1What's New in This Release

What’s New in Siebel Security Guide, Siebel CRM 19.11 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 19.11 Update

Topic

Description

Changing the Anonymous User Password When a User Account is set to Anonymous User

Modified topic. A server restart is not required to change the anonymous user password.

About Installing Certificate Files

Modified topic. Outlines the typical steps to obtain and install certificate files.

Updating the Security Profile for Siebel Gateway

New topic. Describes how to update the security profile for Siebel Gateway using the (Siebel Management Console) safe mode user credentials.

Configuring the Siebel Management Console Safe Mode User

New topic. Describes how to configure the safe mode user in Siebel Management Console.

Configuring User Password Hashing

Modified topic. SiebelHash (the proprietary algorithm) is no longer supported for password hashing. The SHA-1 hashing algorithm is the only algorithm supported for password hashing in Siebel Enterprise.

Security Adapter Configuration When SSO is Enabled

New topic. Outlines security adapter configuration when SSO is enabled.

Network Zones and Firewalls

Recommended Network Topology

Modified topics. The Application Interface accesses the migration database when it is deployed for migration.

Removal of Siebel Application Interface Dependency on Oracle Database Client

New topic. As of Siebel CRM 19.11 Update, the Siebel Application Interface no longer requires the Oracle Database Client, which contains the Oracle LDAP Client.

MIME Sniffing

New topic. Describes how to enable Multipurpose Internet Mail Extension (MIME) sniffing, which is disabled by default in Siebel.

Disabling Command Line Logging

Obsolete topic. This topic has been removed from the guide. Command line logging is disabled by default in Siebel CRM 19.11 Update and later releases.

What’s New in Siebel Security Guide, Siebel CRM 19.7 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 19.7 Update

Topic

Description

Reverse Proxy Servers

Modified topic. For Siebel Innovation Pack 2017 and later releases, a reverse proxy server is required if you want to expose the Siebel app on the Internet.

What’s New in Siebel Security Guide, Siebel CRM 19.6 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 19.6 Update

Topic

Description

User Authentication for Secure System Access

Modified topic. When using multiple authentication mechanisms simultaneously (such as SSO and database authentication), one application interface per authentication mechanism must be installed and configured. This applies to all Siebel versions using application interface.

About Generating Keystore and Truststore Files

Modified topic. When creating certificates, the password for keystore and keypass should be the same. If you change the keystore password, then you must also change the keypass password.

Communications Encryption

About Configuring Encryption for Web Clients

Modified topics. As of Siebel CRM 19.6 update, RSA encryption is no longer supported for Mobile Web Client communications with Siebel Remote server. You can use SISNAPI with TLS encryption for Mobile Web Client communications with Siebel Remote server.

Industry Standards for Security

Installing Certificate Files on UNIX for Client Authentication

Setting Additional Parameters for Siebel Server TLS

About Configuring Encryption for Siebel Enterprise and Siebel Application Interface

Configuring Encryption for Mobile Web Client Synchronization

Security-Related Parameters in the Server Profile

Modified topics. As of Siebel CRM 19.6 update, TLS is supported for Siebel Remote and Mobile Web Client connections (RSA encryption is no longer supported). The format for the DockConnString parameter for the Mobile Web Client has also changed.

Managing the Key File Using the Key Database Manager

Modified topic. Describes how to run the Key Database Manager utility to add new encryption keys to the key file (keyfile.bin) and to change the key file password.

Set up Tasks for Standards-Based Web Single Sign-On

Modified topic. The Siebel Application Interface profile must also be configured if using Web Single Sign-On.

Configuring Siebel Migration Application for Web Single Sign-On

New topic. Describes how to set up Siebel Migration application for Web Single Sign-On.

Load Balancers

Modified topic. From Siebel Innovation Pack 2017 and Siebel CRM 2018 onwards, only native load balancing (through a gateway) is supported for Siebel Servers.

In addition, you can distribute incoming network traffic over multiple servers by using third-party HTTP load balancers that support session-based load balancing in front of a Siebel reverse proxy Web server.

Disabling Command Line Logging

New topic. If not already done so, Oracle recommends disabling command line logging.

What’s New in Siebel Security Guide, Siebel CRM 19.1 Update

No new features have been added to this guide for this release. This guide has been updated only to correct or remove obsolete product and component terms.

What’s New in Siebel Security Guide, Siebel CRM 18.12 Update

No new features have been added to this guide for this release. This guide has been updated to fix only bugs.

Table What’s New in Siebel Security Guide, Siebel CRM 18.12 Update

Topic

Description

Communications Encryption

Modified topic. A reverse proxy should be used if HTTPS is disabled.

About Importing Certificates into Keystore and Truststore

New topic. You must give your certificate an alias when importing it into keystore or truststore, and declare the same alias in the server.xml file.

About Implementing Federated Single Sign-On

Modified topic. This topic discusses what is required to integrate Siebel 17.x and 18.x with an external Web SSO solution.

Siebel Application Interface Profile Parameters

Modified topic. Lists the supported security profiles for Siebel 2018 and later releases.

Guidelines for Assigning Ports on Firewalls

Modified topic. Describes how to configure communication ports when setting up firewalls for your Siebel CRM implementation.

Network Zones and Firewalls

Recommended Network Topology

Modified topics. The figures in these topics have been updated.

What’s New in Siebel Security Guide, Siebel CRM 18.10 Update

No new features have been added to this guide for this release. This guide has been updated to fix only bugs.

Table What’s New in Siebel Security Guide, Siebel CRM 18.10 Update

Topic

Description

Modifying Keystore and Truststore Files

Modified topic. You must update the encrypted password in the applicationinterface.properties file, which is located in the application interface layer in the ai\applicationcontainer\webapps folder.

Deploying TLS for Siebel Enterprise or Siebel Server

Modified topic. On the Security Encryption Level or Type screen, select the SISNAPI to use TLS 1.2 option.

If you decide to change to a different Siebel Management Console, then you might need to redeploy the profile.

Configuring TLS Encryption for Siebel Application Interface

Modified topic. The applicationinterface.properties file is located in the application interface layer in the ai\applicationcontainer\webapps folder.

Enabling SSL Acceleration for Application Interface/Enabling HTTP

Modified topic. Disabling HTTPS has been corrected and combined with enabling SSL acceleration. This topic includes details on how to enable HTTP for the application interface.

What’s New in Siebel Security Guide, Siebel CRM 18.9 Update

No new features have been added to this guide for this release. This guide has been updated to fix only bugs.

Table What’s New in Siebel Security Guide, Siebel CRM 18.9 Update

Topic

Description

Enabling SSL Acceleration for Application Interface/Enabling HTTP

New topic. Describes how to configure SSL acceleration for communications between application interface traffic.

Enabling Support for the Translation of Port Numbers

Modified topic. Describes how to enable support for the translation of port numbers.

What’s New in Siebel Security Guide, Siebel 2018

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel 2018

Topic

Description

Disabling HTTPS

Modified topic. Disabling HTTPS has been corrected and combined with enabling SSL acceleration. For details on how to enable HTTP for the application interface, see Enabling SSL Acceleration for Application Interface/Enabling HTTP.