1What's New in This Release

What’s New in Siebel Security Guide, Siebel CRM 20.8 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 20.8 Update

Topic

Description

Installing Certificate Files on UNIX for Client Authentication (Step 10)

Configuring Encryption for Mobile Web Client Synchronization (Step 2)

Modified topics. As of Siebel CRM 20.8 Update, Oracle Database SE2 has replaced Oracle Database XE for the local database for Siebel Mobile Web Client. As a result, [LOCAL_XE] has changed to [LOCAL_SE]. For more information, see Siebel Installation Guide for the operating system you are using.

Reverse Proxy Servers

Procedure to Configure Reverse Proxy

Modified topics. A reverse proxy server is always required.

Changing Siebel Administrator Account Password

Changing Siebel Administrator Account Password on UNIX

Changing Siebel Administrator Account Password on Windows

Modified topics. Describes how to change the Siebel administrator account (SADMIN) password on UNIX and Windows.

Configuring Encryption and Search on Encrypted Data

Reencrypting Password Parameters in Siebel Gateway Registry

Modified topics. An encryption level below 128 bits is not supported in Siebel CRM.

What’s New in Siebel Security Guide, Siebel CRM 20.6 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 20.6 Update

Topic

Description

Supported TLS, SHA-2 and SHA-3

Communications and Data Encryption

Modified topics. EAI services via JDB standalone connect use TLS 1.2

About the Object Manager’s First Connection and LDAP User

New topic. To avoid performance issues when using LDAP or LDAP with SSO, you must have an SADMIN user created in the LDAP server.

Disabling Siebel REST API

New topic. Shows one method of disabling Siebel REST API data.

Configuring Siebel Migration Application for Web Single Sign-On

Modified topic. Examples have been provided for the following parameters: Host Name and Authentication Host.

About Siebel Session Warning Message

New topic. Describes when and why the Siebel Session warning message appears.

About Service Discovery Initiated by Trusted and Untrusted Sources in Siebel Application Interface

New topic. Describes the paths taken by trusted and untrusted requests.

Disabling REST Anonymous Authentication

New topic. Describes how to disable anonymous user for inbound REST calls. This task applies for Siebel CRM 17.x and later releases.

Reverse Proxy Servers

Modified topic. URL rewrite is at the reverse proxy level and is vendor specific. Configuring reverse proxy is a mandatory post installation task.

Procedure to Configure Reverse Proxy

Modified topic. As of Siebel CRM 20.5 Update, this is a mandatory post installation task. This procedure was previously called Enabling Support for the Translation of Port Numbers.

Assigning Rights to the Siebel Service Owner Account on Windows

Modified topic. The Siebel service owner account must be part of the Local Administrator Group (not the Local Users Group), otherwise the Siebel Server service will not start.

What’s New in Siebel Security GuideS, Siebel CRM 20.1 Update

No new features have been added to this guide for this release. This guide has been updated to reflect only product name changes.

What’s New in Siebel Security Guide, Siebel CRM 19.11 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 19.11 Update

Topic

Description

Changing the Anonymous User Password When a User Account is set to Anonymous User

Modified topic. A server restart is not required to change the anonymous user password.

About Installing Certificate Files

Modified topic. Outlines the typical steps to obtain and install certificate files.

Updating the Security Profile for Siebel Gateway

New topic. Describes how to update the security profile for Siebel Gateway using the (Siebel Management Console) safe mode user credentials.

Configuring the Siebel Management Console Safe Mode User

New topic. Describes how to configure the safe mode user in Siebel Management Console.

Configuring User Password Hashing

Modified topic. SiebelHash (the proprietary algorithm) is no longer supported for password hashing. The SHA-1 hashing algorithm is the only algorithm supported for password hashing in Siebel Enterprise.

Security Adapter Configuration When SSO is Enabled

New topic. Outlines security adapter configuration when SSO is enabled.

Network Zones and Firewalls

Recommended Network Topology

Modified topics. The Application Interface accesses the migration database when it is deployed for migration.

Removal of Siebel Application Interface Dependency on Oracle Database Client

New topic. As of Siebel CRM 19.11 Update, the Siebel Application Interface no longer requires the Oracle Database Client, which contains the Oracle LDAP Client.

MIME Sniffing

New topic. Describes how to enable Multipurpose Internet Mail Extension (MIME) sniffing, which is disabled by default in Siebel.

Disabling Command Line Logging

Obsolete topic. This topic has been removed from the guide. Command line logging is disabled by default in Siebel CRM 19.11 Update and later releases.

What’s New in Siebel Security Guide, Siebel CRM 19.7 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 19.7 Update

Topic

Description

Reverse Proxy Servers

Modified topic. For Siebel CRM 17.x and later releases, a reverse proxy server is required if you want to expose the Siebel app on the Internet or intranet.

What’s New in Siebel Security Guide, Siebel CRM 19.6 Update

The following information lists the changes in this revision of the documentation to support this release of the software.

Table What’s New in Siebel Security Guide, Siebel CRM 19.6 Update

Topic

Description

User Authentication for Secure System Access

Modified topic. When using multiple authentication mechanisms simultaneously (such as SSO and database authentication), one application interface per authentication mechanism must be installed and configured. This applies to all Siebel versions using application interface.

About Generating Keystore and Truststore Files

Modified topic. When creating certificates, the password for keystore and keypass should be the same. If you change the keystore password, then you must also change the keypass password.

Communications Encryption

About Configuring Encryption for Web Clients

Modified topics. As of Siebel CRM 19.6 Update, RSA encryption is no longer supported for Mobile Web Client communications with Siebel Remote server. You can use TLS encryption for Mobile Web Client communications with Siebel Remote server.

Industry Standards for Security

Installing Certificate Files on UNIX for Client Authentication

Setting Additional Parameters for Siebel Server TLS

About Configuring Encryption for Siebel Enterprise and Siebel Application Interface

Configuring Encryption for Mobile Web Client Synchronization

Security-Related Parameters in the Server Profile

Modified topics. As of Siebel CRM 19.6 Update, TLS is supported for Siebel Remote and Mobile Web Client connections (RSA encryption is no longer supported). The format for the DockConnString parameter for the Mobile Web Client has also changed.

Managing the Key File Using the Key Database Manager

Modified topic. Describes how to run the Key Database Manager utility to add new encryption keys to the key file (keyfile.bin) and to change the key file password.

Set up Tasks for Standards-Based Web Single Sign-On

Modified topic. The Siebel Application Interface profile must also be configured if using Web Single Sign-On.

Configuring Siebel Migration Application for Web Single Sign-On

New topic. Describes how to set up Siebel Migration application for Web Single Sign-On.

Load Balancers

Modified topic. From Siebel CRM 17.x and 18.x onwards, only native load balancing (through a gateway) is supported for Siebel Servers.

In addition, you can distribute incoming network traffic over multiple servers by using third-party HTTP load balancers that support session-based load balancing in front of a Siebel reverse proxy Web server.

Disabling Command Line Logging

New topic. If not already done so, Oracle recommends disabling command line logging.

What’s New in Siebel Security Guide, Siebel CRM 19.1 Update

No new features have been added to this guide for this release. This guide has been updated only to correct or remove obsolete product and component terms.