Previous Topic: Help Prevent Attacks

Next Topic: Protect Web Sites Against Cross-Site Scripting

How To Increase Web Agent Security Settings With Revised smdif File

To help prevent CSS attacks, a revised smdif file is available for the SiteMinder Policy Server 6x SP5 CR18 and subsequent versions. This revised smdif file has updated default Agent Configuration objects which use stricter parameter settings than the default Agent Configuration objects in the standard smdif file.

The updated file is installed in the following location:

/netegrity/siteminder/db/smdif/smpolicy-secure.smdif

To increase the security settings of the Web Agents with the revised smdif file, use the following process.

  1. Install the smpolicy-secure.smdif file on your Policy Servers.

    Note: For more information, see the SiteMinder Policy Server Installation Guide.

  2. Change the value in the ValidTargetDomain Web Agent configuration parameter.

More information:

Define Valid Target Domains