Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsNews FeedsNews FeedsFirewall/Proxy authentication Enhancement IdeaFirewall/Proxy authentication Enhancement Idea
Previous
 
Next
New Post
11/4/2008 7:27 AM
 

Hi Peter,

v4.00.01 is working for me, but I've had to build a custom firewall rule to allow the anonymous requests from the NewsFeed module to the destination RSS feed sites.

I know each RSS feed entry has a username and PW capability, but that is for the destination site, if required. I'm thinking there may be value to add a module level username/pw capability so a low level AD Domain account, specifically used for this purpose (i.e., this NewsFeed module) could be used to authenticate against the firewall/proxy to give it outbound access without having to add specific RSS sites to the rule.

My current method works, but this addition could make it easier in certain corporate environments. Since I trust the module to install it on my site, I trust it will only access the RSS sites I configure it to access.

Rob Ralston


Rob Ralston, SilverBullet Technologies LLC, www.silverbullettech.com
 
New Post
11/4/2008 7:51 AM
 

Rob,

shouldn't this be a portal setting or AD provider setting to be used by multiple modules?


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
11/4/2008 11:52 AM
 

Hi Sebastion,

Well, from my firewall logs, the module is making anonymous access requests to the Internet, which is normal, as IE also does that by default first, too. However, IE will receive a notification from the Proxy/Firewall that authentication is required, then IE will pass the currently logged in users' credentials and get access, if the rules allow.

Typically, it is not a good security practice to allow all outbound traffic to every machine or user on the network, so even though my portal's application pool account is run under a low level AD Domain account, portal modules cannot just go out to the Internet and access any site they want because that low level account has no access permissions. It obviously can respond to inbound requests without a problem.

Anyway, this type of setup clearly causes more work for the admin to determine what custom Firewall rules must be written to allow needed outbound access for various internal systems and applications, but at least it's not a "free for all".

So, having said all that, the idea was to allow an admin to create a new "special" low level AD account that would be configured with general outbound http access, and then enter those credentials into the modules settings for it to use to access RSS sites.

I'm sure this is more complex than anyone else cares about. I just like to have strict security controls in place so I know where outbound traffic is originating from and why.


Rob Ralston, SilverBullet Technologies LLC, www.silverbullettech.com
 
New Post
11/18/2008 3:05 PM
 

Hi Rob,

This is indeed an issue. I would like to run through all the security issues sometime soon. This I had not thought about earlier. I hope to involve Cathal in this effort as he has a lot of knowhow on this. I spoke to him about it at OF/EU but haven't gotten round to emailing him yet.

Peter


Peter Donker
Bring2mind http://www.bring2mind.net
Home of the Document Exchange,
the professional document management solution for DNN
 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsNews FeedsNews FeedsFirewall/Proxy authentication Enhancement IdeaFirewall/Proxy authentication Enhancement Idea


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out