<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alfresco 4.1 external SSO Security in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-4-1-external-sso-security/m-p/268824#M221954</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm hoping someone here has an answer for me, I'm working on enabling the external authentication subsystem and had some questions about security.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It seems that once the system is enabled, all Alfresco needs for SSO is a header. If that Alfresco was outward facing, anyone with malicious intent, could simply insert add the Remote-User header with the value admin and have at the repository. Is there a way to ensure that the header was included from my authenticating app and not otherwise injected?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If not, would my next step be to write a custom authentication subsystem?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jan 2013 17:34:00 GMT</pubDate>
    <dc:creator>mstein</dc:creator>
    <dc:date>2013-01-18T17:34:00Z</dc:date>
    <item>
      <title>Alfresco 4.1 external SSO Security</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-4-1-external-sso-security/m-p/268824#M221954</link>
      <description>I'm hoping someone here has an answer for me, I'm working on enabling the external authentication subsystem and had some questions about security.It seems that once the system is enabled, all Alfresco needs for SSO is a header. If that Alfresco was outward facing, anyone with malicious intent, could</description>
      <pubDate>Fri, 18 Jan 2013 17:34:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-4-1-external-sso-security/m-p/268824#M221954</guid>
      <dc:creator>mstein</dc:creator>
      <dc:date>2013-01-18T17:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 4.1 external SSO Security</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-4-1-external-sso-security/m-p/268825#M221955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;You need to make sure there is protection for your authentication tokens.&amp;nbsp;&amp;nbsp; So alfresco should probably be behind a firewall that rips off any malicious tokens.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 18:30:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-4-1-external-sso-security/m-p/268825#M221955</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2013-01-18T18:30:27Z</dc:date>
    </item>
  </channel>
</rss>

