2021-12-10 Log4J Remote Lookup Vulnerability
iGrafx has released new versions of the Cloud and Datacenter solutions to address CVE-2021-44228 as described in https//unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/ as well as CVE-2021-45046, detailed in https://nvd.nist.gov/vuln/detail/CVE-2021-45046.
Antivirus scanning
Cloud-only antivirus scanning of external files: enable it, what happens on upload and download, and the known limitations.
Assign security roles
Create or adjust roles in the Grant/Veto editor and assign server and repository roles to users and groups.
Configuring authentication
Choose how the iGrafx platform recognizes signed-in users by setting a Spring security profile — the default login form, CAS, preauthentication, Kerberos, SAML2, or SiteMinder.
I want to enable Two or Multi-Factor Authentication for users
What is Two/Multi Factor Authentication
Restoring Administrator access to the iGrafx Platform
Your only iGrafx Platform Administrator left the company or is on a hiking trip in Patagonia? There are several legitimate reasons to restore administrative access to the iGrafx Platform.
Security roles and permissions
How access control works: server, repository, and item roles, grant and veto, additive rights, inheritance, and ownership.
SSL (HTTPS) configuration on Tomcat
Decide where to terminate SSL for the iGrafx platform — directly on Tomcat or at an Apache proxy — and configure HTTPS for each case.
Trust an external server's certificate
Import a TLS certificate into the platform's Java trust keystore so the platform trusts a mail, Automation, or directory server it connects to over TLS.