Skip Headers
Oracle® Fusion Middleware Enterprise Single Sign-On Suite Secure Deployment Guide
11g Release 2 (11.1.2.2)

Part Number E37694-01
Go to Documentation Home
Home
Go to Table of Contents
Contents
Go to Feedback page
Contact Us

Go to previous page
Previous
Go to next page
Next
PDF · Mobi · ePub

3 Securing Kiosk Manager

Kiosk Manager allows multiple users to use a single workstation in a kiosk environment, such as a medical office or a hospital, by allowing one or more "sub-sessions" within the context of a single Windows account session.

Oracle recommends that you utilize one or more of Kiosk Manager's session security features:

Provided that Logon Manager has been securely deployed and configured as described in , no extra work is necessary to secure Kiosk Manager. This is because the Kiosk Manager plug-in within Logon Manager uses Logons Manager's synchronization mechanism to interact with the repository, eliminating the need for a dedicated connection. Connection and data security is ensured by Logon Manager's built in encryption mechanisms, provided the repository connection is utilizing SSL.

To prevent a user from accessing the applications of another user within another Kiosk Manager session, you should follow industry standard best practices for securing a public end-user workstation. Specifically, the Windows account under which Kiosk Manager is to run should be stripped from all privileges except those that permit the launching and use of the required target applications so that the user cannot terminate Kiosk Manager or other users' applications.

You should also always set an inactivity timer which will lock the user's session after a short period of inactivity - for example, when the user walks away from the kiosk to tend to a patient.