1.1 Security Recommendations for iFolder 3.x

The following table lists the iFolder server configuration settings that are security related or that impact the security of iFolder resources.

Parameter

Possible Values

Default Value

Recommended Value for Best Security

Port for server to LDAP server communications

iManager > Novell iFolder 3 > System > LDAP Settings Server Port

Port 636 (secure) or port 389 (insecure)

636, secure

636, secure

SSL for server to LDAP server communications

iManager > Novell iFolder 3 > System > LDAP Settings Port Is Secure

Select Yes to enable SSL; deselect Yes (No) to disable SSL

Yes, SSL enabled

Yes, SSL enabled

iFolder Proxy user

iManager > Novell iFolder 3 > System > LDAP Settings iFolder Proxy User

Autogenerated during the iFolder enterprise server configuration; can be modified thereafter

Autogenerated

Keep the autogenerated iFolder Proxy username; if you change it, make sure the username is different than the iFolder Admin user, equivalent iFolder Admin users, and other system users; and update the Proxy User password.

iFolder Proxy user password

iManager > Novell iFolder 3 > System > LDAP Settings Proxy User Password

User-specified

Autogenerated during initial configuration of the iFolder server

User-specified, using strong password practices

Web browser to iManager Server communications

HTTPS and Novell eDirectory™ authentication

HTTPS and eDirectory authentication

HTTPS and eDirectory authentication

iFolder Admin user

User-specified

User-specified administrator user

Special iFolder Admin user identity for managing iFolder services

Equivalent iFolder Admin users

User-specified

None

Users with limited administrator rights, such as for a specific iFolder server

Port for iManager to server communications

iManager > Novell iFolder 3 > (select any task to go to the iFolder Login page) > Port

Port 443 (secure) or port 80 (insecure)

443, secure

443, secure

SSL for iManager to server communications

iManager > Novell iFolder 3 > (select any task to go to the iFolder Login page) > Secure

Select Secure (secure) to use SSL; deselect Secure (insecure) to use unencrypted connections

Select Secure, SSL enabled

Select Secure, SSL enabled

Server to client communications

/opt/novell/ifolder3/web/web.config file

SimiasRequireSSL (Yes/No)

SimiasSSLPort (443/80)

SimiasRequireSSL = Yes

SimiasSSLPort = 443

SimiasRequireSSL = Yes

SimiasSSLPort = 443