customer observed form Forensic Summary reports or audit log that proxy server's IP address are logged for every request
For standalone model of the system, you need to configure the file, config-clientenv.xml, in WEB-INF/CLASSES folder. The file defines the pointer and parameter for your application server. The settings are:
Default URL - the default URL for your application server and is used to post the password page. This page can also redirect the user to other bank actions, like maintenance, cancel actions, etc. This URL is used as a backup for the return URL location sent with the cookie.
<entry key="default">
<value>http://d3.passmarksecurity.com/largebank_client/
resultDispatcherAction.do</value>
</entry>
Note: This URL can be defined as part of the command token (request message) between the System and your application server; however, if the URL is missing in the API, then this default URL is used instead.
URL for Errors - the URL to go to upon error detection.
<entry key="error">
<value>http://d3.passmarksecurity.com/largebank_client/
Error.jsp</value>
</entry>
Reverse Proxies - if you are using a reverse proxy in the middle, the RSA server collects the IP addresses from the x-forwarded-for, rather than from ??RequestedRemoteAddr
<!-- list of trusted proxy IPs -->
<bean id="com.passmarksecurity.utils.HttpUtils" class="com.passmarksecurity.utils.HttpUtils">
<property name="trustedProxiList">
<list>
<value>127.0.0.1</value>
<value>xx.xx.xx.xx</value>
</list>
</property>
</bean>
For webservices model, add following entries in c-application-context.xml
<bean class="com.passmarksecurity.utils.RemoteAddrUtils" id="com.passmarksecurity.utils.RemoteAddrUtils">
<property name="trustedProxyList">
<list/>
</property>
</bean>
Related Articles
Raw Data counts and Task Result counts in Role Collector data runs are sometimes inconsistent in RSA Identity Governance &… 47Number of Views CSV Data Collectors of Data Source Type Database return incorrect result sets when joining multiple CSV files in RSA Ident… 62Number of Views How to access the aveksaServer.log and aveksaServerInfo.log files in RSA Identity Governance & Lifecycle 172Number of Views Job Level variables are sometimes lost when REST or SOAP nodes are configured to work in parallel with other nodes in RSA … 44Number of Views Security scan shows a possible denial of service vulnerability 31Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update RSA Authentication Manager 8.9 Patches and Hotfixes Readme RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide "No decryption codes were found in the zip file" error when decrypting RSA SecurID tokens