Symantec Access Management

  • 1.  How to Prohibit Bypassing Web Agent

    Posted May 04, 2018 04:43 PM

    Hi,

     

    I see three possible ways that might be used to ensure a web agent is never bypassed; thus, ensure a user cannot spoof headers at an app server.

     

    I'm looking for wisdom/experience on each of these -- or possibly other methods I've not thought of.

     

    1) IP Restriction

     

    Pro: Simple to configure on IIS, etc.

    Cons:  Can break production applications when new web servers/app servers are introduced.  Also, some apps like JBoss want to restrict app access always -- but allow direct access for admins.

     

     

    2)  Client Certs

     

     

    3) OFC -- encrypt responses consumed by applications

     

    Pros: Get around hassles with IP Restriction and cert management.  Unless a "hacker" knew the strong session key, there's no way to spoof headers/cookies.

    Cons: Custom code?  But our thinking is we could easily abstract this for our developers since CA provides most of what is needed.

     

     

     

    Thoughts/Experiences?

     

    Cheers,

    Jim



  • 2.  Re: How to Prohibit Bypassing Web Agent

    Posted May 07, 2018 02:14 AM

    Hi Jim,

     

    This has been brought up couple of times before. The consensus has always been the solution you identified.

     

    Please refer to following threads for the discussion the same :

     

    How to protect backend app that accessed via CA SPS ? 

    What are the secure SiteMinder HTTP Header to pass to Protected Back-end Server (Jboss) 

     

    Regards,

    Ujwol