<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAS 9.4 Web Server Hardening in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/246851#M3955</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm very new to SAS 9.4 setup. Anyone can point me to information how I can know more on the SAS Web Server Security Configuration and Setup? Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I know is the server is based on Pivotal WS. How should I proceed with Server Hardedning in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Nelson&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2016 08:27:25 GMT</pubDate>
    <dc:creator>zennigan</dc:creator>
    <dc:date>2016-01-29T08:27:25Z</dc:date>
    <item>
      <title>SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/246851#M3955</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm very new to SAS 9.4 setup. Anyone can point me to information how I can know more on the SAS Web Server Security Configuration and Setup? Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I know is the server is based on Pivotal WS. How should I proceed with Server Hardedning in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Nelson&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 08:27:25 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/246851#M3955</guid>
      <dc:creator>zennigan</dc:creator>
      <dc:date>2016-01-29T08:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/246854#M3956</link>
      <description>&lt;P&gt;AFAIK, this Pivotal thing is based on apache, so the principal rules and configuration options should be the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FWIW, I have no idea why SAS subjects us customers once again to a change in the middleware. AFAIK jboss/apache is alive and kicking.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're Microsofting more and more, SAS!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 09:17:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/246854#M3956</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2016-01-29T09:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/246873#M3958</link>
      <description>In 9.4 you can configure HTTPS for the web server with the deployment wizard during installation and configuration. Its recommended you set up SSL with the deployment wizard so that the SSL configuration with be retained if and when you implement a maintenance release (if you configure manually on the backend the configuration would be reverted during an upgrade).&lt;BR /&gt;&lt;BR /&gt;As Kurt said, though, most techniques for hardening Apache would apply here.&lt;BR /&gt;&lt;BR /&gt;Check this out: &lt;A href="http://www.tecmint.com/apache-security-tips/" target="_blank"&gt;http://www.tecmint.com/apache-security-tips/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The web server config files you're looking for are usually here: &amp;lt;sasconfig&amp;gt;/Lev1/Web/WebServer/conf and &amp;lt;sasconfig&amp;gt;/Lev1/Web/WebServer/conf/extra&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 29 Jan 2016 12:58:08 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/246873#M3958</guid>
      <dc:creator>Timmy2383</dc:creator>
      <dc:date>2016-01-29T12:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247007#M3962</link>
      <description>&lt;P&gt;I would suggest you start out with the &lt;A href="https://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1cy3v8480k4q6n1ew2mrn0ns2ld.htm" target="_self"&gt;Checklist for a More Secure Deployment&lt;/A&gt;&amp;nbsp;section of the&amp;nbsp;&lt;EM&gt;SAS 9.4 Intelligence Platform: Security Administration Guide, Second Edition&lt;/EM&gt;. That will direct you off to other SAS documents&amp;nbsp;for more information on those&amp;nbsp;items you decide to implement. Hardening the web server is just one aspect of maintaining a secure SAS platform so that checklist will get you thinking about some of the other aspects too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might also want to be aware of the &lt;A href="https://support.sas.com/security/alerts.html" target="_self"&gt;SAS&amp;nbsp;Security Bulletins&lt;/A&gt;&amp;nbsp;page. It has&amp;nbsp;some statements that explain how SAS software may or may not be impacted by some of general web/software&amp;nbsp;security issues that have had high profile appearences in the media recently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to keep up to date with hotfixes/patches take a look at the &lt;A href="http://ftp.sas.com/techsup/download/hotfix/hotfix.html" target="_self"&gt;SAS&amp;nbsp;Technical Support Hot Fixes&lt;/A&gt;&amp;nbsp;page. From there you can subscribe to find out about hotfixes as the are released (of which which many may be for products you don't have), or use the&amp;nbsp;&lt;EM&gt;Hot Fix Analysis, Download and Deployment Tool&lt;/EM&gt;&amp;nbsp;(HFADD) to get tailored reports for your&amp;nbsp;specific deployments. I wrote some blog posts about HFADD and hotfixes a while ago that may help: &lt;A href="http://platformadmin.com/blogs/paul/tag/sas-hotfixes/" target="_self"&gt;http://platformadmin.com/blogs/paul/tag/sas-hotfixes/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the SAS&amp;nbsp;platform doesn't stand in isolation you would also want to discuss general platform/network security with the appropriate team within your organization (and perhaps in combination with SAS Professional Services or a local SAS Partner too). They can advise, based on the intended use of, and access to, the SAS platform, any&amp;nbsp;organizational requirements for firewalls, web application firewalls, secure reverse proxies, SSL server/client certificates, identity management, single signon etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2016 01:38:09 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247007#M3962</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2016-01-30T01:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247099#M3970</link>
      <description>&lt;P&gt;Paul,&amp;nbsp;the checklist for a more secure deployment is a SAS view of that direction not the common accepted view how the security&amp;nbsp;should be reviewed (iso27k cobit sox) and surely not the ones for common hardening guidelines (OS webserver) as being very technical.&lt;BR /&gt;&lt;BR /&gt;Kurts remark on getting microsoftical has some real reasons I can agree with him.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 08:54:19 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247099#M3970</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2016-01-31T08:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247102#M3973</link>
      <description>&lt;P&gt;Jaap, if you re-read my reply you might notice that I said the checklist was something to "&lt;EM&gt;start out with&lt;/EM&gt;" and I advised that it would be good&amp;nbsp;to "&lt;SPAN&gt;&lt;EM&gt;discuss general platform/network security&lt;/EM&gt;" with others in the organization. The&amp;nbsp;SAS bias in my reply was on the basis that if someone was asking about "&lt;EM&gt;SAS Web Server Security Configuration and Setup&lt;/EM&gt;" in a SAS software forum then they might want a&amp;nbsp;"&lt;EM&gt;SAS view&lt;/EM&gt;" as a starting point.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 09:32:16 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247102#M3973</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2016-01-31T09:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247103#M3974</link>
      <description>&lt;P&gt;Yes I understand And Have seen &amp;nbsp;"&lt;SPAN&gt;&lt;EM&gt;discuss general platform/network security&lt;/EM&gt;" with others in the organization. That is good.&lt;BR /&gt;and in a SAS software forum then they might want a&amp;nbsp;"&lt;EM&gt;SAS view&lt;/EM&gt;" as a starting point.&lt;BR /&gt;&lt;BR /&gt;My ongoing frustration is those are not aligned.&amp;nbsp;Going to those general platform/network security guys wiht the starting point of a "SAS view" you are quickly seen as the one that is doing dangerous things&amp;nbsp;ans should be blocked or isolated in some dedicated area.&lt;BR /&gt;That is not a nice situation.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 09:43:37 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247103#M3974</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2016-01-31T09:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247126#M3975</link>
      <description>&lt;P&gt;Jaap, that's a bold negative statement that really should be debated, but I have other activities that need my attention more. &amp;nbsp;&lt;SPAN style="line-height: 20px;"&gt;My intention was to point the original poster in the direction of some resources that might be of help to them in the SAS software task they have ahead of them, so I'm going to leave this thread here.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 21:32:06 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247126#M3975</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2016-01-31T21:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 Web Server Hardening</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247212#M3983</link>
      <description>&lt;P&gt;I appreciate the views of all in helping&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/14351"&gt;@zennigan﻿&lt;/a&gt;&amp;nbsp;with this question. For someone new to a SAS set up, a variety of resources can be helpful. Let's keep this in mind as we reply to questions in the community...you never know what one person will find helpful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Shelley&lt;/P&gt;
&lt;P&gt;Online Community Manager&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 14:56:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-Web-Server-Hardening/m-p/247212#M3983</guid>
      <dc:creator>ShelleySessoms</dc:creator>
      <dc:date>2016-02-01T14:56:49Z</dc:date>
    </item>
  </channel>
</rss>

