Cargando…

Securing Access to Controls Applications with Apache httpd Proxy

Many commercial systems used for controls nowadays contain embedded web servers. Secure access to these, often essential, facilities is of utmost importance, yet it remains complicated to manage for different reasons (e.g. obtaining and applying patches from vendors, ad-hoc oversimplified implementa...

Descripción completa

Detalles Bibliográficos
Autores principales: Golonka, Piotr, Kamarainen, Hannu
Lenguaje:eng
Publicado: 2015
Materias:
Acceso en línea:https://dx.doi.org/10.18429/JACoW-ICALEPCS2015-WEPGF010
http://cds.cern.ch/record/2213494
_version_ 1780951997596303360
author Golonka, Piotr
Kamarainen, Hannu
author_facet Golonka, Piotr
Kamarainen, Hannu
author_sort Golonka, Piotr
collection CERN
description Many commercial systems used for controls nowadays contain embedded web servers. Secure access to these, often essential, facilities is of utmost importance, yet it remains complicated to manage for different reasons (e.g. obtaining and applying patches from vendors, ad-hoc oversimplified implementations of web-servers are prone to remote exploit). In this paper we describe a security-mediating proxy system, which is based on the well-known Apache httpd software. We describe how the use of the proxy made it possible to simplify the infrastructure necessary to start WinCC OA-based supervision applications on operator consoles, providing, at the same time, an improved level of security and traceability. Proper integration with the CERN central user account repository allows the operators to use their personal credentials to access applications, and also allows one to use standard user management tools. In addition, easy-to-memorize URL addresses for access to the applications are provided, and the use of a secure https transport protocol is possible for services that do not support it on their own.
id oai-inspirehep.net-1481641
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2015
record_format invenio
spelling oai-inspirehep.net-14816412019-09-30T06:29:59Zdoi:10.18429/JACoW-ICALEPCS2015-WEPGF010http://cds.cern.ch/record/2213494engGolonka, PiotrKamarainen, HannuSecuring Access to Controls Applications with Apache httpd ProxyAccelerators and Storage RingsMany commercial systems used for controls nowadays contain embedded web servers. Secure access to these, often essential, facilities is of utmost importance, yet it remains complicated to manage for different reasons (e.g. obtaining and applying patches from vendors, ad-hoc oversimplified implementations of web-servers are prone to remote exploit). In this paper we describe a security-mediating proxy system, which is based on the well-known Apache httpd software. We describe how the use of the proxy made it possible to simplify the infrastructure necessary to start WinCC OA-based supervision applications on operator consoles, providing, at the same time, an improved level of security and traceability. Proper integration with the CERN central user account repository allows the operators to use their personal credentials to access applications, and also allows one to use standard user management tools. In addition, easy-to-memorize URL addresses for access to the applications are provided, and the use of a secure https transport protocol is possible for services that do not support it on their own.oai:inspirehep.net:14816412015
spellingShingle Accelerators and Storage Rings
Golonka, Piotr
Kamarainen, Hannu
Securing Access to Controls Applications with Apache httpd Proxy
title Securing Access to Controls Applications with Apache httpd Proxy
title_full Securing Access to Controls Applications with Apache httpd Proxy
title_fullStr Securing Access to Controls Applications with Apache httpd Proxy
title_full_unstemmed Securing Access to Controls Applications with Apache httpd Proxy
title_short Securing Access to Controls Applications with Apache httpd Proxy
title_sort securing access to controls applications with apache httpd proxy
topic Accelerators and Storage Rings
url https://dx.doi.org/10.18429/JACoW-ICALEPCS2015-WEPGF010
http://cds.cern.ch/record/2213494
work_keys_str_mv AT golonkapiotr securingaccesstocontrolsapplicationswithapachehttpdproxy
AT kamarainenhannu securingaccesstocontrolsapplicationswithapachehttpdproxy