<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Deployment Agent config question prior to install in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SSL-Deployment-Agent-config-question-prior-to-install/m-p/237213#M3670</link>
    <description>&lt;P&gt;A source of mine writes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri" size="3"&gt;There is a difference between these two types of connections (Web Server connections and Agent connections), and it would be best if they considered them independently within their security infrastructure.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri" size="3"&gt;Given that the connections between the SAS Deployment Agents are internal only connections, they can do whatever they want (set up certificates or not), however, I personally do not think it is a good practice to allow something like the SAS Deployment Agent to remain insecure. It’s basically an API that can execute anything you want on a remote machine. In general, we recommend that the Deployment Agent and the EV Agents be secured using our generated certificates regardless of what they intend to do with external network connections.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2015 21:11:05 GMT</pubDate>
    <dc:creator>gregraka</dc:creator>
    <dc:date>2015-12-01T21:11:05Z</dc:date>
    <item>
      <title>SSL Deployment Agent config question prior to install</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SSL-Deployment-Agent-config-question-prior-to-install/m-p/174395#M2227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When doing a SSL - we only want the web server SSL the SAS Applications like IDP, WRS and STP Web Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence for the section of the SAS 9.4 install/config guide, Implement Certificates for SAS Deployment Agent, will not apply, correct? only 'Certificates for Web Server' section. Correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help on this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Nov 2014 16:40:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SSL-Deployment-Agent-config-question-prior-to-install/m-p/174395#M2227</guid>
      <dc:creator>jplarios</dc:creator>
      <dc:date>2014-11-17T16:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Deployment Agent config question prior to install</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SSL-Deployment-Agent-config-question-prior-to-install/m-p/237213#M3670</link>
      <description>&lt;P&gt;A source of mine writes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri" size="3"&gt;There is a difference between these two types of connections (Web Server connections and Agent connections), and it would be best if they considered them independently within their security infrastructure.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: rgb(31, 73, 125);"&gt;&lt;FONT face="Calibri" size="3"&gt;Given that the connections between the SAS Deployment Agents are internal only connections, they can do whatever they want (set up certificates or not), however, I personally do not think it is a good practice to allow something like the SAS Deployment Agent to remain insecure. It’s basically an API that can execute anything you want on a remote machine. In general, we recommend that the Deployment Agent and the EV Agents be secured using our generated certificates regardless of what they intend to do with external network connections.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 21:11:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SSL-Deployment-Agent-config-question-prior-to-install/m-p/237213#M3670</guid>
      <dc:creator>gregraka</dc:creator>
      <dc:date>2015-12-01T21:11:05Z</dc:date>
    </item>
  </channel>
</rss>

