Cargando…
Securing Access to Controls Applications with Apache httpd Proxy
Many commercial systems used for controls nowadays contain embedded web servers. Secure access to these, often essential, facilities is of utmost importance, yet it remains complicated to manage for different reasons (e.g. obtaining and applying patches from vendors, ad-hoc oversimplified implementa...
Autores principales: | , |
---|---|
Lenguaje: | eng |
Publicado: |
2015
|
Materias: | |
Acceso en línea: | https://dx.doi.org/10.18429/JACoW-ICALEPCS2015-WEPGF010 http://cds.cern.ch/record/2213494 |
_version_ | 1780951997596303360 |
---|---|
author | Golonka, Piotr Kamarainen, Hannu |
author_facet | Golonka, Piotr Kamarainen, Hannu |
author_sort | Golonka, Piotr |
collection | CERN |
description | Many commercial systems used for controls nowadays contain embedded web servers. Secure access to these, often essential, facilities is of utmost importance, yet it remains complicated to manage for different reasons (e.g. obtaining and applying patches from vendors, ad-hoc oversimplified implementations of web-servers are prone to remote exploit). In this paper we describe a security-mediating proxy system, which is based on the well-known Apache httpd software. We describe how the use of the proxy made it possible to simplify the infrastructure necessary to start WinCC OA-based supervision applications on operator consoles, providing, at the same time, an improved level of security and traceability. Proper integration with the CERN central user account repository allows the operators to use their personal credentials to access applications, and also allows one to use standard user management tools. In addition, easy-to-memorize URL addresses for access to the applications are provided, and the use of a secure https transport protocol is possible for services that do not support it on their own. |
id | oai-inspirehep.net-1481641 |
institution | Organización Europea para la Investigación Nuclear |
language | eng |
publishDate | 2015 |
record_format | invenio |
spelling | oai-inspirehep.net-14816412019-09-30T06:29:59Zdoi:10.18429/JACoW-ICALEPCS2015-WEPGF010http://cds.cern.ch/record/2213494engGolonka, PiotrKamarainen, HannuSecuring Access to Controls Applications with Apache httpd ProxyAccelerators and Storage RingsMany commercial systems used for controls nowadays contain embedded web servers. Secure access to these, often essential, facilities is of utmost importance, yet it remains complicated to manage for different reasons (e.g. obtaining and applying patches from vendors, ad-hoc oversimplified implementations of web-servers are prone to remote exploit). In this paper we describe a security-mediating proxy system, which is based on the well-known Apache httpd software. We describe how the use of the proxy made it possible to simplify the infrastructure necessary to start WinCC OA-based supervision applications on operator consoles, providing, at the same time, an improved level of security and traceability. Proper integration with the CERN central user account repository allows the operators to use their personal credentials to access applications, and also allows one to use standard user management tools. In addition, easy-to-memorize URL addresses for access to the applications are provided, and the use of a secure https transport protocol is possible for services that do not support it on their own.oai:inspirehep.net:14816412015 |
spellingShingle | Accelerators and Storage Rings Golonka, Piotr Kamarainen, Hannu Securing Access to Controls Applications with Apache httpd Proxy |
title | Securing Access to Controls Applications with Apache httpd Proxy |
title_full | Securing Access to Controls Applications with Apache httpd Proxy |
title_fullStr | Securing Access to Controls Applications with Apache httpd Proxy |
title_full_unstemmed | Securing Access to Controls Applications with Apache httpd Proxy |
title_short | Securing Access to Controls Applications with Apache httpd Proxy |
title_sort | securing access to controls applications with apache httpd proxy |
topic | Accelerators and Storage Rings |
url | https://dx.doi.org/10.18429/JACoW-ICALEPCS2015-WEPGF010 http://cds.cern.ch/record/2213494 |
work_keys_str_mv | AT golonkapiotr securingaccesstocontrolsapplicationswithapachehttpdproxy AT kamarainenhannu securingaccesstocontrolsapplicationswithapachehttpdproxy |