How Secure is the Bsafe/Enterprise Security PC-client (GUI)?
Any client/server application implementing a GUI will need to use some sort of server on the iSeries. In our case it’s the HTTP server. Here are some points worth noting: 1. Bsafe/Enterprise Security uses a dedicated HTTP instance configured to port 1967, 1983, 55555, 55556 or 55557 depending on your platform and operating system as opposed to port 80, which serves for public use. 2. The Bsafe/Enterprise Security instance is secured with a validation list. That means no public use is allowed. 3. The Bsafe/Enterprise Security instance can be additionally secured with SSL. 4. Bsafe/Enterprise Security uses it’s own additional level of security, like parameter encryption and sumcheck function. 5. Bsafe/Enterprise Security application doesn’t cache administrator passwords on the PC, as does Client Access. As soon as the administrator has logged on to the GUI the user and password used are discarded. 6. The Bsafe/Enterprise Security instance doesn’t allow Put functions, only Get. 7. To run