. And I also configure Apache to serve the static files using Aliasses on the static directories.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/images !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/css !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/scripts !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/swf !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco/yui !&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /alfresco ajp://localhost:8009/alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPassReverse /alfresco ajp://localhost:8009/alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/images "/opt/alfresco/tomcat/webapps/alfresco/images"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/css "/opt/alfresco/tomcat/webapps/alfresco/css"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/scripts "/opt/alfresco/webapps/alfresco/scripts"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/swf "/opt/alfresco/webapps/alfresco/swf"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alias /alfresco/yui "/opt/alfresco/webapps/alfresco/yui"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Advantages:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Tomcat does not have to serve static files. Apache does that a lot better and faster&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Use port 80 by default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Using a rewrite rule, I can add /alfresco automatically.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- A lot more secure to offer your end users an Apache interface and keep the Tomcat interface including the management console separate. Only open port 80 (and 443) in the firewall.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Very easy to implement SSL on Apache&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In short, just use a Web Server for what it's built and use the Application Server to serve the application, and nothing more.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Implementing this security fix took me only one minute and no restart of Alfresco was required. Even more, the Alfresco war is still original.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 12:28:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-read-important-message-regarding-security/m-p/230711#M183841</guid>
      <dc:creator>heydenb</dc:creator>
      <dc:date>2010-08-04T12:28:23Z</dc:date>
    </item>
  </channel>
</rss>

