Security Guide for Siebel eBusiness Applications > Introduction >

Revision History


Security Guide for Siebel eBusiness Applications

Version 7.5.3

Table 1.  Changes Made in Version 7.5.3
Topic
Revision
Added note about using Microsoft Crypto on different machines.
Added paragraph about limitations in the availability of the Password and Confirm Password fields when using external authentication.
Added paragraph about the implications of changing passwords at both the Enterprise and Component level.
Moved content about keyfile exchange here from a previously separate section.
New for 7.5.3: Added sections about configuring Secure Sockets Layer (SSL) encryption and authentication for Siebel Server and Siebel Web Server Extension.
Moved content about session cookies here from a previously separate section.
Removed content about the Standard Encryptor, which is no longer supported.
Added information about restrictions and requirements for encrypted field data and business component fields used for this purpose.
Updated section on requirements for using the security adapter for ADSI.
Updated note about authentication issues for multiple Siebel client types.
Updated description of PasswordAttributeType parameter.
Updated note about authentication issues for multiple Siebel client types.
Updated description of Siebel Server and Application Object Manager in a Web SSO environment.
Updated description of AllowAnonUsers parameter in application configuration file.
Updated note about password encryption utility.
Added optional procedure step for modifying the AnonPassword parameter in the eapps.cfg file.
Added information about how password encryption affects running Siebel Server components.
Updated note about password encryption utility.
Deleted obsolete note about duplicating Siebel user ID data in a directory.
Updated description of effect of SecureBrowse parameter.
Enhanced section to specify some requirements specific to ADSI, and to document using the parameter PasswordExpireWarnDays.
Added note about relationship of data visibility and active position.
Added note about divisions and access groups.
Added illustrations pertaining to data models for User List and Access Group parties.
Added statement about promoting a contact to a user.
Added information about the function of S_PARTY_PER and S_PARTY_REL tables.
In subsection on manager access control, deleted an incorrect note.
Enhanced subsection on manager access control, primarily to add information about Manager List Mode.
Added information about the Employee Organization field for the Employee business component.
Updated description of Organization Type field.
Revised for 7.5.3: Mentioned that default tab layouts are associated with responsibilities.
Added note about requirement for restarting Application Object Manager after modifying visibility or responsibility settings.
Added note about associating organizations with responsibilities.
Added information about the view property Visibility Applet.
Deleted incorrect note in subsection on manager access control.
Updated description of Cascade button.
New for 7.5.3: Added new subsection about managing default tab layouts through responsibilities.
Revised for 7.5.3: Updated section to remove references to managing tab layouts through roles. Default tab layouts are now managed through responsibilities.
Added information about drilldown visibility and visibility rules.
Updated discussion of authentication requirements for using Server Manager.
Added reference to Release Notes for responsibilities provided in seed data.

Additional Changes

January 2003 Bookshelf

Table 2.  Changes Made in Version 7.5, Rev. A for January 2003 Bookshelf
Topic
Revision
New section that lists outside resources for security-related issues. Includes books and Web sites.
New section that describes security issues for Web server image caching.
New section that describes how Web browser security settings impact Siebel applications.
New section on securing communications with Siebel Reports Server.
New section about how password expiration is handled by an external LDAP directory or Active Directory.
New section on how to configure drilldown visibility within a business object or between business objects.
New section on how to monitor log files, usage records, and statistics pages to troubleshoot potential security problems.
Added clarification about the anonymous user requirement for applications that do not allow unregistered users.
Added information about the LoginView parameter and how it relates to the AllowAnonUsers parameter.
Added information about setting configuration file parameters for the Dedicated Web Client and Mobile Web Client.
Added information about how to add new views to responsibilities if you are using a Dedicated Web Client or Mobile Web Client.
Added troubleshooting information for "Web Authentication Failed" error messages.
Updated procedure for upgrading to the Siebel Strong Encryption Package.


 Security Guide for Siebel eBusiness Applications 
 Published: 23 June 2003