background image

Security Levels

9

Application-Level Security

The Breeze application has a built-in ACL-based security model that lets you assign users 
different permissions to access Breeze’s features. For example, you can control what users have 
permissions to publish presentations by adding them to the Account Authors group. You can also 
control which folders individual users can publish to. 

Breeze has four primary groups that grant users access to specific features in the Breeze system. By 
adding users to these groups, you can control what role a user has in your Breeze account. 

These groups are: 

Account Administrators

  Members of the Account Administrators group have access to all 

functions within the Breeze account. They can create and manage users, manage content, create 
and manage courses and create and manage meetings. Note that a member of the Account 
Administrators group will still need to be a member of the Account Authors group in order to 
publish content.

Account Authors

  Members of the Account Authors group have access to publishing features. 

They can publish content to the Breeze system, including using the Breeze plug-in for PowerPoint 
to publish presentations to Breeze.

Course Managers

  Members of the Course Managers group manage the Course Library 

including creating courses, incorporating course content from Account Authors, enrolling users, 
sending enrollee notifications, and setting up course reminders. They can also view content and 
course reports. 

Meeting Administrators

  Members of the Meeting Administrators are able to perform all 

functions associated with creating meetings including setting up a meeting, inviting participants, 
sending invitations and viewing reports.

In addition to adding users to groups to grant them rights to use features in the Breeze system, 
you can also grant them permissions to access specific folders, content, courses and meetings. For 
example, you can control whether or not a certain Account Author has permissions to publish to 
a specific folder.

For more information on using Breeze’s application-level security features, please refer to the 
Breeze presentation titled 

Setting Up Users, Groups, and Permissions

 at 

www.macromedia.com/go/

breeze_support

. Instructions for setting permissions are available in the About Permissions 

chapter of the Breeze Manager Help Guide. You can access the Breeze Manager Help Guide 
through the Breeze Manager web application. To access the Breeze Manager, choose Start > 
Programs > Macromedia > Macromedia Breeze 3 > Breeze Login Page.

Physical Security

Customers who store sensitive information on their servers should be aware of the physical 
security of their systems. Breeze relies on the safety of the host system against intruders, so servers 
should be kept secured where private and confidential data is at risk. Breeze is designed to take 
advantage of native environmental features like file system encryption where available if 
configured by the user.

Summary of Contents for BREEZE-SECURITY

Page 1: ...Security and Macromedia Breeze ...

Page 2: ...ictions including internationally Other product names logos designs titles words or phrases mentioned within this publication may be trademarks servicemarks or tradenames of Macromedia Inc or other entities and may be registered in certain jurisdictions including internationally This guide contains links to third party websites that are not under the control of Macromedia and Macromedia is not res...

Page 3: ... Overview 5 Security Levels 6 Infrastructure Security 6 Solutions for a Secure Infrastructure 7 Application Level Security 9 Physical Security 9 Best Practices 10 Recommended Security Resources and References 11 ...

Page 4: ...4 Contents ...

Page 5: ...anywhere anytime By its very nature any application that is run over a network especially the Internet has security risks associated with it Macromedia Breeze is no different However these security threats can be minimized if careful consideration is taken towards implementing a security design for Macromedia Breeze There are three levels of security that should be considered for Macromedia Breeze...

Page 6: ...channels for private communication These ports must be protected from outside users Breeze s design requires the environment to provide security for these communications It is highly recommended that sensitive ports should be placed behind a firewall that separates them from non trusted machines Below is a list of ports that are used by Macromedia Inbound ports from the internet 80 443 1935 Outbou...

Page 7: ...cure location Databases should be installed in the secure zone of your corporate intranet and never directly connected to the Internet Back up all data regularly and store copies in a secure off site location The Microsoft security web site contains information that applies to both securing SQL Server 2000 and the Breeze built in database www microsoft com sql techinfo administration 2000 security...

Page 8: ...tion Guide 4 Verify that Breeze is working After installing Breeze you should verify that Breeze is working properly both from the Internet and from your local network See the Breeze Installation Guide for more information 5 Test your firewall Now that you have your firewall installed and configured you should verify that your firewall is working correctly Test the firewall by attempting to use th...

Page 9: ...enrollee notifications and setting up course reminders They can also view content and course reports Meeting Administrators Members of the Meeting Administrators are able to perform all functions associated with creating meetings including setting up a meeting inviting participants sending invitations and viewing reports In addition to adding users to groups to grant them rights to use features in...

Page 10: ...atched with all security updates approved by Microsoft or other appropriate platform vendor Perform Database Security Updates Since your database may be another targeted component of the Breeze solution you need to check for database server security holes and apply required patches Like the operating system some of these issues are eliminated by a good firewall but you should also keep up to date ...

Page 11: ... information on this site also applies to the Breeze built in database engine Tools Freeware NMap www insecure org nmap index html A powerful port scanning program that tells you what ports a system is listening on It is freely available under the GNU Public License GPL Note Please note that the effectiveness of any security measure is determined by various factors including but not limited to the...

Page 12: ...12 Security and Macromedia Breeze ...

Reviews: