<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>dbFront.com - Recent questions and answers in Security</title>
<link>https://dbfront.com/qa/qa/security</link>
<description>Powered by Question2Answer</description>
<item>
<title>Answered: Active Directory Federated Services Single Sign-on Setup</title>
<link>https://dbfront.com/qa/1342/active-directory-federated-services-single-sign-on-setup?show=1343#a1343</link>
<description>&lt;p&gt;Active Directory Federated Services (AD FS), is listed as being SAML2 compliant.&lt;/p&gt;
&lt;p&gt;Therefore the answer is Yes.  dbFront supports all SAML2 compliant authentication services.   If you encounter  any difficulties then please let us know.  We would be happy to assist.&lt;/p&gt;
&lt;p&gt;Related Documentation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview&quot;&gt;Microsoft AD FS Overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/single-sign-on&quot;&gt;dbFront Single Sign-on set up Instructions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following article describes setting up AD FS with another Microsoft product named Power Pages.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://learn.microsoft.com/en-us/power-pages/security/authentication/saml2-settings&quot;&gt;SAML2 Setting for AD FS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A related request&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/qa/865/integrated-windows-authentication-kerobos&quot;&gt;Integrated Windows Authentication&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/1342/active-directory-federated-services-single-sign-on-setup?show=1343#a1343</guid>
<pubDate>Fri, 08 Sep 2023 17:50:50 +0000</pubDate>
</item>
<item>
<title>Answered: Admin Grants Access to a Connection</title>
<link>https://dbfront.com/qa/1302/admin-grants-access-to-a-connection?show=1304#a1304</link>
<description>&lt;p&gt;That is described in more detail in the provided link &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/connectionaccess&quot;&gt;https://dbfront.com/connectionaccess&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you are still having issues the please let me know what type of authentication you have specified for your non-admin users.&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/1302/admin-grants-access-to-a-connection?show=1304#a1304</guid>
<pubDate>Wed, 12 Apr 2023 20:11:55 +0000</pubDate>
</item>
<item>
<title>Answered: SSL Certificate - Could we use a wildcard certificate</title>
<link>https://dbfront.com/qa/1211/ssl-certificate-could-we-use-a-wildcard-certificate?show=1285#a1285</link>
<description>&lt;p&gt;I am going to assume that the issue was the load balancer.  Please indicate if there is something else going on.&lt;/p&gt;
&lt;p&gt;The issue with using a LoadBalancer is that they are often the termination point for the SSL connection. The LoadBalancer forwards the conversation to the WebServer/dbFront as plain, unsecure HTTP.  This means that the client sees that the connection is running over SSL but dbFront and the WebServer only see HTTP which is unsecure.&lt;/p&gt;
&lt;p&gt;One solution would be to configure dbFront to look for custom HTTP headers added by the LoadBalancer.  This would need to be site specific.&lt;/p&gt;
&lt;p&gt;Let me know if that functionality is required.&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/1211/ssl-certificate-could-we-use-a-wildcard-certificate?show=1285#a1285</guid>
<pubDate>Fri, 03 Feb 2023 00:08:38 +0000</pubDate>
</item>
<item>
<title>Answered: Can't save Settings.  Access to the path ... is denied.</title>
<link>https://dbfront.com/qa/1125/cant-save-settings-access-to-the-path-is-denied?show=1126#a1126</link>
<description>&lt;p&gt;When you click on &quot;Save Setting&quot;, dbFront requests the credentials of a Server Administrator.&lt;/p&gt;
&lt;p&gt;Once you enter the credentials dbFront &quot;impersonates&quot; that administrative user so that it can save the necessary settings in the application config file.&lt;/p&gt;
&lt;p&gt;This error message means that the user you specified no longer has the necessary access to replace the configuration file in that folder.  You can validate this by opening Notepad and attempting to create a file in the folder &lt;strong&gt;'C:\Program Files (x86)\dbFront\'&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Once solution is to directly give your Administrative user &quot;Full Access&quot; to the folder &lt;strong&gt;'C:\Program Files (x86)\dbFront\'&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;One item that may be confusing is that the specified user may already be a member of an Administrator group which has access to that folder and therefore should &lt;strong&gt;logically&lt;/strong&gt; already have the necessary access.  &lt;/p&gt;
&lt;p&gt;The special groups &lt;strong&gt;ALL APPLICATION PACKAGES&lt;/strong&gt; and &lt;strong&gt;ALL RESTRICTED APPLICATION PACKAGES&lt;/strong&gt; are present on affected folders.&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/1125/cant-save-settings-access-to-the-path-is-denied?show=1126#a1126</guid>
<pubDate>Wed, 26 Jan 2022 22:46:17 +0000</pubDate>
</item>
<item>
<title>Answered: dbFront is NOT affected by the Log4j Security Vulnerability</title>
<link>https://dbfront.com/qa/1107/dbfront-is-not-affected-by-the-log4j-security-vulnerability?show=1108#a1108</link>
<description>&lt;h3&gt;dbFront is NOT affected by the Log4j Security vulnerability.&lt;/h3&gt;
&lt;p&gt;dbFront is built using the Microsoft Dotnet 4.7.2 Framework and uses its own internal logging.&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/1107/dbfront-is-not-affected-by-the-log4j-security-vulnerability?show=1108#a1108</guid>
<pubDate>Sat, 11 Dec 2021 20:08:15 +0000</pubDate>
</item>
<item>
<title>Answered: Warning: The User List Was Truncated!</title>
<link>https://dbfront.com/qa/912/warning-the-user-list-was-truncated?show=913#a913</link>
<description>&lt;p&gt;dbFront will download the user list in order to allow dbFront administrators to directly manage the dbFront access and avoid the creation of additional network security groups.&lt;/p&gt;
&lt;p&gt;For smaller Active Directory installations (less then 100,000 users), this should work as expected.&lt;/p&gt;
&lt;p&gt;For larger Active Directories or slower networks, the time to query the user-list can become excessive.  To avoid problems, dbFront will truncate the user-list if the query takes longer then expected.&lt;/p&gt;
&lt;p&gt;This problem can be solved in two ways.&lt;/p&gt;
&lt;h2&gt;1) Reduce the number of users returned.&lt;/h2&gt;
&lt;p&gt;dbFront has a number of settings that allow you to limit the total number of dbFront users.&lt;/p&gt;
&lt;p&gt;See: &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/qa/77/performance-issues-when-using-access-button-limit-selection&quot;&gt;https://dbfront.com/qa/77/performance-issues-when-using-access-button-limit-selection&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;2) Increase the Time-out when querying for users.&lt;/h2&gt;
&lt;p&gt;By default dbFront will allow a AD query to run for 120 seconds.  After that dbFront will stop the request and return the what it has retrieved up to that point.&lt;/p&gt;
&lt;p&gt;To increase the timeout you will need to edit the file [**C:\Program Files(x86)\dbFront\dbFrontService.exe.config**] and add the key.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt; &amp;lt;add key=&quot;UserDomainTimeout&quot; value=&quot;120&quot; /&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The value of the key is in seconds.&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/912/warning-the-user-list-was-truncated?show=913#a913</guid>
<pubDate>Mon, 15 Mar 2021 19:33:12 +0000</pubDate>
</item>
<item>
<title>Answered: Row Level Security examples including CASE and IF</title>
<link>https://dbfront.com/qa/775/row-level-security-examples-including-case-and-if?show=776#a776</link>
<description>&lt;p&gt;The row-security expressions must evaluate to true or false.   The expression syntax is the same as when you create a regular where clause.  The only difference is that fields from the current table must be bracketed by {[ and ]}.&lt;/p&gt;
&lt;p&gt;Anything that is normally permitted in a SQL where clause should work including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;%username% = 'Admin'&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;{[ProductId]} &amp;gt; 7&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;{[DiscontinuedDate]} is not null&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;{[StandardCost]} between 0 and 100&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;{[CategoryId]} in (select CategoryId from Category where name = 'Bikes')&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;{[ID]} = case {[StatusId]} when 0 then 30 when 1 then 42  end&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;CASE Statements that return a Boolean&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If your SQL server understands the keywords &lt;strong&gt;TRUE&lt;/strong&gt; and &lt;strong&gt;FALSE&lt;/strong&gt; then you can write a CASE statement as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;case when {[Color]}= 'red' then TRUE else FALSE end&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Otherwise you can write it as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;(case when {[Color]}= 'red' then 1 else 0 end) = 1&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Stored Functions&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you have even more complex requirements then your SQL server likely supports the use of Stored Functions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;More details&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/rowsecurity&quot;&gt;Row Level Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/775/row-level-security-examples-including-case-and-if?show=776#a776</guid>
<pubDate>Wed, 12 Aug 2020 15:46:06 +0000</pubDate>
</item>
<item>
<title>Answered: Filter recordset by user access with where clause</title>
<link>https://dbfront.com/qa/772/filter-recordset-by-user-access-with-where-clause?show=774#a774</link>
<description>&lt;p&gt;The functionality you describe is called &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/rowsecurity&quot;&gt;Row Level Security&lt;/a&gt;.  This is a core part of the dbFront functionality.&lt;/p&gt;
&lt;p&gt;Please see the following topics for more details about implementing security: &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/rowsecurity&quot;&gt;Row Level Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/usersecurity&quot;&gt;User Level Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/772/filter-recordset-by-user-access-with-where-clause?show=774#a774</guid>
<pubDate>Wed, 12 Aug 2020 13:28:40 +0000</pubDate>
</item>
<item>
<title>Answered: Single-Sign-On Extent?</title>
<link>https://dbfront.com/qa/668/single-sign-on-extent?show=669#a669</link>
<description>&lt;p&gt;Enabling Single-Sign-On disables Windows and Database authentication as an authentication option when signing in to dbFront.&lt;/p&gt;
&lt;p&gt;When Single-Sign-On is enabled, the user will no longer see any authentication attempts by dbFront.  Instead, dbFront will delegate all authentication attempts to the configured Single-Sign-On service.&lt;/p&gt;
&lt;p&gt;This has no effect on the process of creating database connections.  The database connections are used exclusively to create applications that are made available to users.&lt;/p&gt;
&lt;p&gt;The database connections must be made using that specific database server's authentication.  Windows or SSO authentication is not applicable at that point.&lt;/p&gt;
&lt;p&gt;NOTE: It is possible to bypass SSO but ONLY directly on the server using the URL: [http://localhost/dbFront], This allows administrators to configure the SSO setup.&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/668/single-sign-on-extent?show=669#a669</guid>
<pubDate>Tue, 24 Mar 2020 14:57:06 +0000</pubDate>
</item>
<item>
<title>Answered: Error: &quot;No Database connection access&quot;, How to login without Admin access?</title>
<link>https://dbfront.com/qa/146/error-database-connection-access-login-without-admin-access?show=147#a147</link>
<description>&lt;p&gt;Before a Non-Administrative user can login to dbFront they must first be granted access by an Administrator.&lt;/p&gt;
&lt;p&gt;This can be done in two different ways.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1) Admin Grants Access to a Connection&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Normally an administrator will create a database connection and setup an application and then grant regular users access to that connection.&lt;/p&gt;
&lt;p&gt;This means that the regular users will have only the access to that connection that the administrator has granted.&lt;/p&gt;
&lt;p&gt;For more details see: &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/connectionaccess&quot;&gt;Connection Access&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2) Grant dbFront Admin access to specific user group&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The second option is to setup dbFront so that a specific user group is also granted dbFront Admin access.  Two extra access levels are available.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;AdminAllGroup&lt;/strong&gt;: These users will have the ability to create or administer all Database Connections.  Local and Domain Administrators will automatically have this privilege.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;AdminMyGroup&lt;/strong&gt;: These users will have the ability to create or administer their own Database Connections.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more details see: &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/appserverinstall#users&quot;&gt;User Access Config&lt;/a&gt;&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/146/error-database-connection-access-login-without-admin-access?show=147#a147</guid>
<pubDate>Fri, 01 Jun 2018 15:38:54 +0000</pubDate>
</item>
<item>
<title>Answered: Can't get SID for 'groupname', The Server service is not started.</title>
<link>https://dbfront.com/qa/128/cant-get-sid-for-groupname-the-server-service-is-not-started?show=129#a129</link>
<description>&lt;p&gt;This error means that there is a windows service named &quot;Service&quot; on the computer that hosts your user directory that was not available at the time that dbFront attempted to resolve the group name.&lt;/p&gt;
&lt;p&gt;The computer hosting the directory service could be your domain controller or the local server depending upon how you have your authentication setup.&lt;/p&gt;
&lt;p&gt;To resolve this issue you should restart the dbFrontService.&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/128/cant-get-sid-for-groupname-the-server-service-is-not-started?show=129#a129</guid>
<pubDate>Fri, 16 Feb 2018 17:52:03 +0000</pubDate>
</item>
<item>
<title>Answered: AD Groups Support</title>
<link>https://dbfront.com/qa/88/ad-groups-support?show=89#a89</link>
<description>&lt;p&gt;As of version &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/releasehistory#v1.0.2.9740&quot;&gt;1.0.2.9740&lt;/a&gt;, dbFront now allows you to specify Update and a ReadOnly AD Groups.  Users in those groups will have either Update or Readonly permissions.&lt;/p&gt;
&lt;p&gt;This is in addition to the existing support for specifying user specific permissions.   User specific permissions will override group membership if present.&lt;/p&gt;
&lt;p&gt;Otherwise the &quot;Default Access&quot; for that connection will apply.    This applies to all other users that have dbFront access.&lt;/p&gt;
&lt;p&gt;For more details see: &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/windowsauthentication&quot;&gt;https://dbfront.com/windowsauthentication&lt;/a&gt;&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/88/ad-groups-support?show=89#a89</guid>
<pubDate>Wed, 04 Oct 2017 04:34:02 +0000</pubDate>
</item>
<item>
<title>Answered: AD performance issues when using the &quot;access&quot; button (limit OU selection)</title>
<link>https://dbfront.com/qa/77/performance-issues-when-using-access-button-limit-selection?show=78#a78</link>
<description>&lt;p&gt;dbFront allows you to specify the &lt;strong&gt;User Container&lt;/strong&gt; used when querying Active Directory.   This setting can be managed via [Help]/[Settings] in the [Authentication] tab.   For more details search for &quot;UserContainer&quot; on:  &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/appserverinstall&quot;&gt;Application Service Install&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In addition dbFront has the following three settings that can be used to select which users have access to dbFront.   These settings allows you to specify the access level of the users returned from your AD.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;AdminAllGroup&lt;/strong&gt;:	The name of the local or domain group who's users will have the ability to add or administer all Database Connections.&lt;br&gt;
Local and Domain Administrators will automatically have this&lt;br&gt;
privilege.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;AdminMyGroup&lt;/strong&gt;:	 The name of the local or domain group who's users will have the ability to add or administer their own Database&lt;br&gt;
Connections.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;UserGroup&lt;/strong&gt;:	The group of users who have access to login to dbFront.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more details please see: &lt;a rel=&quot;nofollow&quot; href=&quot;https://dbfront.com/appserverinstall#users&quot;&gt;https://dbfront.com/appserverinstall#users&lt;/a&gt;&lt;/p&gt;
</description>
<category>Security</category>
<guid isPermaLink="true">https://dbfront.com/qa/77/performance-issues-when-using-access-button-limit-selection?show=78#a78</guid>
<pubDate>Thu, 20 Jul 2017 03:02:44 +0000</pubDate>
</item>
</channel>
</rss>