Strengthening and security for Oracle Content & Portal Server

Hi all

I developed an Application Oracle WebCenter Portal Framework, which is a public website from the front. There are no requirements for users to connect to the Web site or to contribute any content. All content are delivered through Intranet Portal.

Static web application resources such as css, javascript and images are checked in Oracle Content Server with the public group. I set the definition of the region and as a WebLogic group check-in and it is defined as a connection of UCM via the Application Framework of portal in Oracle Enterprise Manager.

I set up Web URL mapped folders to serve my static content (css, javascript, pictures) through the content server that I can access my pictures by clicking using the http://localhost/CS/folder/pictures/filename.jpg 

Content and portal servers are behind a reverse proxy (Oracle iPlanet Web server), but I noticed there are several defined servlet in the Web.XML as portlets, servlets admin which I think it should be deleted if not used.

I also put web.xml as zero, connection authentication mode because I don't expect all users to connect to the public Web site. I also defined safety for all groups to be seen only in the hierarchy of the Page options.

Is there something else I should take note of the strengthening of the security/point of view?


Hello

I don't have your question. Intranet portal and portal public face are the same application or different? What authentication using provider?

Anyone who is not connected to the WebCenter Portal assumes the role of the Public user. Out-of-the-box, the role of the Public user has minimal privileges, i.e. approval of request for an opinion. Be careful when granting permissions to the Public user role. Avoid to grant administrative permissions as Application managing all, Application-managed Configuration or any permission that can be considered useless.

If you don't want the unauthenticated users to see content marked "public" WebCenter portal, do not grant the permission View Application to the Public user role. When public access is disabled, the public content is invisible to unauthenticated users. In addition, the homepage for WebCenter Portal is not displayed; public users are directed to a login page. Administrators can customize the default login page, if necessary.

Please check below the administration guide on the permissions of the application

http://docs.Oracle.com/CD/E29542_01/WebCenter.1111/e27738/wcadm_ps_security.htm#CDDHEAAC

Please specify on servlet. Also the version of the webcenter portal.

Thank you

Amey

Tags: Fusion Middleware

Similar Questions

  • Are there privacy and security for facetime ios 9

    I am afraid to do a call facetime from what I have heard tell that many people try to vocation and someone answer it then call us if there are privacy and security for facetime in ios 9, please let me know

    What are you talking about?

    Please explain.

    Why are you afraid?

  • Where to place the folder forms and reports for oracle 10g on Linux server

    Hello...

    Currently, iam has a migration to oracle 10g module.
    All my modules which consists of form and report files are inside a
    folder named PROJECT and placed in C:\ in windows server.
    So when I want to call a form or a report I used the path as "C:\PROJECT\module_name\form_name.fmx."
    My client now wants her project to be used in the LINUX-based server.

    Now, I want to know where I should put my form project file and file reports
    and how I should call them...

    Thanks in advance

    Can you say how can I call reports as u said hardcode the path when the report is not a good practice.

    I agree with Dhiraj Madan, paths of coding is a very bad idea, your application has become non-portable.

    For FORMS_PATH, you can use default.env, as already said (or .env, if applicable).

    The same can be done for REPORTS_PATH, using the reports.sh script, in $ORACLE_HOME/bin.

  • Cannot install KB979909 and KB979906 for Windows 2000, Windows Server 2003 and Windows XP

    Original title: Microsoft .NET Framework 3.5 SP1 and .NET Framework 2.0 SP2 security update for Windows 2000, Windows Server 2003 and Windows XP x 86 __Microsoft .NET Framework 1.1 SP1 (KB979909) update for Windows 2000 and Windows XP (KB979906) __KB979909)

    I was warned, I got updates, I clicked on install

    he installed an and failed both

    I can't determine how to solve this problem, and the little shield that warns me still here says I need to update

    the explanation refers to the sp?

    IM unaware of what these elements affect

    See the RESPONSE message in this thread: http://social.answers.microsoft.com/Forums/en/vistawu/thread/5dc22ff1-ba9a-4a3a-9f19-49e85908c4c9 ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • BlackBerry Smartphones Forget the question of password and security for Blackberry Id

    I try to use my Blackberry Id and I realize that I forgot my password question and security.

    I can't find a solution, I have to do?

    Read this to get instructions to reset your password BlackBerryID:

    KB26361 How to reset a BlackBerry ID password

    *****
    It must be remembered the BlackBerryID password or secret answer to the question. Without either, you're stuck.
    Your choice is:
    -Use a different e-mail account to create a new BlackBerryID (with which you will lose access to all apps purchased using the 'forgotten' first BlackBerryID, or)
    -Find the initial email you have been sent to confirm the initial BlackBerryID and there are a link to click to cancel and delete the account. Click on this, delete the account and then you can use that same e-mail to create a new account.
    Good luck.

  • ServicePack 2 KB9481332 not install error code 8007321 and security for windows vista updated it not install error code 8007321

    Diagnostic report (1.9.0027.0):
    -----------------------------------------
    Validation of Windows data-->
    Validation status: genuine
    Validation code: 0
    Validation caching Code online: n/a, hr = 0xc004f012
    Windows product key: *-* - F4GJK - KG77H-B9HD2
    The Windows Product Key hash: iJAth4TbScMi8HdcPurlASXdEkw =
    Windows product ID: 89578-OEM-7332157-00204
    Windows product ID type: 2
    Windows license Type: OEM SLP
    The Windows OS version: 6.0.6001.2.00010300.1.0.003
    ID: {1875E091-75B7-41D8-958B-843FB221316C} (1)
    Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/a, hr = 0 x 80070002
    Signed by: n/a, hr = 0 x 80070002
    Product name: Windows Vista (TM) Home Premium
    Architecture: 0x00000000
    Build lab: 6001.vistasp1_gdr.100218 - 0019
    TTS error:
    Validation of diagnosis:
    Resolution state: n/a

    Given Vista WgaER-->
    ThreatID (s): n/a, hr = 0 x 80070002
    Version: 6.0.6002.16398

    Windows XP Notifications data-->
    Cached result: n/a, hr = 0 x 80070002
    File: No.
    Version: N/a, hr = 0 x 80070002
    WgaTray.exe signed by: n/a, hr = 0 x 80070002
    WgaLogon.dll signed by: n/a, hr = 0 x 80070002

    OGA Notifications data-->
    Cached result: n/a, hr = 0 x 80070002
    Version: 2.0.48.0
    OGAExec.exe signed by: Microsoft
    OGAAddin.dll signed by: Microsoft

    OGA data-->
    Office status: 100 authentic
    2007 Microsoft Office system - 100 authentic
    OGA Version: Registered, 2.0.48.0
    Signed by: Microsoft
    Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_70AFE6BE-656-80070057_E2AD56EA-815-80070057

    Data browser-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default browser: C:\Program may Explorer\iexplore.exe
    Download signed ActiveX controls: fast
    Download unsigned ActiveX controls: disabled
    Run ActiveX controls and plug-ins: allowed
    Initialize and script ActiveX controls not marked as safe: disabled
    Allow the Internet Explorer Webbrowser control scripts: disabled
    Active scripting: allowed
    Recognized ActiveX controls safe for scripting: allowed

    Analysis of file data-->

    Other data-->
    Office details: {1875E091-75B7-41D8-958B-843FB221316C}1.9.0027.06.0.6001.2.00010300.1.0.003x 32*-*-*-*-B9HD289578-OEM-7332157-002042S-1-5-21-3856123575-3819749968-2084870378Dell Inc.. XPS M1330                       Dell Inc.. A12 20080708000000.000000 + 00032323507018400F804090409Eastern Standard Time(GMT-05:00)03DELL M08 1001002007 Microsoft Office system1236C3896821FDB0Cj14tOk8/me2hXF/W2AM1dxJcsw =89451-OEM-6672833-451754

    Content Spsys.log: 0 x 80070002

    License data-->
    The software licensing service version: 6.0.6001.18000
    Name: Windows Vista, HomePremium edition
    Description: operating system Windows - Vista, channel OEM_SLP
    Activation ID: bffdc375-bbd5-499d-8ef1-4f37b61c895f
    ID of the application: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 89578-00146-321-500204-02-1033-6001.0000-2972008
    Installation ID: 002291501995125740168792437623497931990145071114719384
    Processor certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473
    Machine certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474
    Use license URL: http://go.microsoft.com/fwlink/?LinkID=43476
    Product key certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475
    Partial product key: B9HD2
    License status: licensed

    Windows Activation Technologies-->
    N/A

    --> HWID data
    Current Hash HWID: OgAAAAEABgABAAEAAQABAAAAAwABAAEA6GEAhAqefPQSeei4YNEM8kaDuLdEnPL0mEaGdW4LrFZGyg ==

    Activation 1.0 data OEM-->
    N/A

    Activation 2.0 data OEM-->
    BIOS valid for OA 2.0: Yes
    Windows marker version: 0 x 20000
    OEMID and OEMTableID consistent: Yes
    BIOS information:
    ACPI Table name OEMID value OEMTableID value
    REFERENCE DELL M08 APIC
    FACP DELL M08
    HPET DELL M08
    STARTING DELL M08
    MCFG DELL M08
    M08 DELL SLIC
    SSDT PmRef CpuPm

    Hi crawlerpa,
     
    We have checked for Service pack 2 KB9481332 and the error code 8007321. Unfortunately, not found no information on this subject. We recommend you to cross check if the number you entered is correct and provide us with the exact error code.
     
    To download and install Service Pack 2, click download the Service Pack 2
    Kind regards
    Syed - Microsoft technical support.
    Visit our Microsoft answers feedback Forum and let us know what you think.
  • How blackBerry Smartphones wipe a backup and security for Blackberry Curve.

    Hi all, first time poster, second spectator of time... If that makes sense!

    New jobs and support of BlackBerry devices for the first time (mainly because I have one, ergo;) I'm an expert!). No problem it's always good to learn new things...

    Well, that's my problem - I have a user who cannot respond to emails - I have read some posts that were all on the money as to why and how to solve them. My problem is I have to perform a back up and wipe security, but do not know how and was hoping someone could guide my way. What is a professional user I won't spoil and lose\delete his email and addresses, etc.

    It is important that we use Notes and Domino (Boo!) instead of Outlook and Exchange? And it is an easy process?

    Thank you very much.

    London_Exile.

    Follow these steps for peripheral storage BlackBerry-

    1. connect your device using the USB cable

    2. click on the backup and restore

    3. click the backup button

    4. Select the location where you want to keep the backup data

    5. click on Ok to continue

    Note: I have described the process according to desktop manager 4.5. You can download it here.

    To wipe your handheld computer, follow these steps-

    1. go to Options

    2. security options

    3. General settings

    4. click on the Menu button

    5. Select wipe Handheld

    6. enter in blackberry to proceed

  • How to uninstall manually introduce securiy and security for windows 8

    the new update windows8 have security and what I need to remove my security presents because he wants me to uninstall manually? Thank you

    Windows 8 has MSE as standard antivirus and anti-spyware feature.  If you upgraded a system Windows 7 to Windows 8, you may well need to uninstall what you have.  I would recommend against replacement Windows 7 for a whole bunch of reasons.  I installed it on a different partition (which you can easily create).

    Good luck.

  • Library and Viewer for Ipad Content Viewer

    Hello

    How to activate or add "Library" and "Viewer" in the Adobe Ipad content viewer.

    Thank you

    If you are talking about the highest navigation at the bottom of the screen with icons bar, this feature is available only for customers of the company. If you are a corporate customer, you can specify icons customized for this navigation bar in the generator of spectator.

  • Problems w / Live ID and security for the family

    I decided to activate the parental control feature which required that I opened a new Windows Live ID.  After that and start Family Safety, I realized I misspelled the name on the email address in hotmail and went to correct him.  What I didn't realize was the popup of the parental control connection automatically fills the incorrect spelling and does not change.  Neither recognizes the password for incorrect spelling.  I tried to enter through hotmail using the incorrect spelling and said there was no such email address.  When I went to MS to register using this name, she said that it was already in use.  After many hours on it, I'm almost ready to reinstall everything.  Any suggestions?  Thank you

    Hello

    If this is the case, we recommend that you follow the steps in the article below from the solution. He will guide you on how to uninstall and install the parental control client so that the current credentials will be removed and allow you to enter a new e-mail address when signed.

    How to reset the ID of the Parent in parental controls after rename my account to Outlook.com

    Let us know the result later.

    Thank you.

  • Installation problem: other updates and security for Windows Vista (KB981852)

    In my history of update, this update shows as installation again and again "with success" since August, but he is still listed as an update to install.  This also applies to Windows Vista Service Pack 2 (kb948465), who has reportedly updated several times and still is listed as an update.

    Some info: I'm currently using Norton 360 - like Firewall and antivirus.  I also run Spyware Doc.  I was attacked last year, computer failed and I had to wipe my computer. (Assistance with this manufacturer.)  I'm not sure it solved the problem.  Since then, I have had problems with the computer running the browser to leave/run slowly, slowly, the problems to open programs.  This may be due to the loop of 'Windows update '?

    Thanks for any help.

    Hi Silk_Tea,

    First let's start with the question of the update of Windows. You can read the following article and try the steps and check whether you can solve the problem or not.

    Troubleshooting Windows Update or Microsoft Update when you are repeatedly offered an update

    http://support.Microsoft.com/kb/910339

    Hope this information is useful.

    Jeremy K
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

    If this post can help solve your problem, please click the 'Mark as answer' or 'Useful' at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • Oracle - SSMA.licence for Oracle to SQL Server Migration Assistant

    I can't download the license file, probably due to firewall, political settings, IE etc.

    Is there another way?

    Andy, one of the developers of my Microsoft sent using a contact of a forum address specialized - they reported an ongoing "maintenance" with the site and sent us the key directly.  This works.

    The real email address that he used is not in my mail to copy, but the friendly display name is 'SSMA for access' - I imagine that in a forum search will yield results.  If not, repost and I'll try and find.

    Congratulations to all,

    Mike

  • I forgot the password question and security for MSN.


    When msn has changed, I was on someone's account. Easy to get on and now the passwards guestions or security works. All contacts and e-mail required. hope im not ground

    Support MSN:
    http://support.Microsoft.com/kb/940784

  • INTERFACE to AUTHENTICATE USER and CONNECTION for Oracle Forms 10g...

    Hello Hello Silvere all the...

    I was wondering, is it possible to create a small interface where a user may connect by giving the user name and password to view the form... Run, a popup window by default when the user mode
    must give its user and password... is it possible... If Yes... Please show me how...

    And secondly, I have two 10gs oracle on separate computers, we're on laptop and we're on the home computer, both Versions are identical, and I create a BCSPROJECT user with 25-30 tables and
    views, I exported and imported from the laptop to my computer at home... My question is, is it POSSIBLE, when I connect my laptop to a WAN in my LAB of the DEPARTMENT and have access to my house
    computer base... ANY HELP will facilitate my work import and export again and still much easier...

    Hello

    You can try to create you're own login form.

    Please search in this forum, you will find the right answer.

  • Where to put the report server ip and port for the Siebel server?

    Hello

    Where to put the report server ip and port for the Siebel server? I have checked the document "Reports Siebel Guide" but does not know where is the configuration section ' ip address of the server and port ' for 'Oracle BI Publisher.

    Note: I have installed BI Publisher, now necessary to define the ip editor and siebel server port.

    Please help, thanks.

    Hello

    Communication between Siebel and BEEP coming through webservices. You must set the Siebel Outboundwebservice 'PublicReportService' address to address BI Publisher.

    Similarly, the address of the webservice Siebel Inbound 'BIPSiebelSecurityWS' will be used by BEEP setting under the security model of Siebel - Siebel end Webservice poin of connecting to Siebel EAI, data inorder of success authenticate the Siebel user to perform the tasks of report being initiate Siebel UI.

    Please go through the integration document attached to the thread "Re: ADVISE WEBCAST: BI Publisher 11g Configuration with Siebel", it is any integration Siebel with BEEP 11g steps. " But if you go through each step, there are details about why we do it. Through this way you can better understand the integration.

    I hope this helps.

    Thank you
    Maria

Maybe you are looking for