Go to primary content
Oracle® Retail Home Oracle Retail Home Security Guide
Release 3.0.2
F16689-01
  Go To Table Of Contents
Contents

Previous
Previous
 
Next
Next
 

1 Overview

Oracle Retail Home is a portal-based application for the RGBU enterprise designed to provide a central view and entry point into a customer's Retail applications. The UI provides a tile-based dashboard highlighting important metrics and PKIs across RGBU applications. The dashboards are configured by a Retail Home administrator for each enterprise role.This chapter focuses on the secure deployment and configuration of the Retail Home client and services in a cloud environment. This includes deployment in both Weblogic Server and hosted container environments.

General Security Principles

The following principles are fundamental to using any application securely.

Keep Software Up to Date

Good security requires keeping up to date with the latest releases and patches of installed software. This document assumes Retail Home is up to date and being run in updated and supported environments.

Restrict Network Access to Critical Services

Retail Home uses REST services for communication between the client and server. Ensure that the server is deployed in a secure network environment and that all access goes through appropriate firewalls and authentication mechanisms. Additionally, be sure that other network resources used by the application, such as databases and other RGBU applications, are likewise deployed in secure environments.

Follow the Principle of Least Privilege

Retail Home restricts administrative duties to users assigned administrator roles. Ensure that these roles are not assigned except to users who need them.

When running in a hosted container, Retail Home must use a User ID that can read the wallet files with its credentials. The wallets should therefore be created as a non-root user, and that user should not have any extra permissions beyond what is needed to run the container.

Monitor System Activity

Monitoring the activity on the system is essential to maintaining security. Retail Home services log events to the host machine. These logs should be regularly audited.

Keep Up to Date on the Latest Security Information

The Retail Home software and documentation are regularly updated. Check this document with each update for revisions.