Alliance Access 7.1
On Alliance Web Platform
Security Guide
This security guide describes the security-related features of Alliance Access. It outlines the aspects of security that anAlliance Security Officer must consider to protect Alliance Access and its operating environment from security threats. Italso describes the controls that an Alliance Security Officer can implement, such as common backup strategies to protectagainst system failure.This security guide is written specifically for an Alliance Security Officer, and anyone who is responsible for operationaland computer security will find its contents useful.27 March 2015
Connectivity
Table of Contents
.Preface
.............................................................................................................................................................................4
1Training for SWIFT Users
2Security of Alliance Access
....................................................................................................................... 6
2.1Description of an Alliance Security Officer
............................................................................................ 6
2.2Tasks of an Alliance Security Officer (LSO and RSO)
........................................................................ 6
2.3Preparing for a Security Role
.................................................................................................................. 7
3Security Aspects to Consider
3.1Terms and Definitions
3.2Overview of the Alliance Web Platform
3.3Security Features of Alliance Access
3.4Customer Security Controls
3.5Addressing Additional Vulnerabilities in Web-Based Applications
3.6Security on AIX, Linux, or Solaris Systems
3.7Security on Windows Systems
3.8Alliance Access Operating Modes
3.9Offline Maintenance Utilities
.................................................................................................................. 35
4Installation, Upgrade, and Licensing
................................................................................................... 37
4.1What Is Secure Channel?
4.2Alliance Initialisation Password
4.3Alliance Master Password
4.4Sign-on Time Limits
................................................................................................................................ 39
5Configuration and Security Parameters
............................................................................................. 41
5.1Classes of Configuration Parameters
5.2Security Parameters
6User Management
6.1Management of User Accounts
6.2Alliance Password Modes
6.3Password Renewal
6.4Resetting User Passwords
6.5Defining Alliance Access Operators
6.6Support for Service Bureau
6.7Profiles in a Sample Service Bureau
6.8Operators and Users of Alliance Access
6.9Using Operator Profiles
6.10Definition of Units and Restrict Functions
........................................................................................... 80
6.11Authentication Server Groups and One-Time Passwords
................................................................ 81
6.12Password Controls
Alliance Access 7.1 on Alliance Web Platform2Security Guide
7Default Operator Profiles
........................................................................................................................... 84
7.1Overview of Default Operator Profiles
................................................................................................. 84
7.2Access Control Application
.................................................................................................................... 86
7.3Application Interface Application
........................................................................................................... 87
7.4Calendar Application
............................................................................................................................... 90
7.5Correspondent Information File Application
........................................................................................ 90
7.6CRnet Interface Application
................................................................................................................... 92
7.7Event Log
................................................................................................................................................. 92
7.8Integ. Platform Application
..................................................................................................................... 93
7.9Message Approval Application
.............................................................................................................. 94
7.10Message Creation Application
.............................................................................................................. 96
7.12Message File Application
7.13Monitoring Application
7.14Relationship Management Application
7.15Reporting Application
7.16Routing Application
7.17Security Definition Application
............................................................................................................. 108
7.18SWIFT Interface Application
7.19SWIFT Support Application
7.20SWIFTNet Interface Application
7.21SWIFTNet Support Application
7.22System Management Application
8Securing System Resources
................................................................................................................. 117
8.1Backup Strategies
................................................................................................................................. 117
8.2Software and Data Integrity
8.3Software Integrity
8.4Data Integrity Checking
8.5Encryption of Secret Data
8.6Minimising the Impact of System Failure
9Controlling Message Processing
9.1Message Preparation Controls
9.2Other Message Processing Controls
9.3Application Interface Controls
9.4CRnet Interface Controls
.Legal Notices
.............................................................................................................................................................144
Table of Contents27 March 20153
Preface
Purpose of the document
This Security Guide provides:•a description of all of the security-related features of Alliance Access and Alliance WebPlatform•a reference document for Alliance Security Officers, who are involved with or responsible foroperational and computer securityFor security details of Alliance Workstation, refer to the Security Guide for Alliance Workstation.
Audience
This document is aimed at those personnel who influence either the security policies or theimplementation and management of security controls within their organisation or business.
Significant changes from the previous version
This document has been reorganised to emphasise the following:•specific information regarding the Alliance Web Platform•tasks and responsibilities of the Alliance Security Officer
Feedback on This Document
This is a new version of this document and your feedback is welcome. Please provide anyfeedback by means of SWIFT Support.
Alliance Access 7.1 on Alliance Web Platform4Security Guide
1Training for SWIFT Users
Overview
SWIFT Training is your first point of contact for learning how to use SWIFT standards, products,and services accurately and effectively. Training is available to all SWIFT users.
Related courses
SWIFT recommends the following Alliance Access courses. For full descriptions, consult theTraining pages on swift.com:•Operating Alliance Access and Entry•Managing Alliance Access and Entry•Deploying Alliance Access•Optimising Your Alliance Resilience•Alliance - Disaster Recovery•SWIFT Audit GuidelinesTo view the full training portfolio that SWIFT offers, see www.swift.com > Training > Trainingtopics.
How to register for training
To register for SWIFT Training, visit www.swift.com/training. You must have a swift.com username and password to register for SWIFT Training. If you do not have a swift.com user nameand password, register at swift.com. Instructions will be sent to you by e-mail.
Training for SWIFT Users27 March 20155
2Security of Alliance Access
Introduction
This section describes the security aspects that an Alliance Security Officer must consider whenselecting the security controls to implement to protect Alliance Access and its environment fromsecurity threats.
2.1Description of an Alliance Security Officer
Overview
An Alliance Security Officer has a key role in configuring and managing the security functionswithin Alliance Access. The Alliance Security Officer must work with auditors, SWIFTNetSecurity Officers, project teams, system administrators, and anyone else within the institutionwho is responsible for ensuring that the environment in which the business and applicationsoperate is secure and protected against security threats.There are two security officers, the left security officer (LSO) and the right security officer(RSO). Together they control which users can sign on to Alliance Access and what those usersare permitted to do.SWIFT has predefined the actions that Alliance Security Officers can perform within AllianceAccess. You cannot change those pre-defined entitlements and permissions.In a service bureau and other multi-BIC environments, with the correct security parameter set,the left security officer and right security officer can create "local" security officers for each of theSWIFT institutions, which effectively delegates part of the security officers' authority.
2.2Tasks of an Alliance Security Officer (LSO andRSO)
Overview
Both Alliance Security Officers (LSO and RSO) perform the following tasks:•Obtain the licence and passwords for Alliance Access from the Secure Channel. For moreinformation, refer to "What Is Secure Channel?" on page 37.•Enter their password during the installation, upgrade or relicensing of the Alliance Accesssoftware, and also in the creation of user accounts in Alliance Access. For more information,refer to "Alliance Initialisation Password" on page 37.•Reset the password of the other Alliance Security Officer, if required and permitted. For moreinformation, refer to "Alliance Master Password" on page 38.•Manage operator profiles. An operator profile is a set of permissions that you can assign to aspecific type of user. For more information, refer to "Defining Alliance Access Operators" onpage 71.•Manage user accounts, passwords, and sign-ons. You can delegate this task within yourinstitution, if required. For more information, refer to "Management of User Accounts" onpage 69.
Alliance Access 7.1 on Alliance Web Platform6Security Guide
•Configure security parameters and the use of passwords. For more information, refer to"Classes of Security Parameters" on page 56.•Approve routing schemas. A routing schema controls how messages are handled and routedwithin Alliance Access. For more information, refer to "Routing Application" on page 107.•Work with the Operating System Administrator and Alliance Administrator to ensure that thesystem on which Alliance Access runs is secure and resilient. For more information, refer to"Security Aspects to Consider" on page 8.•Monitor the activities of the users of Alliance Access for any security-related risks or threats.For more information, depending on your operating system, refer to "Security on AIX, Linux,or Solaris Systems" on page 21 or "Security on Windows Systems" on page 30.Security officers are not entitled to perform operational duties, such as sending and receivingmessages. This ensures that operational and security-related duties are kept strictly separate.This guide provides an overview of the tasks that an Alliance Security Officer performs.
2.3Preparing for a Security Role
Knowledge Required
If you are new to the role of Alliance Security Officer, then the following guides provide usefulbackground information about the tasks that you perform on Alliance Access:•
Alliance Access Administration Guide
•
Alliance Access Configuration Guide
•
SWIFTNet Certificate Administration Guide
•
SWIFTNet Service Description
•
Alliance Access Service Description
•
Hardware Security Module Operations Guide
Related Training
If you are new to the role of Alliance Security Officer, then you may be interested in attendingthe following training courses:•Managing Alliance Web Platform•Managing Alliance Access•PKI for SWIFTNet Security OfficersFor a complete list of SWIFT's training offerings, go to http://www.swift.com/training/index.page?lang=en.
Security of Alliance Access27 March 20157
3Security Aspects to Consider
3.1Terms and Definitions
Throughout this guide, several special terms are used to describe the different aspects ofsecurity. To avoid possible confusion, those terms are defined here. They describe the basicrequirements for information security, and for the security of systems that process information.
Security termDefinitionIntegrity
Relates to information that may be relied upon to be consistent, complete,accurate, valid, and useful. For user data, this implies that no information maybe altered by unauthorised persons. For system data, this term implies that nounauthorised changes are made to programs, scripts, configuration files, logfiles, and so on, thus ensuring the integrity of the complete system.
Confidentiality
Refers to information that is disclosed only to authorised persons, at authorisedlocations, and at authorised times. For user data, this implies that confidentialinformation is not disclosed to unauthorised third parties. For system data,confidentiality refers to the secure protection of sensitive operational data, suchas password files and encryption keys.
Availability
Implies that both the information and the systems used to process, display, printand so on that information be both accessible and usable as and when required.For user data, this means that information must be processed on time, andstored in the correct place to be available to authorised users. The availability(and integrity) of valid system and configuration data has a direct influence onservice availability. Also, all of the necessary components of a system must beworking to ensure service availability.
Auditability
Every user of a system must be held accountable for his or her own activities.This implies that all actions can be
audited
. That means that all relevant actionscan be monitored, and that any one action can be uniquely attributed to aknown user, at a particular time and date. Similarly, a computer system must beheld responsible for automated actions, and log files maintained accordingly.
When configuring and administering information systems, the following principles assist greatlyin ensuring the basis of a security system:
Security principleDefinitionNeed-To-Know
Information and resources must only be made available strictly on a need-to-know basis.Alliance Access ensures that operators only have access to the information,files, and system resources necessary for their defined tasks. Access to othersystem functions is barred.
Least Privilege
Users must only be granted the minimum level of privileges required for them toperform their normal tasks.Alliance Access ensures that operator privileges are controlled in a way whichallows all privileges to be tailored to individual needs.
Alliance Access 7.1 on Alliance Web Platform8Security Guide
Security principleDefinitionAccountability
All user activity, such as access attempts and command usage, must be loggedand attributed to a known user.Ideally, system activity such as information about processes, network events,and system errors, must also be logged.Alliance Access provides a comprehensive event logging facility which logs alloperator and system events that occur within Alliance Access.On an exceptional basis, for example, in an emergency, normally inaccessibleinformation may be made available, or higher privileges may be granted tousers but always in a controlled manner.It is important to realise that the implementation of these principles may createrestrictions for users in the use of their systems. However, these restrictions arenecessary to protect against accidental damage caused by inexperienced staff,as well as to protect against malicious attacks.
3.2Overview of the Alliance Web Platform
Overview
This section provides an overview of the functionality and available versions of the Alliance WebPlatform.
3.2.1Alliance Web Platform
Description
The Alliance Web Platform is the framework that hosts the browser-based graphical userinterfaces (GUIs) of the Alliance portfolio and that replaces Alliance Workstation. It offers aconsistent end-user interface to the functionality managed by the Alliance Access servers.Alliance Web Platform runs in an application server environment, enabling centraliseddeployment of the software.
Versions
The Alliance Web Platform is delivered in two versions:•One version requires a web application server (IBM WebSphere Application Server) that canbe configured in a cluster to provide robust operational capacity, such as load balancing andresilience mechanisms.•The other version (Alliance Web Platform Server-Embedded) includes the application serverthat the software requires.In addition, the Alliance Web Platform enables access to the Browse services provided by third-party service providers (typically market infrastructures) on SWIFTNet.For more information about the Alliance Web Platform, see www.swift.com > Products &services > Web Platform, Alliance > Details.
3.2.2Alliance Web Platform as GUI for Alliance Servers
The Alliance Web Platform provides a common set of services to all GUI applications(packages) deployed in it. The packages deployed in the Alliance Web Platform include:•Configuration
Security Aspects to Consider27 March 20159
•Message Management•Monitoring•Relationship ManagementAn Alliance Web Platform package is accessed by users using their browser. The Alliance WebPlatform then interacts with the Alliance Access Server to provide the services requested by theuser.
Overview of Alliance Web Platform
D 1 3 5 0 0 0 3
BrowserWebPageAlliance Web PlatformApplication ServerJDBCPlatformAlliance Web PlatformAdministration PackageGUIApplication(Package)Alliance IntegratorAlliance GatewayAllianceAccess/EntryHTTPS
Platform DB
Note
Alliance Integrator and Alliance Gateway are not discussed in this document. Referto the respective product documentation for more details on these products.The Alliance Web Platform manages its own data store (platform database) to maintainconfiguration and monitoring data. Management of the configuration data of the Alliance WebPlatform and basic GUI administration functions are performed by means of the Alliance WebPlatform Administration package. The Alliance Web Platform Administration package isaccessed in the same way as any other package that is registered for the Alliance WebPlatform.
Alliance Access 7.1 on Alliance Web Platform10Security Guide
Overview of Alliance Access
FINInterActFileActSWIFTNetNetworkConnectionAlliance GatewayCommunicationsSoftwareAlliance Access PackagesConfigurationMonitoringMessage ManagementRelationship ManagementMessagingSoftwareDesktopAccessApplicationIntegrationWeb ServicesADKFile TransferMQSOAPDirect FileActCAS Web PlatformWorkstation
D 0 5 4 0 2 0 9
Back-OfficeIntegrationApplicationInternet Explorer
The following table outlines the entities that are contained in each of the Alliance Access GUIapplications (packages), as shown in the preceding graphic. For more information about defaultoperator profiles, entitlements and entities, see "Default Operator Profiles" on page 84.
Alliance Access GUI Applications (Packages)EntitiesConfigurationMonitoringMessageManagementRelationshipManagement
Access Control
✓
ApplicationInterface
✓ ✓ ✓
Calendar
✓
CorrespondentInformation File
✓
Event Log
✓ ✓
Security Aspects to Consider27 March 201511
Message Approval
✓
Message Creation
✓
MessageModification
✓
Message File
✓
Monitoring
✓
RelationshipManagement
✓
Routing
✓
Security Definition
✓
SWIFT Interface
✓ ✓
SWIFT Support
✓
SWIFTNetInterface
✓ ✓
SWIFTNet Support
✓
SystemManagement
✓ ✓
3.3Security Features of Alliance Access
3.3.1Authentication and Session
The Alliance Access server authenticates the users who connect to Alliance Access through theAlliance Web Platform. Administrators use the Alliance Web Platform Administration packageare authenticated against the user registry of the application server.Whenever the browser connects to Alliance Web Platform to perform a logon, a new session isalways established. This session is identified by a session ID generated by the server andreturned to the browser in the form of a secure cookie.To authenticate a user, the Alliance Web Platform performs the validation of the user credentialsagainst the Alliance Access Server. Upon successful validation, the Alliance Web Platformgenerates a user context identifier that is returned to the browser:•
Server Side
Alliance Web Platform is authenticated using an SSL server certificate, which can be signedby a trusted third party. SWIFT recommends using a recognised Certification Authority (CA)or a Certification Authority under the customer's control.•
Client Side
By default, an end user is authenticated towards the back-end Alliance Access Server usinga UID or password. SWIFT recommends the selection of a strong password policy followingindustry best practices. As already mentioned, the authentication is performed at the level ofthe target hosts (for example, Alliance Access, Alliance Gateway).In addition, for some Alliance products, SWIFT provides the option to use a One-Time-Password (OTP) using hardware tokens or authentication by means of an LDAP server.These options should be considered when using Alliance in a non-trusted environment.
Alliance Access 7.1 on Alliance Web Platform12Security Guide
The generated user context identifier is stored in the memory of the browser, and everyincoming request from the browser carries this identifier as a parameter of every request to theapplication server. The Alliance Web Platform verifies the user context identifier for every userrequest.
3.3.2Server Authentication and Confidentiality
All network traffic is encrypted using Secure Socket Layer (SSL) one-way authentication. Thisfeature ensures confidentiality on the network and protects against replay attacks, which is aform of network attack in which a valid data transmission is maliciously or fraudulently repeatedor delayed.The communication between an Alliance Web Platform package and the server is secured bySecure Socket Layer, ensuring the confidentiality of the operator user name and passwordexchanged between the Alliance Web Platform and the Alliance server.HTTPS, using Secure Socket Layer, is enforced for the communication between the browserand Alliance Web Platform. The browser is able to authenticate the application server with thecertificate deployed on the application server.
Note
To avoid SSLv3 (CVE-2014-3566 - POODLE) vulnerability, SWIFT recommendsthat you disable SSL encryption in your browser settings to access SWIFTproducts and services. By doing so, you will eliminate any residual risk that thisSSLv3 vulnerability may cause.Before disabling SSLv3, SWIFT recommends that you test the compatibility of TLSwith all of your various Browse services. For information on configuring the browserto use TLS, see Web browser settings in the
Alliance Web Platform Installation Guide
for AIX, Linux, Oracle Solaris, or Windows. If you encounter difficulties
reaching a Browse service, consult with the relevant service provider.SWIFT will cease to accept SSLv3 encryption for browser connections in early2015.
3.3.3Four-Eyes Control and Approval
Alliance products provide a large panel of authorisations options, such as the segregation ofroles, units, and duties; four-eyes control over critical security operations; and six-eyes controlfor the sending of messages (creation, verification, and authorisation) to manage userprivileges. These features allow applying the least-privilege principle and thus reinforcing theapplication security.The authorisations are not enforced at the Alliance Web Platform level, but rather at the back-end server level, where the processes that the web client communicates with reside (the sameas for authentication). This architecture minimises the impact of an attack on the Alliance WebPlatform by mitigating the risk of the user authorisations mechanism.
Security Aspects to Consider27 March 201513
3.3.4Summary of Security Officer Tasks and Alliance AccessFeatures
Summary
The following table summarises the tasks assigned to Alliance Security Officers and the relatedfeatures in Alliance Access.
Key Security Features of Alliance AccessAlliance SecurityOfficer TaskAuthentication andSessionServer Authenticationand ConfidentialityFour-Eyes Control andApproval
Obtain the license andpasswords for AllianceAccess from the SecureChannel
✓ ✓
Enter a password duringthe installation, upgradeor relicensing of theAlliance Accesssoftware, and also in thecreation of useraccounts in AllianceAccess
✓ ✓ ✓
Reset the password ofthe other AllianceSecurity Officer, ifrequired and permitted
✓
Manage operatorprofiles
✓
✓
Manage user accounts,passwords and sign-ons
✓
Configure securityparameters and the useof passwords
✓
Approve routingschemas
✓
Along with theOperating SystemAdministrator andAlliance Administrator,ensure that the systemon which AllianceAccess runs is secureand resilient
✓ ✓ ✓
Monitor the activities ofthe users of AllianceAccess for any security-related risks or threats
✓
✓
Alliance Access 7.1 on Alliance Web Platform14Security Guide
3.4Customer Security Controls
This section lists the minimum set of controls that SWIFT recommends for customerimplementation and explains the changes in the security practices linked to the migration fromexisting Alliance non-web clients to the Alliance Web Platform.Alliance Web Platform is designed to be implemented in a secure customer environment. Thisassumes that a minimum set of controls is implemented at the customer site, as outlined in"Recommendations" on page 17.The physical and logical security of the computer and the network that is used to run theAlliance product is a key element in maintaining a secure environment. The security of theinfrastructure is not specific to Alliance Web Platform, but is valid for any critical businessapplication at the customer premises.
3.4.1Customer Infrastructure
Customers must consider the following controls at the infrastructure level:•
Secure Server Environment
–Physically and logically protect the server running Alliance products. –Ensure that the operating system on which each Alliance product runs is appropriatelyconfigured according to the vendor recommendations, and only install authorised andrequired software / applications. For more information, see the OS Levels and PatchesBaseline document, which is available at www.swift.com, and the Release Letter for
Alliance Access. –Ensure that the application server (that is, IBM WebSphere) is appropriately configuredbased on the recommendation by the vendor. –Ensure that all system software is up-to-date with the latest security patches.•
Secure Client Environment
–Manage firewall and web content filtering components facing the Internet. The firewallmust not allow any incoming connections towards the PC used to access Alliance WebPlatform. –The client host infrastructure should feature up-to-date anti-virus, anti-malware services,and associated up-to-date databases to protect PC from infection. –Ensure that PC components are up-to-date with the latest security patches. –Physically protect the PC used to access the Alliance products. Ensure that onlyauthorised persons have physical access to the PC.
3.4.2Secure Browsing
From a practices point of view, the customer must ensure that users are following securebrowsing practices, such as:•Segregated general browsing from Alliance Web Platform either by using different Windowsaccounts or, ideally, by using different PCs.
Security Aspects to Consider27 March 201515
•Not browsing sites other than Alliance Web Platform when an Alliance session is open.•Never following links in e-mails that would pretend to direct the user to Alliance WebPlatform.•Security awareness for Alliance end users, which allows for the development andmaintenance of secure-minded behaviour in the user base and which ensures that users arefully aware of threats related to browsing (such as ensuring that PC user sessions cannot betaken over).
3.4.3Network Segregation
Alliance product design provides the flexibility for customer to implement adequate networksegregation in line with best practices. Alliance Web Platform can be implemented in a De-Militarised Zone (DMZ). This allows for the implementation of strong firewall rules:•between the end-user browser and Alliance Web Platform allowing only HTTPS•between Alliance Web Platform and Alliance Gateway packages allowing only SWIFTTransport Layer (SwTL, a TCP-based SWIFT proprietary transport protocol) based onSecure Socket Layer (SSL)•between Alliance Web Platform and Alliance Access or Access Integrator packages allowingonly SWIFT Transport Layer (SwTL) based on SSL or SOAP over HTTPS in the context ofWeb services.In addition, all management services must not be accessible by means of un-trusted networks.
3.4.4Front-End Reverse Proxy
Alliance Web Platform is running on top of several third-party products. Over time, thoseproducts can have vulnerabilities that are exploitable by attackers.Hence, these require the regular installation of new patches or upgrades. Although SWIFT hasdeveloped Alliance Web Platform following third-party specifications, the installation of a patchon system running critical application must be evaluated and tested by customers. During thiselapsed time, the system could be considered at risk.An industry practice against such a common issue is the implementation of a reverse proxy oran application firewall as a front end to Alliance Web Platform. Alliance Web Platform supportssuch a configuration (that is, a configuration type 2 cluster with an HTTP server front end).
3.4.5Account Management and Segregation of Duties
The least privilege and segregation of duties principles must always be considered whendefining user profiles. This is not specific to Alliance Web Platform, because those controls areenforced at the Alliance server level.For example, for Alliance Access, SWIFT recommends implementing "Segregation of Duties"between users authorised to create messages and users authorised to approve messages (thatis, messages to be sent over SWIFTNet).In addition, all actions performed by means of Alliance Web Platform must be adequatelymonitored to maintain efficient accountability. This can be performed using the monitoring andlogging features provided by the different Alliance Access Servers.
Alliance Access 7.1 on Alliance Web Platform16Security Guide
3.4.6Migrating to Alliance Web Platform
The only change of security practices in the customer's SWIFT environment can be linked to thefact that, unlike non-web-client architecture, users can access Alliance interfaces from anydesktop with a browser installed.If non-web-client software has been used as a control by your organisation, networksegregation and firewalls can achieve the same security objective by allowing only dedicatedPCs to access Alliance Web Platform.
3.4.7Alliance Web Platform in a Non-Secure Environment
Alliance products are designed to be implemented in a secure customer environment, asoutlined in "Recommendations" on page 17.When Alliance Web Platform is directly exposed to an insecure network such as the Internet,the security risk is considered higher due to an increase in likelihood of existing attacks. This isinherent in the usage of uncontrolled networks such as the Internet. Even though the productallows such a deployment; this set-up is not recommended by SWIFT.If you decide to operate Alliance Web Platform in such a configuration, then the followingadditional controls are strongly recommended:•
Segregated Servers
In addition to the network segregation, SWIFT recommends that the Alliance Web Platformused by external users is not also used for internal access. This limits the potential impact ofsuccessful attacks on the externally exposed system. For example, packages developed tomanage Alliance Gateway, Access, or Integrator must not be exposed to an insecurenetwork.•
Virtual Private Network
In addition, Virtual Private Network (VPN) using IPSec technology can always be used, whichcreates an additional layer of security between the client and the server premises. In thiscontext, Alliance Web Platform is no longer directly exposed to a non-trusted network.
3.4.8Recommendations
This section lists typical SWIFT recommendations for Alliance users. However, this is not anexhaustive list, and Alliance Web Platform users should implement complementary securitymeasures where and when justified by their own security risk analysis.SWIFT recommends that you:•Install and manage a firewall facing the Internet, that does not accept any incomingconnections towards the PCs where you run the browser accessing Alliance Web Platform.•Install and manage a local firewall on each PC, as well as anti-virus/anti-malware that iscontinuously active and kept up-to-date with the latest threats.•Restrict outgoing traffic of the PC to business-critical sites (in addition to legitimate sitesrequired for software updates).•Ensure that the PC used for accessing Alliance is physically and logically accessible only bythe person entitled to access this PC.
Security Aspects to Consider27 March 201517
•Ensure that only authorised and necessary software is installed on the PC used to accessAlliance products.•Ensure that all of the software running on the PC is regularly updated and patched, includingWindows, internet browser, and any additional features (called plug-ins).•Reserve PCs to accessing internal sites of the same criticality as Alliance, and only accessthese sites from these PCs.•Set up end-user management practices that ensure that only authorised end users arecreated, and that the list of authorised end users is kept up-to-date as users change roles orleave the company.•Use entitlement management practices that ensure that end users are only granted access toAlliance functions on a "need to know" or "need to have" principle.•Always restart your browser instance before and after accessing the Alliance Web Platformapplication.On the other hand, SWIFT recommends that you:•Do not browse the Internet from the PC where you access critical Alliance functionality.•Do not browse any other site at the time that you access the Alliance Web Platformapplication, up until you have ended your session.•Never write down any passwords.•Never communicate your password to anyone.•Do not follow a hyperlink contained in an e-mail, even if that URL seems perfectly valid froma business perspective. Instead, once you have confirmed the business need to visit that site,re- type the URL within the browser as it was visible in the mail. Such phishing attacks maylead to rogue sites that can steal information or infect your PC.•Never accept a pop-up asking that you to download and install executables.•Do not grant the administrator and message approval roles to the same individuals.
3.5Addressing Additional Vulnerabilities in Web-Based Applications
When deploying any web-based application in the institutions, customers must be aware of thevulnerabilities of this technology and how to address them.This section gives an overview of the typical threats and attacks for web-based applications andsummarises the security features and controls available to mitigate security threats and attackslikelihood and to limit the impact of successful attacks.
Alliance Access 7.1 on Alliance Web Platform18Security Guide
3.5.1Threats and Attacks
The deployment of Alliance Web Platform does not introduce new threats. However, any web-based application is exposed to attacks, and those attacks must be considered when AllianceWeb Platform is deployed by a customer. The attacks that must be considered are the following:•end-user impersonations that affect message confidentiality and integrity•Alliance Web Platform host attacks due to third-party software weaknesses (because it isaccessible to a larger community, that is, the Internet)•Denial of Service (DoS) attacks that affect service availability.Currently, the most popular hacker techniques to achieve impersonation are:•
Spyware
This technique is based on the installation of hardware or software on the client system to getcredentials to perform further attacks.•
Phishing
Creating a replica of an existing "login page" to fool a user to capture financial information, orcredential data (passwords and so on). Phishing is the term coined by hackers who imitatelegitimate companies in e-mails to entice people to share static passwords or credit-cardnumbers.•
Sniffing
The ability to view network traffic and to steal credentials, confidential information, or othersensitive data•
Man-in-the-Middle
A man-in-the-middle attack occurs when the attacker intercepts a message sent between thebrowser and the web application. The attacker then changes the message and forwards it tothe web application. The web application receives the message, trusts the message ascoming from the genuine end user, and acts on it. When the web application sends amessage back, the attacker intercepts it, alters it, and returns it to the browser. Both thebrowser and the web application never know that they have been attacked.For all impersonation attacks, the highest impact is always equal to the highest user privilege.As a consequence, the best way to limit the impact is to have application authorisationsimplemented with the "Need-to-know" and "least privilege" principles in mind. In addition,traceability of user actions plays an important role to limit the impact of malicious acts.For Denial of Service attacks, unavailability impact must be evaluated by every institution.
Security Aspects to Consider27 March 201519
3.5.2Addressing Security Threats
The following table provides, for typical attacks, the controls that must be considered whendeploying Alliance Web Platform and Alliance servers. The controls highlighted in
italic
must beput in place by the customer. The controls highlighted in
bold
are features provided by theAlliance products. Some of those features must be appropriately configured by Allianceadministrators.
Security Threat ControlsThreatTypicalattacksControlsAlliance WebPlatformAccess/EntryGatewayIntegratorUserCustomerinfrastructure
Steal passwordor sessionKey loggerSessionguessingPhishingShouldersurfing
SessionmechanismSSL TunnelStrongPasswordPolicyOTPAccountmanagementSessionMechanism
Secure Browsing practices Protection of the system used by Alliance product
DataeavesdroppingPhishingSniffing
SSL TunnelSSL Tunnel
Secure Browsing practices
Data tamperingMan-in-the-middle
ServerauthenticationActivating andusing dualauthorisationandsegregation ofdutyprocedures
Secure Browsing practices Network segregation Patch management Logical and physical control VPN
Third-partyproductweakness
Reverse proxy DMZ
Network segregation Patch management
Denial ofService (DoS)
Patch management Reverse proxy Patch management
Network segregation Server segregation Protection of the system used by Alliance product VPN
For more information, see "Security on Windows Systems" on page 30 or "Security on AIX,Linux, or Solaris Systems" on page 21, depending on your operating system.
Alliance Access 7.1 on Alliance Web Platform20Security Guide
3.6Security on AIX, Linux, or Solaris Systems
Overview
This section describes security considerations when running Alliance Access on an AIX, Linux,or Solaris operating system.
3.6.1AIX, Linux, or Solaris User Accounts
3.6.1.1 The Alliance Administration Account
Overview
At installation, Alliance Access prompts the installer for the name of the "Administrator" account,the UNIX or Linux account to be used by the Alliance System Administrator.The system offers the default name of
all_adm
. If you install additional Alliance instances, thenit is recommended to give each Alliance instance a different administration account name. Forexample, the first instance can be given the name
all_adm
, the next instance,
all_adm1
, andso on. The account is a captive account protected by a UNIX-level or Linux-level password thatmust be known only to the Alliance System Administrator.Having logged on to UNIX or Linux, the Alliance System Administrator enters a dedicatedgraphical environment provided by the System Administration application from which theadministrator is able to start and stop the Alliance servers, and to use various functions
specifically provided to manage Alliance.
3.6.1.1.1 Accessing AIX, Linux, or Solaris as Administrator
Administrator access
The Alliance System Administrator also has access to the UNIX or Linux command line. Oncelogged-in as administrator (and after selecting an instance - if multiple instances are installed),the System Administration application appears. From the
OS Configuration
menu, the
Xterm
command opens a UNIX or Linux shell window. From here the Alliance administrator can issueUNIX or Linux commands.For more information, see the
Administration Guide
for your AIX, Linux, or Oracle Solaris
operating system.
3.6.1.2 Comparison of Administrative Roles
Administrative roles
The following table compares the roles of the Alliance System Administrator (assuming that theaccount for the Alliance Access instance has been given the account name "all_adm"') andUNIX or Linux System Administrator ("root") as applied to the system configuration, installation,and ongoing maintenance of the Alliance Interface.
Note
The UNIX or Linux System Administrator may also be responsible for other system-related tasks, not directly connected with the use of Alliance Access.
Function or Procedureall_admrootInitial System Configuration:
Configure Dual Hardware options (if licensed)
✓
Security Aspects to Consider27 March 201521
Function or Procedureall_admroot
Create default directories and file systems
✓
Set file attributes
✓
Define environment variables (for installation)
✓
Software installation and uninstallation:
Run install program
(1)
✓
Perform licensing procedures (with security officers)
✓
Set password mode
✓
Remove software
✓ ✓
Install and remove software patches
✓
System Management:
Create new UNIX or Linux account
✓
Set file attributes for new accounts
✓
Modify user profile (new user)
✓ ✓
Copy alliance_init to new user
✓
Start the Alliance Access servers
✓
Stop the Alliance Access servers
✓
Kill Alliance Access processes
✓
Check database consistency
✓
Run Alliance security check
✓
Use of the
saa_bankquery
tool (with Support)
✓
Back up and restore:
Back up the release tree
✓
Restore the release tree
✓
Back up the database
✓
Recover the database from backup tape
✓
(1)The software can be installed with a non-root account, but specific preparatory actions are required beforehand.For more information, see the
Installation Guide
for AIX, Linux, or Oracle Solaris.
3.6.1.3 Auditing User Activities
Auditing access
Most UNIX or Linux systems provide some form of logging facility that may be used as the basisfor auditing access to the system.Log files typically record:•user names and logon times•logoff times•the identity of the terminal used
Alliance Access 7.1 on Alliance Web Platform22Security Guide
•for networks, the name of the host that the logon originated fromIn addition, an accounting function may be used to record which commands have been run,including:•the identity of the user•the name of the command•the time that the process was terminatedAIX provides a comprehensive audit function, potentially generating huge amounts of data onthe activities of a system. This function is not normally active but is used, at specific times, totrace certain events in the system. By default, auditing is deactivated for Alliance Access.
3.6.2AIX, Linux, or Solaris Passwords
Passwords
Standard UNIX or Linux access control consists of a password-protected logon. No criteria areimposed on the choice of password. UNIX or Linux does not offer (or rarely offers):•inactivity time-out•password aging•control of password format•terminal-dependent logon•time-based access controls•action on repeated logon failuresUNIX or Linux passwords are encrypted using an encryption algorithm and diversified using oneof 4096 "salts", derived from the system time. The UNIX or Linux "crypt" algorithm is availableon the system.Encrypted password values are stored in a file which is freely accessible by all users, makingthem vulnerable to so-called dictionary attacks. These rely on the fact that most people selectpasswords which are words that may be found in a dictionary. By encrypting common words,and comparing the result with that stored in the password file, a determined intruder candiscover a user's password. This is one very good reason why not to select passwords that arewords found in a dictionary.AIX uses hidden password files which are not accessible to normal users. In addition, AllianceAccess requires a separate (and independent) level of operator identification andauthentication, based on the use of a SWIFT-proprietary one-way encryption algorithm.When a UNIX or Linux account is first created, the UNIX or Linux System Administrator assignsan initial UNIX or Linux password and advises users how to change this password following afirst successful logon. Thereafter, it is the responsibility of individual users to update anypasswords in line with local security requirements.In relation to Alliance Access, if users share a common UNIX or Linux password, it is importantthat all Alliance Access users are notified when this shared password is updated.
Security Aspects to Consider27 March 201523
3.6.3AIX, Linux, or Solaris File System
Introduction
UNIX or Linux is a file-oriented operating system. Every program, directory, data file, and device(such as terminal, communications interface, or printer) is represented by a file.Each file has a number of attributes associated with it, including:•File Ownership: every file is owned by a known user•Group Ownership: users may belong to user-definable groups. The group ownership of a filedetermines which group that file is associated with (allowing members of that group a definedlevel of access to that file).•File Permissions: these determine who has: –Read access (that read that file) –Write access (that update and modify that file) –Execute access (that run that file, assuming that the contents are executable) –Each of the above is set independently for:
•
•
the members of the group which owns that file
•
the rest of the world (meaning all other users of that system, including connectedsystems)The attributes are maintained for all files in the system and are stored with each file. Read,write, or execute access is denied to a user that does not possess the correct level ofprivilege, as defined by the file attributes. File permissions may be modified, at any time, bythe owner of that file or by the UNIX or Linux system administrator.All Alliance Access program and data files are owned by the Alliance system administratorand accessible, with restrictions, only by members of the ALLIANCE group of users.The
saa_system integrity
command can be used at any time to verify the correct setting ofAlliance Access file attributes. For more information, see the
Administration Guide
for yourAIX, Linux, or Oracle Solaris operating system.
3.6.3.1 File Access Controls
Controls
The UNIX or Linux operating system provides basic security mechanisms to ensure that filesmay be read, updated, or run only by those users that have been granted the correct UNIX orLinux-level privileges. Groups of users may share the same privileges.These privileges may be granted separately to:•the owner of that file•other members of that same group•all usersThe Alliance installation process ensures that all Alliance users belong to the group ALLIANCE.All executable files are owned by the Alliance Administrator.
Alliance Access 7.1 on Alliance Web Platform24Security Guide
In this way, no user - other than the Alliance System Administrator - has direct access (forexample, using normal UNIX or Linux commands) to Alliance programs and files.To ensure that the file protection mechanisms remain unaltered, checks are made at varioustimes on UNIX or Linux file permissions, as described in the following sections.
3.6.3.2 Security Check
Checks
A full integrity check of all executable files (as performed during the installation process) may beperformed at any time during the life of an installation.If the integrity of Alliance software is ever in doubt (or periodically as a precautionary measure)then the Alliance System Administrator may run a dedicated script which performs the followingfunctions:•the full CRC values - for each executable file - are re-calculated and checked against thetrusted values stored in the Alliance database. Any discrepancies are reported on-screen (notin the Event Log).•the file permissions of all Alliance software files are checked against the trusted values storedin the Alliance database. Any discrepancies are reported on-screen.
3.6.4AIX, Linux, or Solaris Software and Data Integrity
3.6.4.1 Software Backup
Terminology and overview
The software is the release tree of the programs used to handle data in the database. Softwareis always defined by the Name, Release, and Patch level.Software backups provide protection against software corruption.Consider the worst-case scenario in which your system crashes, software files are corrupted,but your backup is not available, meaning:
SituationAction required
No Alliance Access software isavailable.The entire Alliance Access software must be reinstalled.No Alliance Access patches areinstalled.The latest mandatory patch and possible optional patches must bereinstalled.The database backup isuseless.It is not possible to restore the database backup on another machinewithout a previous restore of an adequate software backup.
Best practice
Keep a software backup on external media or at least on a different disk. It is highlyrecommended to make a software backup before any sensitive action, such as a softwareupgrade.
Security Aspects to Consider27 March 201525
Limitations and known problems
The Alliance Access server and workstations must be on the same Release and Patch level,except when explicitly specified differently in the Release Letter.For more information about the release and patches of operating systems for Alliance Access,see the OS Levels and Patches Baseline document.
3.6.4.2 Use of Dual Disks
Dual disks
Alliance supports the use of dual disks - systems using two disk drives to segregate datastorage and to improve disk performance. For example, Alliance software and the databasemay be stored on one disk, while the backups of message and event archives may be stored onthe other.If a reliable backup regime is used, following a single-disk failure then the complete AllianceInterface may be recovered from the files stored on the remaining disk and from software anddata backups.
3.6.4.3 Dual Hardware Configurations
Dual hardware
Dual hardware configurations provide a high level of protection against most types of hardwarefailure.Systems may be configured in pairs, sharing X-Terminal connections over a common LAN, andsharing dual disk resources between the two systems. In such configurations, one processoracts as the live machine and performs all processing functions. The other machine acts as a
standby. In the event that one machine (or a part of that machine) fails, external connections(for example, to the SWIFTNet) only have to be swapped to the other machine for processing tobe restarted with minimal disruption to operations.The
Installation Guide
for AIX, Oracle Solaris, or Windows provides a detailed description of the
dual hardware configurations supported for Alliance.
Note
This facility is not supported on certain operating systems, such as Linux.
3.6.4.4 HACMP - High Availability Cluster Multi-Processing (AIX only)
Introduction
This solution consists of two nodes running in a cluster. In case of first node failure, the HACMPstarts the second node, where Alliance will start after the database recovery.For more information, see the IBM PowerHA SystemMirror Standard Edition 7.1 Installation andUser Guide.
Alliance Access 7.1 on Alliance Web Platform26Security Guide
3.6.5AIX, Linux, or Solaris-Related Security Weaknesses
Introduction
Historically, UNIX or Linux systems possess a number of shortcomings with regard to systemsecurity - either directly or indirectly:•UNIX or Linux systems are typically administered by a single system administrator who takesole charge of the system and its resources.•UNIX or Linux systems are widely available - including the source code for many routines.This allows weaknesses to be exploited by those seeking to take advantage of such systems.•UNIX or Linux systems are becoming less and less expensive. The cost of full-time expertUNIX or Linux system administrators becomes relatively high and is, therefore, oftenoverlooked.•UNIX or Linux systems are powerful and offer lots of different utilities. This makes UNIX orLinux systems complex (with literally thousands of files) and relatively difficult to administer.•UNIX or Linux systems are flexible and it is possible to set up a system in many differentways, some of which are inherently insecure.•UNIX or Linux programs are portable and many are granted too high a level of privilege, justto make them work. Some implementations suffer from translation bugs with significantsecurity consequences.•UNIX or Linux offers many networking possibilities for distributed processing and for remoteaccess. Security threats tend to multiply with networking, or the network itself becomes asecurity threat.Some of these concerns do not apply to Alliance Access when running as the only applicationon a stand-alone system. However, the level of concern increases when other applications arerun on the same system, and when the Alliance Interface runs on distributed networks.While SWIFT has confidence in the Alliance Interface and in the UNIX-based or Linux-basedsystems on which it is implemented, SWIFT clearly cannot be responsible for the use of badsecurity procedures by persons with an inadequate level of knowledge or skill.
3.6.5.1 Root Privileges
Root identity
Every UNIX or Linux system has a UNIX or Linux system administrator that, from time to time,must act with "superuser" or "root" privileges to perform administrative tasks at the operatingsystem level. When acting in this way (that is when logged on as "root") security checks - suchas the restrictions imposed by file ownership and access permissions - are ignored (althoughsome systems can log all root activity).When using the root identity, all of the following actions are possible by the UNIX or Linuxsystem administrator:•add, remove, or change user accounts•read, delete, or modify any file in the system•run any program•kill any process which is running
Security Aspects to Consider27 March 201527
•shut down the system•mount and unmount file systems•enable or disable audit facilities•become any other UNIX or Linux user on the system•reconfigure network devices and LAN connections•alter the limits set for CPU time, data segment size, core file size, and so on•turn accounting on and off•access any device on the system (printer, terminal, modem, and so on)•set (or reset) the date and time•change the priority of a process
Protection
Clearly, persons acting as root are able to take complete and sole charge of a system. There isno ability to exercise dual control over root privileges. The only real protection against othersusing the root account is by means of the password assigned to the root account. Thispassword must be protected at all times and NEVER disclosed to others.Most system break-in attempts are designed to acquire root privileges. When this is achieved,an intruder can do almost anything inside the system.The UNIX or Linux command "su" (substitute user) can be used to acquire temporarily theidentity of another user. Doing so prompts for the password of the account to which you arechanging. Intruders may guess at the root password, so it is important to select a very strongpassword for the root account. Most systems log bad su attempts, identifying the users that triedto acquire another's identity. A similar facility allows processes to be made to run with rootprivilege.The existence of the root account represents, for some, the most serious security weakness inUNIX or Linux systems. However, by adopting the following procedures, this weakness can, atleast, be minimised:•give careful consideration as to who must be appointed to the role of the UNIX or Linuxsystem administrator (and therefore act with root privileges)•provide adequate system and security awareness training to the UNIX or Linux systemadministrator to provide that person with the skills necessary for this important task•limit direct access to the root account. Ensure that the UNIX or Linux system administratoralso has a normal UNIX or Linux user account, within which much of the administrator's workcan be performed. When necessary, the administrator may then
su
to the root account toperform privileged tasks•ensure that special consideration is given to the choice of password for the root account. Ifthe root account password is compromised, then the whole system is compromised•to enable emergency access to the system with root privilege, this password can be recordedby the UNIX or Linux system administrator in two parts, and each part safe-stored and madeavailable to another user (with suitable skills) for emergency use
Alliance Access 7.1 on Alliance Web Platform28Security Guide
3.6.5.2 Client/Server Communications
Client and server processes
The architecture of the Alliance Interface is built around the concepts of client and serverprocesses, where client processes request services from servers and server processes provideservices to clients.To authenticate the communications between clients and servers (and to ensure that no rogueprocesses have been introduced), Alliance Access uses a security block in all RemoteProcedure Call (RPC) communications. This enables file ownership and permissions, operatoridentities, process IDs, and so on to be verified at each RPC. The full format of this securityblock is not published outside of SWIFT, and the code used to create and verify the securityblock is highly complex.For more information about RPC, refer to the
Installation Guide
for AIX, Linux, or Oracle Solaris.
3.6.5.3 Use of LANs
Local Area Networks
The use of Local Area Networks (LANs) enable remote terminals to connect to host systemsand different hosts to be connected together to form networks. Various protocols (for example,X-Windows to connect X-Terminals, or Ethernet and TCP/IP for network communications)enable discrete connected systems to operate as one logical system.LANs are used to carry the necessary commands and data between display manager andterminal, between client and server and between connected hosts.A possible weakness exists in that data, considered critical on one system, may be sent toanother system, or terminal, through a connecting LAN, in clear. This can allow someone, ableto monitor LAN traffic, to gain access to secret data. For example:•user names and passwords, entered at a remote terminal, are sent over the connecting LANin clear, for verification by the host system to which that terminal is trying to log on•Alliance Access encrypts data at the database layer using server processes dedicated to thereading and writing of encrypted data. A remote client, requiring the use of some encrypteddata, will receive that data over the LAN only after it has been read and decrypted by thedatabase server - that is in clear.
3.6.5.4 Use of X-Terminals
X-Terminal
The X-Windows environment (commonly known as X11) provides a flexible means wherebyhumans can interact with computer processes in a meaningful way - such as through agraphical user interface.Traditionally, if a computer process must display information to a user, it had to know at whichterminal the user can be located. With X-Windows, each host on a system runs an X11 windows
manager, which takes care of the sending and receiving information between user terminals andthe processes running at that host.At the terminal level, each runs an X-Terminal protocol allowing users to log on to one or morehosts from the same screen, and relying on the X-Terminal protocol to manage thecommunications with the X-Windows managers of those hosts. Separate physical windows maybe displayed on a user's screen, each communicating with a specific host.
Security Aspects to Consider27 March 201529
In a networked environment, with many hosts, perhaps running distributed processes, X-Windows ensures that keyboard and mouse input is directed to the correct remote process, atthe correct host. Similarly, output from processes running on hosts anywhere in the network isrouted, by the X-Windows manager at that host, to the correct terminal.In practical terms, this means that, when properly configured, a user may log on to a host (whichneed only be identified by name), run programs, manipulate data files and so on, withoutneeding to know the physical location of that host.X-Terminal emulation programs are common on many small desktop computers, such as PCs.This enables, for example, a PC to be used as an X-Terminal for much larger and morepowerful UNIX or Linux systems. LANs are used to connect X-Terminals into the network.X-Windows implements the true meaning of the server concept. Your display can serve clientson any system and, conversely, clients running on your system can display their output on anyother screen.However, from the security point of view, the scope for abuse is considerable. The design of X-Windows allows any client that successfully connects to your local X server to take completecontrol of your display (and allows your local clients to do the same to others).Two methods of controlling X-Windows access are possible:•Host-Based Access Control: Host-based access control uses a file which contains a list of thehosts (by name) that are allowed to send clients to display on your terminal. This list,normally configured by the UNIX or Linux system administrator, is read at startup. However,this scheme suffers from two major restrictions which make it inadequate for real security: –You cannot run client processes, for display at your terminal, from those hosts who do nothave access to your display. You therefore have to deny yourself access, to deny it toothers. –This control mechanism is easily bypassed. Any user with an account on your machine (orany other host your server allows access to) may access your display.•User-Based Access Control: With this scheme, when a user logs on, a secret code is writtento a file in the user's home directory, by the display manager. This code is also madeavailable to the local X-server. Once this code is established for an X-session, any clientwanting to access the user's display, must first present the correct code before it is allowedaccess to the server.•This scheme relies on the fact that UNIX or Linux processes, started by a particular user,inherit that user's file attributes. The file containing the secret code can only, therefore, beread by the owning user, or by processes started by that user. This method is only as secureas the user's account and, therefore, the user's password. Not all versions of X-Terminalsupport user-based access controls.
3.7Security on Windows Systems
Overview
This section describes security considerations when running Alliance Access on a Windowsoperating system.
Alliance Access 7.1 on Alliance Web Platform30Security Guide
3.7.1Windows User Accounts
Overview
The system administrator is responsible for setting up a Windows user account for each Allianceoperator. A user account contains a list of groups to which the user belongs. Membership of agroup gives the user the right to perform various tasks within Windows. For example, membersof the Administrators group have the right to fully administer the computer or domain.The administrator may have to set up a user group specifically for the Alliance users to ensurethat other Windows users do not have access to the Alliance software.
Note
Alliance users that are enabled to start and stop the Alliance server must have anadministrator account.An Alliance operator must be a member of either the Administrators group or the group whichhas rights to use Alliance.
3.7.1.1 Built-In Accounts
Description
Windows has two built-in accounts,
Administrator
and
Guest
. When Windows is first installed,Guest has no password and its account is enabled. It is recommended that Guest must bedisabled, renamed, and assigned a password. Administrator must also be renamed andassigned a password.For information about modifying the built-in accounts, see the Microsoft Windowsdocumentation on User Manager.
3.7.1.1.1 File Protection
Permissions
All the directories and files in an NTFS partition have permissions associated with their use. Thedefault permission in Windows is "Full Control".For a directory, Full Control allows:•viewing file names and sub-directory names•changing to the directory's sub-directories•viewing data in files and running application files•adding files and sub-directories to the directory•changing data in files•deleting the directory and its files•changing permissions on the directory and its files•taking ownership of the directory and its files.For a file, Full Control allows:•viewing the file's data•running the file if it is a program file
Security Aspects to Consider27 March 201531
•changing data in the file•deleting the file•changing permissions on the file•taking ownership of the file.Alliance does not set any file permissions during installation, so Full Control is applied to allsoftware and data. It is recommended that access to software and data is restricted to the usersthat need it. Restricting file permissions protects data against unauthorised use. Executable filesmust be set to read-only and restricted to users authorised to run them.For information about how to manually change permissions, see the Microsoft Windowsdocumentation on Windows Explorer and User Manager.
3.7.1.1.2 Auditing Files and Directories
Overview
Auditing files and directories allows you to track their usage. For a particular file or directory, youcan specify which groups or users and which actions to audit. You can audit both successfuland failed actions. Windows stores the information generated from auditing in a file. Forexample, auditing can be set to monitor attempts to modify protected files. Be careful to limit theactions that you audit. If you audit too many actions, then the performance of your system maybe affected.For information about activating auditing, see the Microsoft Windows documentation onWindows Explorer.
3.7.2Windows Passwords
Overview
Windows users must specify their user names and passwords each time they log on toWindows.The system administrator is responsible for the initial definition of user names and passwords.These are either defined during the installation of Windows or later on with User Manager.Details of the user name and password are then passed to the user they have been created for.From then on, the user is responsible for keeping a password secret and renewing it whenrequired.
RestrictionDescription
Maximum Password AgeThe length of time a user's password is valid before they are forcedto change it.Minimum Password AgeThe minimum length of time a password must be used for before itcan be changed.Minimum Password LengthThe minimum length of a password.Password UniquenessThe number of new passwords that are used by a user accountbefore an old password can be reused.
These restrictions are part of the Account Policy of each user account. There are also thefollowing user properties:
Alliance Access 7.1 on Alliance Web Platform32Security Guide
PropertyDescription
User Must Change Password atNext LogonForces a user to change the password at the next logon. This is away of ensuring that a user becomes responsible for his or herpassword.User Cannot Change PasswordThis option is usually applied only to user accounts used by morethan one person.Password Never ExpiresPrevents the password from expiring, overriding the MaximumPassword Age setting in the Account Policy.
Users are forced to change passwords in the way defined in the user's account. If users thinkthat someone else knows their password, then they must change it.
3.7.2.1 Screen Savers
Overview
A password-protected screen saver ensures that unauthorised users cannot access a computerthat has been left unattended. Windows has a password-protected screen saver. If someonetries to access Windows when this screen saver is on, then a
Lock Workstation
dialog boxappears. To unlock the workstation, the user's password must be entered.
3.7.3Windows File System
Overview
Alliance must be installed in a Windows file system (NTFS) partition. NTFS has useful directorysecurity features which let you define file and directory permissions and define the ownership offiles.When resources are shared in the NTFS environment, remote access is limited by acombination of two sets of permissions:•network sharing permissions•local NTFS permissions.Alliance Workstation users do not have permission to share directories on the server. They areable to update the Alliance database because of the entitlements, and permissions given tothem in their operator definition.Alliance Workstation does not store any data in the local NTFS partition.
3.8Alliance Access Operating Modes
Description
Alliance Access can operate in either of two modes:•Operational mode is the normal multi-user mode of operation. In this mode, all definedAlliance Access operators may sign on and make use of Alliance Access facilities.•Housekeeping mode is selected whenever system maintenance tasks have to be performed.In this mode, by default only one user at a time is allowed to sign on to Alliance Access.Security officers can change the number of operators permitted to sign on in housekeepingmode.
Security Aspects to Consider27 March 201533
In housekeeping mode, queues are frozen and messages cannot be sent or received. Noscheduled processes take place when the servers are running in housekeeping mode.Note the following additional restrictions on the use of housekeeping mode:•Gateway connections are not visible when the servers are running in housekeeping mode.•You cannot activate or deactivate a correspondent when the servers are running inhousekeeping mode•You cannot add or delete countries or currencies when the servers are running inhousekeeping mode.Additionally, certain system changes can only be made if Alliance Access is in housekeepingmode (when only a single user can sign on). The system must be stopped and restarted toswitch between the normal operational mode (when all users can sign on) and housekeepingmode. Backups can be done in both housekeeping and operational mode.Following are examples of tasks that must be performed in housekeeping mode:•installing a new message syntax table•creating and configuring logical terminals•installing value-added services, such as FINCopy•managing the FINCopy Profiles•installing the Alliance Bank File•managing the MX message standards•assigning routing keywords•modifying active routing rulesThe
Stop Alliance
and
Restart Alliance
commands in the System Management entity areused to stop and restart Alliance Access in a different operating mode. A restart causes AllianceAccess to halt its current operation and shut down, before restarting in the selected operatingmode.When Alliance Access is stopped, any user currently signed on to Alliance Access is warned. Ashort period of time is allowed for all current users to sign off (after which their current sessionsare aborted).If a calendar has been created, then Alliance Access can be scheduled to stop or restartautomatically at specific times on specific days.The entitlement to stop and restart Alliance Access is provided to security officers, systemadministrators and Supervisors, and may also be assigned to an operator as part of an operatorprofile. For more information about the default profiles, see "Default Operator Profiles" on page84.
Alliance Access 7.1 on Alliance Web Platform34Security Guide
3.9Offline Maintenance Utilities
Overview
A number of facilities are provided in Alliance Access for exclusive use by the SystemAdministrator for off-line maintenance of Alliance Access. These facilities are provided bymeans of the System Administration application and the Installation application. Only users setup as members of the administrators group can access these applications.The use of these facilities is summarised in this section, and detailed in the
Administration Guide
for AIX, Linux, Oracle Solaris, or Windows.
ConfigurationOn Windows:
On Windows servers, the Installation application includes facilities that allow the systemadministrator to:•change information about the Alliance Access server•display version information•produce a detailed system configuration report which includes hardware and softwareinformation.The System Administration application includes a facility to configure archive directories andmessage partners.
On UNIX or Linux:
The System Administration application provides commands to manage the system and makeconfiguration changes.
Instance management (UNIX or Linux only)
The System Administration application provides functions to display and rename Allianceinstances installed on the system.
Start/Stop Alliance servers
The System Administration application provides facilities for the Alliance System Administratorto start the Alliance Access servers and to shut down the servers in an orderly fashion. TheAlliance Access servers may also be shut down (or restarted) from within the SystemManagement entity through the use of the
Stop Alliance
and
Restart Alliance
commands.
Backup and restore facilities
Facilities are provided within the System Administration application (on Windows only) andthrough command line tools to create offline backups of the Alliance Access database - andlater restore these backups if a recovery is required.These facilities must only be used in exceptional circumstances, but must be fully tested andproven for each new installation as part of the normal operational readiness testing (that is,before live operations begin).Unless the database recovery mode is activated (which requires licence option 14:DATABASE
RECOVERY), the messages and Event Log (that is, those not yet archived) are never backedup and hence, never restored. This is to avoid the risk of duplication. For more informationabout the database recovery mode, see the
Administration Guide
for AIX, Linux, Oracle Solaris,
Security Aspects to Consider27 March 201535
or Windows or www.swift.com > Connectivity > Alliance Access Database Recovery Information
Paper.
Software security check
All executable files (that is, programs, shared libraries and scripts) on the Alliance Accessrelease DVD are authenticated by SWIFT. A list of all valid authentication codes is also includedon the release DVD and stored (in an enciphered form) with each Alliance installation.The
saa_system
command line tool enables the Alliance System Administrator to verify that noexecutable files currently installed have been changed or tampered with. Any discrepancies arereported (on-screen) whenever this tool is run. For more information about this tool, see the
Administration Guide
for AIX, Linux, Oracle Solaris, or Windows.
A software security check is also performed online every time an executable file is run. The filein question is verified before it is run, and is not run if a discrepancy is found.
Use of bank query
The
saa_bankquery
tool provides access to the dedicated Alliance Access database enquiryand repair facility. The tool is used to verify and repair database entities. Only the AllianceAdministrator can run this tool.Given the powerful nature of this tool, its use is protected by three different passwords:•the first password is the operating system password of the Alliance Administrator (initiallyrequired to log on to the Alliance Administrator account to run
saa_bankquery
)•the second password is that of any Alliance operator (for example, a supervisor) who hasbeen granted the specific entitlement, within Alliance Access, to run
saa_bankquery
•the third password is a dedicated password that must be obtained from Support, asdescribed further.When running the
saa_bankquery
tool for repair, the Alliance Access servers must not berunning.All access to bank query is logged on the Event Log. Any updates or modifications to AllianceAccess data is also logged.For more information about the use of the
saa_bankquery
tool, see the
Administration Guide
for AIX, Linux, Oracle Solaris, or Windows.
Note
An operator using One-Time Passwords cannot use the
saa_bankquery
tool.
Use of journal query
The System Administration application provides a facility that allows users to query and use theEvent Log entity, without having to sign on to Alliance Access. Journal Query may also be usedfor diagnostic purposes if either the System Administration application or the Alliance userinterface is unavailable or cannot be started.
Alliance Access 7.1 on Alliance Web Platform36Security Guide
4Installation, Upgrade, and Licensing
Introduction
Alliance Access provides a number of controls to ensure that only genuine users can gainaccess to it. This section describes the use of account names and passwords - at both theoperating system level and the Alliance Access level - and shows how the security officerscontrol access to the Alliance Access software.Before Alliance Access is installed, the security officers, or the technical engineers, shoulddetermine what changes are needed to the default settings, such as configuration and securityparameters. In addition, they should determine what level of security to implement to secure thesystem, as well as the user access to the software.
4.1What Is Secure Channel?
Overview
Secure Channel is an online application for SWIFTNet Security Officers and Alliance SecurityOfficers. It enables registered SWIFTNet Security Officers to:•submit SWIFTNet offline interventions•register new, or de-register obsolete SWIFTNet Security Officers•update their own address details•manage the PKI delegation and the authorisation setting•recertify SWIFTNet Security Officer profilesSecure Channel also allows registered Alliance security officers to view SWIFT Interfacesoftware licence keys online.
How to Access Secure Channel
To acquire access to the Secure Channel application, you must first be a registered user for theonline services on www.swift.com. A swift.com administrator in your institution must approveyour registration request before you can use the online services.On www.swift.com, go to Support > Secure Channel > Access Secure Channel.
4.2Alliance Initialisation Password
Overview
The use of the Alliance Initialisation Password provides a mechanism whereby the legal rightsto the use of Alliance Access software with the purchased options (by the relevant destinationsand with the relevant message types) may be passed from SWIFT to the purchasingorganisation in a reliable and controlled manner.The two parts of the password are each 16 alphanumeric characters in length:•Part 1 is addressed to the left security officer.•Part 2 is addressed to the right security officer.
Installation, Upgrade, and Licensing27 March 201537
The Initialisation Password is calculated using a proprietary algorithm together with a hard-coded enciphering key, known only to SWIFT.The Alliance Initialisation Password is uniquely calculated for each combination of:•Alliance Access software release•the software options purchased•the identity of the licensed SWIFT destinations•the SWIFT message types used at those destinations
How to obtain
To obtain passwords, use Secure Channel. For more information, see http://www.swift.com/ support/secure_channel.page?.
When to use
Both parts of the Initialisation Password must be entered during the installation of the AllianceAccess software release (or upgrade), enabling dual control to be exercised over softwareinstallation. Without both parts of the Initialisation Password, Alliance Access cannot beinstalled.During software installation, the Initialisation Password is recalculated using the informationentered during installation. The calculated Initialisation Password must match that entered bythe security officers for the software installation to proceed further.
4.3Alliance Master Password
Overview
The Alliance Master Password is calculated by SWIFT at the same time as the InitialisationPassword and is based on the same combination of data, but using a different hard-coded key.This password is also in two parts (each part consisting of eight alphanumeric characters), andis distributed along with the Initialisation Password. Part 1 is dispatched to the left securityofficer of the purchasing organisation along with the relevant part of the Initialisation Password.Part 2 is addressed to the right security officer at the same organisation.During installation, the Master Password is recalculated using the licensing data and stored inencrypted form. Also during installation, two operator definitions,
LSO
and
RSO
, are created.
LSO
and
RSO
allow the two security officers to sign on and use Alliance Access afterinstallation. To sign on, the security officers use Parts 1 and 2 of the Master Password. TheMaster Password entered by the security officers is verified against the stored version.
Password Control
When the security officers sign on for the first time, they are forced to change their part of theMaster Password.
Note
Each security officer must first update their part of the Master Password beforeeither security officer attempts to use any other facilities. The Master Password canbe changed to any combination of characters, but must be a minimum of fourcharacters in length and a maximum of 30.The current Master Password is one of the inputs used to create system-generated passwordsin Alliance Access. Therefore, whenever the Master Password is updated, all operatorpasswords that include a system-generated element, must also be renewed.
Alliance Access 7.1 on Alliance Web Platform38Security Guide
After initial sign-on, the secrecy of the Master Password is the joint responsibility of the leftsecurity officer and the right security officer. The Master Password is the most importantpassword in Alliance Access. If a security officer (left security officer or right security officer)forgets a password, then it is possible under certain conditions to reset the security officer'spassword to the original Master Password supplied by SWIFT. It is therefore important that theoriginal Master Password is retained and stored in a secure place under the control of bothsecurity officers. For more information, see "Resetting a Master Password" on page 39.
Logging In
See the Alliance Access
Configuration Guide
for the specific steps to log in, change yourpassword, and log out. In the same document are detailed instructions on how to use theAlliance Access graphical user interface (GUI).
4.3.1Resetting a Master Password
Password conditions
If a security officer (left security officer and right security officer) forgets a Master Password,then the password can only be reset if both the following conditions are met:•the other security officer resets the password - an operator with Approve Operatorentitlement cannot do so•the
Password: Reset Peer Offi cer Pwd
parameter is already set to
Yes
.For example, if the above conditions are met, then the left security officer can use the
Reset RSO Pwd
command in the Security Definition entity to reset the right security officerpassword. The password is reset to the eight alphanumeric character Master Password thatSWIFT dispatched to the right security officer at the most recent Alliance Access licensing.On installation, the
Password: Reset Peer Offi cer Pwd
parameter is set to
No
, whichmeans that the security officers cannot reset each other's password. The security officers canuse the Security Definition entity to change the value of this and other security parameters.If the
Password: Reset Peer Offi cer Pwd
parameter is set to
No
, and a security officerforgets a password, then the institution's local Support Centre must be contacted for furtherinstructions.
4.4Sign-on Time Limits
Restricting access times
Alliance enables security officers to restrict the time of day during which any particular operatormay sign on. This feature prevents an operator from being able to sign on outside normalworking hours, for example.Each day of 24 hours is split into two distinct time periods. As a part of that operator's profile, asecurity officer may define the start and end times for each of the two periods, during which asign-on by that operator is allowed. Any attempt by that operator to sign on to Alliance outsideof these defined periods, is rejected. Only sign-on attempts are monitored - once signed on, anoperator may use Alliance as long as required (or until the system is shut down). Initially, thereis no restriction as to when any operator can sign on. Both security officers must approve anychanges to this parameter.
Installation, Upgrade, and Licensing27 March 201539
Warning
When an operator signs on from the Alliance Web Platform GUI, Alliance comparesthe defined sign-on period for the operator with the system time of the system fromwhich the browser was launched. If the system time is within the operator's sign-onperiod, then the operator can sign on. Therefore, an operator who can change theWindows time (or time zone) of the system from which the browser was launchedcan potentially bypass the sign-on period.
Automatic disabling after period of inactivity
Alliance enables security officers to define the number of days during which an enabledoperator must sign on. If the operator fails to do so, then the operator is automatically disabled.This feature prevents an operator from being able to sign on after an extended period ofabsence.The security parameter
System: Di sabl e Peri od
, which is available to the security officersfrom the Security Definition application, can be set to any value between 0 and 999.When set to 0, no validation is performed, and operators are not automatically disabled.When set to a value other than 0, Alliance validates each operator (at midnight). If the value isgreater than the number of days since the operator last signed on (or was enabled), then theoperator is disabled. The same validation is performed each time the Alliance Access serversare started.
Note
An operator's password being reset does not affect this validation.The
LSO
and
RSO
operators cannot be automatically disabled.
Alliance Access 7.1 on Alliance Web Platform40Security Guide
5Configuration and Security Parameters
5.1Classes of Configuration Parameters
Overview
Alliance Access contains a number of system parameters that you can configure. You canchange the values of these parameters only if the permissions of your operator profile permityou to change them.Configuration parameters are grouped by class.
Note
Some parameters described in this section are only available if you have licensedthe relevant option for your system.
IPLA configuration parameters
In addition to the classes listed here, configuration parameters resulting from installingcomponents for IPLA may also appear. The bundle symbolic name appears as the value forClass. The value for Component is
I PLA
.
5.1.1Activation
List of activation parameters
ParameterDescription
Start evaluationEnter an activation code, which SWIFT hasprovided, to start the evaluation period forOperational Reporting. This will activateOperational Reporting, which will copy allmessages to the Reporting data store. Dependingon the number of messages in the database, thisoperation could take a considerable amount oftime.Activate reportingTo activate Operational Reporting, set thisparameter to
Acti vate
. This will copy allmessages to the Reporting data store. Dependingon the number of messages in the database, thisoperation could take a considerable amount oftime.To deactivate Operational Reporting, set thisparameter to
Deacti vate
. This operation willremove all message data from the Reporting datastore.
Configuration and Security Parameters27 March 201541
5.1.2Alarm
List of alarm parameters
ParameterDescriptionMaximum
The maximum number of alarms that can be displayed on Alliance Workstationsimultaneously:•Default:
3
•Minimum:
1
•Maximum:
20
Changes to this parameter take effect at the next login to Alliance Workstation.
Timeout
The number of minutes an alarm popup remains on screen:•Default:
15
•Minimum:
1
•Maximum:
120
Changes to this parameter take effect at the next login to Alliance Workstation.
Note
Alliance Access on Linux does not support Alliance Workstation.
5.1.3Alarm Message
List of alarm message parameters
ParameterDescriptionSender LT
Specifies the logical terminal (BIC12: LT followed by XXX) that is used to sendalarm messages to Internal Correspondents.Changes to this parameter take effect at the next Alarm Message/Frequencycheck.
Frequency
Alarm Message/Frequency check (in minutes). Default value:
5
.Changes to this parameter take effect at the next Alarm Message/Frequencycheck.
5.1.4Backup
List of backup parameters
ParameterDescriptionArchive BackupDir Object
The Oracle database requires this parameter to create the Data Pump filescontaining the backups of archives.Maximum value: 30.Changes to this parameter take effect at the next backup or restore operation.This parameter is only available when the Alliance Access database is hosted.
Alliance Access 7.1 on Alliance Web Platform42Security Guide
ParameterDescriptionDB Backup DirObject
The Oracle database requires this parameter to create the Data Pump filescontaining the backups of the Alliance Access database.Maximum value: 30.Changes to this parameter take effect at the next backup or restore operation.This parameter is only available when the Alliance Access database is hosted.
LocationBackups
This parameter defines the file directory wherein the Alliance Access backups arecreated. This directory must be shared between the Alliance Access host and thedatabase host. If the parameter has no value, then no backup or restore can takeplace.The parameter has no value by default.Changes to this parameter take effect at the next backup or restore operation.This parameter is only available when the Alliance Access database is hosted.
LocationBackups DB Host
This parameter defines the file directory remotely accessed from the database hostwherein the Alliance Access backups are created. If this parameter has no value,then the value specified for the
Location Backups
parameter is used.The parameter has no value by default.Changes to this parameter take effect at the next backup or restore operation.This parameter is only available when the Alliance Access database is hosted.
5.1.5Batch Input
List of batch input parameters
ParameterDescriptionAutomatic -Backup Dir
Automatic Input Backup Directory.All files in this directory that are older than the Batch Input History Period aredeleted.Default:
C:\Alliance\Access\usrdata\FTA\back
Changes to this parameter take place at the next poll.
Automatic -Disabling
Specifies whether the status of a message partner is set automatically to
Di sabl ed
if the message partner receives an invalid batch file.Possible values are
Yes
and
No
.Default:
Yes
Changes to this parameter take effect the next time the MXS component is started.This parameter has an effect on File Transfer message partners only.
Automatic - ErrorDir
Automatic Input Error Directory.All files in this directory that are older than the Batch Input History Period aredeleted.Default:
C:\Alliance\Access\usrdata\FTA\error
Changes to this parameter take place at the next poll.
Automatic -Polling Timer
The Session Autostarter Polling Timer in seconds. Default value: 60.Changes to this parameter take place at the next poll.
History Period
The number of days to keep history records for batch duplication check and tokeep the files in the file transfer adapter backup and error directories. Defaultvalue: 10.Changes to this parameter take place at the next poll.
Log Directory
The location where report files generated for XML version 2 (MT/MX) input arestored.
Configuration and Security Parameters27 March 201543
5.1.6Batch Output
List of batch output parameters
ParameterDescriptionInclude payloadin LTA
Specifies whether or not the payload (full) path must be automatically added to theLTA command parameters by Alliance Access, for File messages sent over a FileTransfer Message Partner.If this parameter is on and the message partner
Maxi mumnumber of messagesper sessi on
is set to
1
, then Alliance Access automatically adds the payload fullpath as the last parameter of the LTA command (after the XML file) for Filemessages.If this parameter is on and the message partner
Maxi mumnumber of messagesper sessi on
is greater than 1, then Alliance Access automatically adds the path tothe payload location as the last parameter of the LTA command (after the XMLfile).
LTA Timeout
Defines the Local Transfer Agent completion time in minutes. This is the time thatAlliance allows for the Local Transfer Agent to process a batch output file. If theLocal Transfer Agent has not finished its task within this time, then an event iswritten to the event log. Default value:
5
.
LTA waitingmode
Specifies whether Alliance can wait for Local Transfer Agent completion beforeclosing the session. Default value:
Off
.
5.1.7Database
List of database parameters
This parameter is not available when the licence package
13:HOSTED DATABASE
is present.
ParameterDescriptionLocationMessages
Location of the daily Messages database files. Changes to this parameter takeeffect when the next database file is created.Note: if the user enters an invalid path or if the server processes have no writeaccess to the specified location, then the new database files are created in thefollowing directory:•On UNIX or Linux:
$ALLI ANCE/ database/ datafi l es/ MESG
•On Windows:
%ALLI ANCE%\ database\ datafi l es\ MESG
Location JournalEvents
Location of the daily Journal Events database files. Changes to this parameter takeeffect when the next database file is created.Note: if the user enters an invalid path or if the server processes have no writeaccess to the specified location, then the new database files are created in thefollowing directory:•On UNIX or Linux:
$ALLI ANCE/ database/ datafi l es/ J RNL
•On Windows:
%ALLI ANCE%\ database\ datafi l es\ J RNL
Alliance Access 7.1 on Alliance Web Platform44Security Guide
5.1.8Alliance Developers Kit
List of Alliance Developers Kit parameters
ParameterDescriptionADK Storage
This parameter defines the directory in which Alliance Developers Kit applicationscan store their specific information. The contents of this directory are consideredduring the backup and restore operations.The default path for this directory is as follows:•On Windows:
%ALLI ANCE%\ data\ ADK_DI R
•On UNIX or Linux:
$ALLI ANCE/ data/ ADK_DI R
Operational Trace
When this parameter has a value
On
, a journal entry is written for every call that ismade to an Alliance Developers Kit (Toolkit) function. The journal entry describesin full the call made by the Alliance Developers Kit function. Default value: Off.You must restart an application in the Alliance Developers Kit, to apply the changesto this parameter.
5.1.9Disk Space
List of disk space parameters
ParameterDescriptionFrequency
The interval in seconds (in multiples of 60) at which disk space is checked.Default value: 300. Minimum: 120. Maximum: 3600.Change to this parameter take effect at the next disk-space check.A warning will be given if free disk space drops below a Warning parameter.Repeat warnings are given at 10 times the interval.
RecoveryShutdown - MB
Alliance Access shuts down when the free space of the Recovery Backup Diskbecomes less than this number of megabytes. If the value is 0, then no action istaken.Default value: 1000. Minimum: 0. Maximum: 4190000.This parameter is available when
14:DATABASE RECOVERY
is licensed.
RecoveryWarning - MB
Alliance Access issues a warning when the free space of the Recovery BackupDisk becomes less than this number of megabytes. If the value is 0, then no actionis taken.Default value: 5000. Minimum: 0. Maximum: 4190000.This parameter is available when
14:DATABASE RECOVERY
is licensed.
Shutdown - MB
Sets the absolute minimum free disk space (in MB) that must be available on thefile systems hosting the database. If the free disk space available for one of thesefile systems falls below this value, then Alliance Access shuts down.Default value: 1000, to which the system automatically adds (for recoverypurposes) the size of the largest database file stored in the database, plus the sizeof the database index file. Minimum: 0. Maximum: 4190000.The frequency at which this parameter is checked is set using the
Disk Space -Frequency
parameter.You must restart Alliance Access, to apply the changes to this parameter.
Shutdown -Release Dir
Shutdown Alliance Access when the available space on the disk of the source treeis less than this value (in Kbytes). Default value: 20000.Changes to this parameter take effect at the next disk-space check.
Configuration and Security Parameters27 March 201545
ParameterDescriptionWarning - MB
Alliance Access issues a warning when the free space of one of the monitored filesystems hosting the database becomes less than this number of megabytes. Thefile system is set in an exception state in the resources monitoring.Default value: 5000. Minimum: 0. Maximum: 4190000.If the value is 0, then no action is taken.Changes to this parameter take effect at the next disk-space check.
Warning -Release Dir
Alliance Access issues a warning when available space on the disk of the ReleaseDirectory is less than this value.Default value: 50000 (Kbytes).Changes to this parameter take effect at the next disk-space check.UNIX or Linuxonly:
Warning - PrinterSpool
Alliance Access issues a warning when available space on the /tmp disk is lessthan this value (in Kbytes).Default value: 10000. Minimum: 1024. Maximum: 200000.Changes to this parameter take effect at the next disk-space check.
5.1.10Display Format
List of display format parameters
ParameterDescriptionAmount
Specifies the convention used to separate decimals and units of a thousand:•
Decimal-Comma/Thousand-Nothing
, which corresponds to the ISO format. This isthe default value.•
Decimal-Point/Thousand-comma
, which corresponds to the American format.•
Decimal-Comma/Thousand-Point
, which corresponds to the European format.
Date
The display format of the date: American date format is MM/DD/YY, European dateformat is DD/MM/YY, ISO date format is YY/MM/DD. Default: European.You must restart Alliance Workstation, to apply the changes to this parameter.
Time
Specifies the time format:•
Day of 24 Hours
, which uses 24-hour clock notation, for example, 13:15:00. This isthe default option.•
Day of 12 Hours
, which uses 12-hour clock notation, for example, 01:15:00 p.m.
See also "Display/Print" on page 47.
Alliance Access 7.1 on Alliance Web Platform46Security Guide
5.1.11Display/Print
Display/Print parameter
ParameterDescriptionFIN UserHeader
Specifies whether to display or print the FIN User Header (block
3
) of MT messages.The allowed values are:•
Yes
- display block
3
in the message details in the
Text
tab of the Message Detailsarea, and in the results of a message search. In addition, print block 3 in the printedreports of message details, both from the GUI and from a Print message partner.•
No
- do not display block
3
in the message details, and do not print it in reports thatprovide message details.The default value is
No
.
5.1.12Emission
List of emission parameters
ParameterDescriptionCorr. onhold criteria
Indicates the period of time (in minutes) after which a correspondent is put on hold for areal-time service if all emission attempts for that correspondent/real-time service havefailed during that period.If set to
0
, correspondents are never put on hold for a real-time service.The possible values are numbers from
0
to
999
. The default value is
10
.Any changes to this parameter take effect immediately.
EP PollingTimer
Indicates the period (in seconds) according to which the Alliance Access polls thedatabase for the next message to send:•Maximum value:
300
•Minimum value:
1
•Default value:
30
You must restart the SWIFTNet Interface Services (SNIS) component, to apply thechanges to this parameter.
Retry Timer
Indicates the timeout period (in seconds) between two attempts to emit a message:•Maximum value:
120
•Minimum value:
0
•Default value:
60
You must restart the SWIFTNet Interface component, to apply the changes to thisparameter.
Configuration and Security Parameters27 March 201547
5.1.13Event
Event parameter
ParameterDescriptionSNMP MaxEvent Size
Indicates the maximum size of the event text distributed to SNMP managers. 0 meansthat there is no maximum size. Default value: 2000.
5.1.14File
File parameter
ParameterDescriptionFile DigestAlgorithm
Indicates the default file digest algorithm that Alliance Access uses to compute thedigest on the payload file of the FileAct message if no file digest algorithm is provided bythe back-office application. The following values exist: SHA-1 and SHA-256. Defaultvalue: SHA-256.Changes to this parameter take effect immediately.
5.1.15Message
List of message parameters
ParameterDescriptionCheck EP/LTexistence
Activates the rejection of MT messages submitted with LTX when there is no LTdefined for the LTX BIC8 and the rejection of IA/FA messages when there is noEmission Profile for the message Requestor DN/Service.Possible values are
On
(activates the check) or
Off
(no check). The default value is
Off
.Changes to this parameter take effect immediately.
Defaultemission expiry
Indicates the default time (in minutes) to be added to the message creation date andtime to calculate its emission expiry date and time.This parameter applies only to messages submitted without an emission expiry dateand time.Possible values are integers from
1
to
43200
. The default value is
28800
.Changes to this parameter take effect immediately.This parameter impacts InterAct and FileAct messages (RT or SnF). If a messagefails transmission, it is retried until the message expires (that is, until it reaches theexpiration date and time) or until the emission is manually cancelled.
ExpansionLanguage
Specifies the language that message expansion fields are displayed in. Default value:
Engl i sh
.Changes to this parameter take effect when an application is restarted.
Alliance Access 7.1 on Alliance Web Platform48Security Guide
ParameterDescriptionLT loadbalancing
Starts the automatic allocation of logical terminal allocation.Possible values are:•
On
- the messages originated by a destination can be transmitted by any logicalterminal which is logged in and assigned to that destination.•
Off
- the logical terminal specified in the message transmits the message.Default value:
Off
.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.
Maximum FileSize
Indicates the maximum size of a file in Mbytes (Mb) that a back-office application cansend to Alliance Access.•Maximum value:
2048
•Minimum value:
1
•Default value:
250
You must restart the Application Interface Services (MXS) component, to apply thechanges to this parameter.
RMAauthorisationfor T&T
Specifies whether RMA Authorisation is required for FIN Test and Trainingmessages. Possible values are:•
Not requi red
•
Requi red
Default value:
Not requi red
.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.
RTV Routing
Controls the RTV routing information in a retrieved message. When this parameter isset to:•
Off
- the
routing_code
field for a retrieved message is set to
RTV
•
On
- the
disposition_address_code
field for a retrieved message is set to
RTV
.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.Default value:
Off
.
Common RefCalculation
Controls the calculation of the Common Reference, which is part of field 22 of Block4, in FIN messages that are input through message partners and that have the dataformat CAS, RJE, DOS-PCC, or XML version 2. Alliance Access always calculatesthe Common Reference in messages that a user enters manually.The values are:•
Yes
- Alliance Access calculates the Common Reference, even it exists in field 22.•
No
- does not calculate the Common Reference in field 22. In this case, the valuesof
Validation level
and
Message Modification allowed
are ignored, and a NAKmay be received if field 22 of the message contains incorrect information.Default value:
Yes
.You must restart the Application Interface Services (MXS) component to apply thechanges to this parameter.
Configuration and Security Parameters27 March 201549
ParameterDescriptionFT MonitoringRetention
The number of days during which a file transfer with the status
Compl eted
or
Aborted
remains visible in the list of File Transfers in the Monitoring package.The list can contain a maximum of 1000 completed or aborted file transfers. This limitensures that the performance of Alliance Access remains optimal. Therefore, if thelist contains 1000 completed or aborted file transfers, then Alliance Access removesthe oldest of those file transfers.You must restart the SWIFTNet Interface component to apply the changes to thisparameter.Maximum value:
30
Default value:
0
Regardless of the value set for this parameter, a restart of the servers will clear filetransfer records from
Message Management > File Transfer Monitoring
or
Monitoring > File Transfers
.
Activate coldstart
Determines if cold start processing should be automatically started upon receipt of anMT 082 report (with cold start indication) for FIN, or an xsys.005.002 report forInterAct and FileAct.Possible values are
Acti vate
and
Deacti vate
The default value is
Acti vate
.Changes to this parameter take effect immediately.
FIN CS TimeMargin
Time margin (in minutes) applied by Alliance Access when performing cold startMT082 post-processing.The minimum value is 0 and the maximum value is 780. The default value is 15.Changes to this parameter take effect immediately.
W3C - PrimarySAG list
List of primary SWIFTNet connections to be used for handling W3C signaturecomputation and verification requests submitted with no SWIFTNet connections.This is a comma-separated list of SWIFTNet connections, which is by default empty.This parameter is applicable in the context of W3C signature Web services, eitherexposed by means of a Web service or the Connector for T2S. For more information,see the Alliance Access T2S Web Services Developer Guide or the Connector for
T2S Release Letter.
W3C -Secondary SAGlist
List of secondary SWIFTNet connections to be used to handle W3C signaturecomputation and verification requests submitted with no SWIFTNet connections,when none of the SWIFTNet connections in the
W3C - Primary SAG list
is available.This is a comma-separated list of SWIFTNet connections, which is by default empty.This parameter is applicable in the context of W3C signature Web services, eitherexposed by means of a Web service or the Connector for T2S. For more information,see the Alliance Access T2S Web Services Developer Guide or the Connector for
T2S Release Letter.
5.1.16Network
List of network parameters
ParameterDescriptionSWIFTNetBatching Timeout
Maximum delay (in seconds) that Alliance buffers an input message before it issent. SWIFT determines the final value used. Default value: 2.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.
SWIFTNet Maxbatch count
Maximum number of FIN APDUs that can be sent in a single DATA PDU. SWIFTdetermines the final value used. Default value: 30.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.
Alliance Access 7.1 on Alliance Web Platform50Security Guide
ParameterDescriptionReconnect Timer
Indicates the time (in minutes) after which the SWIFTNet Interface component(SNIS) attempts to reconnect an interrupted profile. Default value: 20. Minimum: 1.Maximum: 300.You must restart the SWIFTNet Interfaces Services (SNIS) component, to applythe changes to this parameter.
Preferred Order
Used by the Message Preparation application to propose a default value for thepreferred network when the receiver is a wild address, that is, the network addressis not in the correspondent file. The default display order is
SWIFT
,
APPLI
,
OTHER
,
IPLA
.Changes to this parameter take effect when the application is restarted.
Usersync - MaxRetries
Specifies the number of attempts that are allowed to reconnect a failedcommunication session with the SWIFT network. Default value: 20.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.
Usersync - MaxTime
Specifies the duration (in minutes) for which attempts to reconnect a failedcommunication session with the SWIFT network are made. Default value: 30.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.
Usersync - RetryTimer
Specifies the time-out period (in seconds) between reconnect retries. Default value:120.You must restart the SWIFT Interfaces Services (SIS) component, to apply thechanges to this parameter.
5.1.17Performance
List of performance parameters
ParameterDescriptionActiveCorrespondent
Controls whether correspondents are checked to see whether they have an activestatus, before sending a message. The possible values are "On" or "Off". Defaultvalue: On.You must restart the SWIFTNet Interfaces Services (SNIS) component, to applythe changes to this parameter.
FIN KeywordExtraction
Controls whether keywords are extracted from incoming (output) MT messages.The possible values are "On" or "Off". Default value: On.You must restart the SWIFTNet Interfaces Services (SNIS) component, to applythe changes to this parameter.
Maximum ReadRate
Disk I/O in MB/sec used to read from the database disks when a Recovery Backupis created. Minimum: 0. Maximum: 1024. Default value: 0. If the value is 0, thenmaximum disk I/O is used.Change to this parameter take effect at the next recovery backup creation.This parameter is ignored unless the Alliance servers are running and option
14:DATABASE RECOVERY
is licensed.
MQSAInterventions
Controls whether the writing of some interventions is suppressed. The possiblevalues are "None", "All", or "System". Default value: None.You must restart the SMQS component, to apply changes to this parameter.This parameter applies to the WebSphere MQ Interface for Alliance Access(MQSA). It does not apply to the WebSphere MQ Host Adapter.
Configuration and Security Parameters27 March 201551
ParameterDescriptionMX KeywordExtraction
Controls whether keywords are extracted from incoming (output) MX messages.The possible values are "On" or "Off". Default value: On.You must restart the SWIFTNet Interfaces Services (SNIS) component, to applythe changes to this parameter.
RoutingIntervention
Controls what types of interventions are suppressed. The possible values "All","System generated only", or "None". Default value: None.
5.1.18Print
List of print parameters
ParameterDescriptionMessage SearchResults
Specifies the maximum number of items that can be printed in a Message SearchReport. Default value: 1024. The value "0" means that no limit is set.
SkipInterventions
Specifies whether Printer message partners print notifications without system oruser interventions. This does not apply to transmission notifications. The defaultvalue is No, with notifications being printed with system or user interventions.Setting this parameter to Yes saves paper when notifications are printed.
ST200-likeFormat
Specifies whether Printer message partners print messages in an ST200-likeformat, with an eye-catcher and warning banner. This parameter has no effectwhen messages are printed to a file. Default value: No.
See also "Display/Print" on page 47.
5.1.19Queue
Queue parameter
ParameterDescriptionThreshold
Frequency of alarm generation - the number of messages that can be added abovea queue threshold or the number of overdue message instances before a newalarm will be generated. Minimum: 20. Maximum: 100. Default value: 20.Changes to this parameter take effect at the next alarm.
5.1.20Receiver
List of receiver parameters
ParameterDescriptionDefault HQ forMT074
Specifies the receiver for system messages 074. Default value:
SWHQBEBBBCT
.
Default HQ forMT090
Specifies the receiver for system messages 090. Default value:
SWHQNLNLXXX
.
5.1.21Reception
Reception parameter replaced by GUI option
As of Alliance Access 7.0.75, the
SnF RProf Resequencing
global system configurationparameter has been discontinued. It is replaced by an
OSN Resequencing
GUI option at the
Alliance Access 7.1 on Alliance Web Platform52Security Guide
individual Store-and-Forward reception profile level. As a result, Alliance Access applies OSNresequencing to a Store-and-Forward reception profile if its
OSN Resequencing
option isselected or if its
SAA_DO_RESEQ_<RPName>
environment variable is set to
On
. Alliance Accessdoes not apply OSN resequencing to a Store-and-Forward reception profile only when bothindicators are off.For more information on the
OSN Resequencing
GUI option, see the section on the
Configuration
tab of the
Reception Profile Details
window in the Configuration Guide.
5.1.22Reporting
Reporting parameters
ParameterDescriptionMail server address
Defines the HOST:PORT that will be used by theOperational Reporting mail server.
HOST
can beeither an IP address or a hostname.Changes to this parameter take effect immediately.
Activate Reporting
If set to
Activate
, Operational Reporting isactivated. This will copy all messages to thereporting data store, which may take some time,depending on the number of messages. Set thisparameter to
Deactivate
to deactivate OperationalReporting, which will remove all message datafrom the reporting data store.
5.1.23RMA
RMA parameter
ParameterDescriptionAuto Refresh
If this parameter is set to No, then the automatic refresh of the view lists is disabledin the Relationship Management application. Default value: Yes.You must restart the Relationship Management Application (RMA) component, toapply the changes to this parameter.
5.1.24Shutdown
List of shutdown parameters
ParameterDescriptionDelayed
After a request to stop the servers, this is the number of seconds delay before theGUI applications are terminated. Default value: 120.
Forced
After a request to stop the servers, this is the number of seconds delay before theserver processes are terminated. Normally the server processes stop before thistime has elapsed. Default value: 240.
Configuration and Security Parameters27 March 201553
5.1.25System
System parameter
ParameterDescriptionStartup Mode
This parameter enables Alliance Access to start automatically after the machinewhere the Alliance Access instance is installed is rebooted.On UNIX or Linux, this parameter can have the following values:•
Automati c
- Alliance Access starts as a result of starting the Alliance Accessbootstrap•
Manual
- An operator must explicitly start Alliance Access.Default value: Manual.On Windows, this parameter can have the following values:•
Servi ce
- Alliance Access runs as a Windows service under control of theAlliance Access Bootstrap service.In Service mode, mapped network drives cannot be used.
Tip
To start Alliance Access automatically after a reboot, select
Servi ce
and use the Windows Service Management interface toconfigure the Alliance Access Bootstrap service to startautomatically•
Normal
- Alliance Access does not run as a Windows service.Default value: Normal.
SNMP HeartbeatInterval
This parameter enables you to activate/deactivate the SNMP heartbeatfunctionality and, if activated, to define the number of seconds between twoSNMP heartbeats.Possible values are 0 and 120-900 (the number of seconds between two SNMPheartbeats). 0 means that the heartbeat functionality must not be activated.All values less than 120 mean the heartbeat is not active.Changes to this parameter will take effect at the next heartbeat or at most 900seconds later if the heartbeat is not active.
SNMP HeartbeatDist. List
This parameter enables you to provide the name of the distribution list to be usedfor sending SNMP heartbeat trap to SNMP servers.Create this distribution list and populate it with the SNMP server(s) to which theSNMP heartbeat must be sent.The list name can be up to 15 characters long.Changes to this parameter will take effect at the next heartbeat.
5.1.26Traffic Recon
Traffic Recon parameter
ParameterDescriptionDelivery Notif
If set to Yes, then Traffic Reconciliation generates notifications for each matchedmessage instance. Default value: Yes.
Alliance Access 7.1 on Alliance Web Platform54Security Guide
ParameterDescriptionFIN Mult.reconciliation
If set to yes, FIN messages can be reconciled multiple times.Default value: No.
Msgreconciliationcycle
Interval (in seconds) at which Alliance Access reconciles messages.Possible values 60-600. Default value: 300.Changes to this parameter take effect at the next reconciliation poll.
5.1.27WebSphere MQ
List of WebSphere MQ parameters
If the licence package
13:MQ HOST ADAPTER
is installed, then the following parameters areavailable:
ParameterDescriptionConnection Mode
Specifies the mode that the Web Sphere MQ interface of Alliance Access uses toconnect to a Queue Manager. The options are:•
Cl i ent
- The WebSphere MQ interface can connect at the same time to multipleQueue Managers which are located on the same host or on a different host asthe MQ Adapter.
Note
See the WebSphere MQ client and WebSphere MQ servercomponents in the WebSphere MQ Interface User Guide forinformation about setting the environment variables for"MQSERVER" and "MQ channel table".•
Server
- The WebSphere MQ interface can connect to one Queue Managerlocated on the same host as Alliance Access.Default value: Server.You must restart the Application Interface Services (MXS) component, to apply thechanges to this parameter.
Input MessageRate Limit
Limits the number of messages that Alliance Access reads per second from all theWebSphere MQ queues that are configured in Alliance Access.The default value is 0, which means that the incoming WebSphere MQ traffic is notlimited. Mininum: 0. Maximum: 999.Before you change this parameter, you must disable all the Websphere MQmessage partners.
Recovery Time -Initial
The time interval, in seconds, after which the first attempt to reopen thecommunication session with WebSphere MQ is made in case of a brokenconnection. Default value: 60.
Recovery Time -Increment
The increase of the time interval, in seconds, between consecutive attempts toreopen a WebSphere MQ session. Default value: 30.
Recovery Time -Max
The maximum time interval, in seconds, between consecutive attempts to reopen aWebSphere MQ session. Default value: 600.
5.2Security Parameters
Description
A number of security parameters exist in Alliance Access which apply globally to all operators.
Configuration and Security Parameters27 March 201555
The security parameters have default values, as outlined in "Classes of Security Parameters" onpage 56. After Alliance Access is installed, the Security Officers can change the values of theparameters by means of the Alliance Access Configuration. Only a Security Officer (left securityofficer or right security officer) can make changes to the values of any of the securityparameters, and the changes must be approved by both the left security officer and rightsecurity officer.For more information on changing parameters, see the section on security parameters in theConfiguration Guide.
5.2.1Classes of Security Parameters
5.2.1.1 Alarm
List of Alarm parameters
ComponentParameterDescriptionBSSPath of ScriptFile
Full pathname of the user-defined script that Alliance Access runswhen an Alarm Event occurs.It must be:•owned by the Alliance Administrator•located in a directory accessible by this user•UNIX or Linux: it must be compliant with the requirements of theUNIX or Linux exec system call, regarding the execution of aninterpreter file.Maximum length: 255Default value: none
5.2.1.2 Backup integrity
List of Backup integrity parameters
ComponentParameterDescriptionBSSBackupintegrity
Specifies the type of digest that is calculated to ensure the integrity ofarchive backups.Possible values are:•
Fast
- integrity of the backup is based on a digest covering themetadata.•
Ful l
- a second digest is added, covering the data in the backup.Default value:
Ful l
Alliance Access 7.1 on Alliance Web Platform56Security Guide
5.2.1.3 Mesg Archive
List of Mesg Archive parameters
ComponentParameterDescriptionBSSArchive Method
Possible values are:•
Normal
- create the archive (all messages must be completed).•
Destructi ve
- do not create archive, all messages must becompleted, and are deleted from the database.Default value:
Normal
.
5.2.1.4 Message
List of Message parameters
ComponentParameterDescriptionBSSCheckauthorisationexist
Indicates whether the existence of an RMA authorisation is checkedduring message entry or message modification.
Note
: If you have the licence option
07:STANDALONE REC
, thenthis parameter indicates whether an RMA check is performedwhatever the network is (OTHER included).Default:
Yes
.
MXSContinue onLAU failure
This parameter is only applicable for message partners configuredwith the WebSphere MQ connection method.This parameter is only applicable for message partners configuredwith the WebSphere MQ connection method.When this parameter is set to
Off
, Alliance Access will reject amessage that arrives on an input message partner if the LAU checkfails. At the same moment, the message partner sessions will bestopped.When the parameter is set to
On
, messages arriving from an inputmessage partner that fail the Local Authentication check will still beaccepted by Alliance Access, and the message partner will continueto process messages, while a specific event is generated. In such asituation, you should check the routing rules of all message partnersensure that the appropriate behaviour is achieved (for example, tomove the messages to the _MP_emi_sec queue and force them topass through authorisation). Assigning the messages to a specificUNIT can help you to control who can handle these exceptions, aswell as locating them back in the message database.To change the default behaviour, the routing rule(s) handling the LAUfailure using the new LAU_RESULT_FAILURE routing keywordshould be set as first routing rule(s) of _AI_from_APPLI.For changes to this parameter to take effect, the Application Interfacecomponent must be restarted.
BSSFIN CS timemargin
Time margin (in minutes) applied by Alliance Access whenperforming cold start MT082 post-processing.The minimum value is
0
and the maximum value is
780
. The defaultvalue is
15
. Changes to this parameter take effect immediately.
Configuration and Security Parameters27 March 201557
ComponentParameterDescriptionBSSJournalise MsgText
If this parameter is set, then the text block from the message isincluded in the message event description. A change to thisparameter takes effect after the SWIFT Interface component isrestarted.Possible values are:•
Message Text J ournal i sed
•
Message Text Not J ournal i sed
Default value:
Message Text J ournal i sed
BSSMessageRepair Action
Indicates the type of action that is performed by default on theoutstanding live messages, which are flagged with possible duplicateemission (PDE), if the database is partially recovered.Possible values are:•
Prompted
: the user can select an option when the tool islaunched.•
None
: the messages are routed as defined•
Compl ete
: the messages are completed•
I nvesti gate
: the messages are routed to the
_MP_recovery
queue for investigation.Default value:
Prompted
This parameter appears when either
14:DATABASE RECOVERY
or
13:HOSTED DATABASE
are licensed.
SISMT398messageextraction
Specifies whether the SWIFT Interface component performs aproprietary authentication code (PAC) verification on messagesembedded in the MT 398. A change to this parameter takes effectafter the SWIFT Interface component is restarted.Possible values are:•
Off
•
On
Default value:
Off
.
BSSRe-activationScope
Determines whether completed messages are re-activated at arouting point.Possible values are:•
Ful l
: all the allowed routing and exit points appear.•
Parti al
: only exit points appear.•
Restri cted
: The target re-activation queue is selectedautomatically, as follows: – input messages: Text Modification queue – output messages: Modification After Reception queueDefault value:
Ful l
.
Alliance Access 7.1 on Alliance Web Platform58Security Guide
ComponentParameterDescriptionSISRetrievedmessageextract
Indicates whether the SWIFT Interface component extracts thecontents of MT 021 of output messages into separate messages. Achange to this parameter takes effect after the SWIFT Interfacecomponent is restarted.Possible values are:•
On
•
Off
Default value:
Off
.
5.2.1.5 Operator
List of Operator parameters
ComponentParameterDescriptionBSSPrefix OperatorName
If this parameter is activated, then Alliance Access validates the BIC8prefix of an operator name when the operator is created. If anoperator name is modified, then the name is validated only if theoperator name already has a BIC8 prefix.The prefix must meet the following conditions to be valid:•The prefix must be a BIC8 (upper case) followed by anunderscore (_) character.•The BIC8 must be one of the licensed destinations of the AllianceAccess instance (either production, or Test and Training).•If the
creating
operator has one or more restricted BICdelegations, then the prefix must be a BIC that is delegated to the
creating
operator.•If the
created
operator has one or more restricted BIC delegations,then the prefix must be a BIC that is delegated to the
created
operator.•If the
created
operator has one or more restricted profiledelegations, then the names of the selected profiles must startwith a BIC8 that is delegated to the
creating
operator.This parameter is useful for institutions that use or manage multipleBICs.Possible values are:•
Yes
: Validate the prefix of an operator name•
No
: Deactivate the validation of the prefixDefault value is
No
.
Configuration and Security Parameters27 March 201559
ComponentParameterDescriptionBSSRestrictDelegation
The left security officer and right security officer of a service bureauuse this feature when creating local security officers. Indicateswhether restrictions are applied for operator profiles, units, anddestinations.This parameter does not affect the left security officer and rightsecurity officer because they always have unrestricted access tooperator functions.Possible values are:•
Yes
: An operator who is adding a new operator can only selectoperator profiles, units, and licensed destinations from a restrictedlist.If set to
Yes
, then this parameter overrides the
RestrictFunctions
parameter.
No
: Delegation is not possible.Default value:
No
.
BSSRestrictFunctions
Specifies whether the operator-related functions (open, print, add,modify, approve, or remove) are restricted.Possible values are:•
Yes
:An operator with the appropriate entitlements can only performthese functions on the operators that belong to a subset of thesame units as the operator performing out the action.For more information, see "Definition of Units and RestrictFunctions" on page 80.•
No
: these functions are not restricted, and an operator with theappropriate entitlements can search for, open, print, add, modify,approve, or remove operators belonging to any unit.Default value: No.This parameter does not affect the left security officer and rightsecurity officer because they always have unrestricted access tooperator functions.
BSSSoftwareOwner Profile
Specifies the operator profile that is assigned as the owner of thesoftware. An operator with that profile can perform specific actions onAlliance Access, such as exporting configuration data or querying thedatabase for messages or events.If this parameter is empty or invalid, then the software owner operatoris disabled.The servers must be restarted for changes to this parameter to takeeffect.
Alliance Access 7.1 on Alliance Web Platform60Security Guide
5.2.1.6 Password
List of Password parameters
ComponentParameterDescriptionBSSIllegal Patterns
Specifies the patterns of characters that are not allowed inpasswords. An error message appears if any operator tries to createa password which contains one of the defined characters orcharacter strings.Both security officers must approve any changes to this parameter.Type a string consisting of patterns separated by
|
. Changes to thisparameter take effect the next time an operator changes a password.Maximum length: 255For example,
@| $| Bob
prohibits the use of the following characters inpasswords:
@
,
$
, or
Bob
BSSMaster Period
Specifies the number of days after which the security officers have tochange the Master Passwords.The possible values are
0
through
365
.Default value:
100
.A value of
0
means that the security officers are never forced tochange their passwords.
BSSMax Bad Pwd
Specifies the maximum number of times that a user can enterincorrect passwords before the sign-on action is refused. Bothsecurity officers must approve any changes to this parameter.Alliance Access monitors invalid password entries. A parameter canbe used to disable an operator who has not entered a valid passwordwithin a defined number of attempts. When disabled, an operatorcannot sign on to Alliance Access (even with the correct password)until a security officer or an operator with the correct permissions re-enables it.If a security officer exceeds the specified number of attempts (whensigning on or when changing their password) , they are disabled for aperiod of 10 minutes.Possible values are
0
through
100
Default value:
5
.If the value is set to
0
, then an unlimited number of password entryattempts is allowed (this is not recommended for security reasons).
BSSMin PwdLength
Specified the minimum length of the user password.Possible values are
4
through
20
.Default value:
6
.
BSSNbr RetainedPwd
Specifies the number of user passwords that Alliance Access keepstrack of.Whenever a user password is successfully updated, the old userpassword is written to that user's password history file. AllianceAccess can check a user's password history file and prevent the userfrom changing the password to one that has been used before.Both security officers must approve any changes to this parameter.Possible values are
0
through
20
.Default value:
10
.
Configuration and Security Parameters27 March 201561
ComponentParameterDescriptionBSSReset PeerOfficer Passwo
Specifies whether the left security officer can reset the right securityofficer's password to the Master Password which was valid at thetime of installation, and vice versa. This is useful if a security officerforgets a password. An event is written to the Event Log each timethat a password is reset.Possible values are:•
Yes
•
No
: the security officers cannot reset each other's password.Default value:
No
.
BSSSec Officer OneTime Pwd
Activates the use of one-time passwords for the security officers. Thevalue of this parameter applies to both security officers.Both security officers must approve a change to this parameterbefore it takes effect. Until both security officers have not approvedthe change, the security officers must log on using their user-definedpassword.Possible values are:•
Yes
: If the Sec Officer OTP Srv Group parameter is correctly setand approved, then the left security officer and right securityofficer can use one-time passwords.•
No
: the master passwords have to be used at the next sign-on ofthe left security officer and the right security officer, and theirpassword must be changed as if it was the first logon.Default value:
No
.
BSSStrongValidation
Specifies whether passwords are validated as being strong from asecurity perspective. Changes to this parameter become effectivewhen an operator changes the password. If the new password failsthe strong validation test, then an appropriate error appears to theoperator indicating that the password is not compliant with the strongvalidation rules.Both security officers must approve any changes to this parameter.Possible values are:•
Yes
: validates that the user password contains a combination ofalphabetic and numeric characters, with at least 1 numericcharacter.•
No
Even if the value is set to
No
, all the other validation rules (such asillegal pattern verification and minimal number of characters)remain applicable.Default value:
No
.
BSSUser Period
Specifies the number of days that a user can use a password beforethe password must be changed. Both security officers must approveany changes to this parameter.Possible values are
0
through
120
.If the value is set to
0
, then passwords are valid indefinitely (this isnot recommended for security reasons).Default value:
30
.
Alliance Access 7.1 on Alliance Web Platform62Security Guide
ComponentParameterDescriptionBSSSec OfficerOTP Srv Group
Specifies the authentication (OTP) server group that is assigned to asecurity officer if both security officers are configured to useauthentication by means of the Sec Officer One Time Pwdparameter.This is a textual parameter. By default, this value is empty.
5.2.1.7 Reports
List of Reports parameters
ComponentParameterDescriptionBSSRoot Path forReport File
The path name which is the top level of the directory tree wherereport files are stored.Maximum length: 64The default location is:•UNIX or Linux:
$ALLI ANCE/ usrdata/ report
•Windows:
C: \ Al l i ance\ Access\ usrdata\ report
5.2.1.8 RMA
List of RMA parameters
ComponentParameterDescriptionRMSAuto AcceptUpdates
Indicates whether Alliance Access automatically applies the updatesthat it receives for an Enabled authorisations-to-send.A change to this parameter is immediately taken into account.Default value:
No
RMSClean up StaleAuth.
Specifies the minimum number of days that an authorisation or aquery must be kept before it can be removed.A change to this parameter becomes effective immediately.Possible values are
1
through
365
.Default value:
180
RMSNeeds StatusConfirmation
Indicates whether an operator must confirm the revocation orrejection of an authorisation.A change to this parameter becomes effective immediately.Default value:
Yes
Configuration and Security Parameters27 March 201563
5.2.1.9 Signoff
List of Signoff parameters
ComponentParameterDescriptionBSATimeout
Specifies the number of seconds after a Signon Timeout occurs thatan operator can be inactive on Alliance Workstation before theoperator is logged off automatically from Alliance Workstation.Possible values are
0
through
3600
.Default value:
1800
If the value is set to
0
, then the Alliance Workstation is not signed offautomatically.
BSSWS SessionTimeout
The number of seconds that a web-service operator session canremain inactive before the session is stopped and removed.The possible values are
1800
through
5400
. Default value:
2700
.
5.2.1.10 Signon
List of Signon parameters
ComponentParameterDescriptionBSSMultiple
Specifies the numbers of concurrent sign-ons to Alliance Access thatthe same operator is permitted to perform.Possible values are
1
through
10
.Default value:
1
For example, if the value is set to
2
, then the operator can sign on tothe same instance of Alliance Access from two different AllianceWorkstations. However, an attempt to log on from a third Workstationwill be rejected.If a login attempt fails because the maximum number of sessions forthe operator has been exceeded and the operator attempts to log inagain, a prompt is displayed that asks if Alliance Access canterminate the session that has been idle for the longest time. If theoperator accepts, the login proceeds. Otherwise, the login is rejected.
BSATimeout
Specifies the number of seconds that an operator can be inactive,before the operator has to re-enter the password. For moreinformation, see "Use of timeout parameters".Possible values are
60
through
28800
.Default value:
600
Use of timeout parameters
Following a successful sign-on to Alliance Access, an inactivity timer is started, which is reseteach time an operator performs some activity within Alliance Access. When the inactivity timerexpires, all windows on the screen are frozen. The same operator must re-enter a passwordbefore being allowed to continue. Having re-entered the correct password, all windows arereinstated and the operator can continue work.This feature helps to prevent unauthorised users from using Alliance Access, if an operator iscalled away. It is not intended to replace the normal practice of signing off from Alliance Access,for example, when an operator leaves to take a break.
Alliance Access 7.1 on Alliance Web Platform64Security Guide
Alliance Access uses a total of four session timeout parameters related to operator sign-on,three of which are global security configuration parameters:•
Signon Timeout
•
Signoff Timeout
•
WS Session Timeout
In addition, the operator profile definition contains the following parameter:
Access Control >Signon > WS Session Timeout
.Alliance Web Platform contains the
Session Expiry Timeout
parameter, which is found in theconfiguration of the Alliance Web Platform 7.0 package.On Alliance Web Platform, when the value of the
Session Expiry Timeout
parameter is smallerthan the value of the
WS Session Timeout
parameter, and when an operator is inactive for atime period equal to the parameter
Session Expiry Timeout
, Alliance Web Platform ends thesession. The message "You have been logged out because the user session expired" isdisplayed and you must re-enter the operator name and password. This is the recommendedset-up and behaviour.On Alliance Web Platform, when the value of the
WS Session Timeout
parameter is smallerthan the value of the
Session Expiry Timeout
parameter, and when an operator is inactive fora time period equal to the value of the
WS Session Timeout
parameter, Alliance Access endsthe session. The operator does not see this until he tries to perform an action, when a messagepop-up is displayed, as follows:•For the RMA or Configuration GUI package, the following message is displayed: "YourAlliance Access/Entry session is no longer valid. Please logout and login again."•For the Message Management GUI package, the following message is displayed: "Failed tocommunicate with Alliance Access/Entry. The connection to Alliance Access/Entry hasdropped." In this case, it is also necessary to log out and log in again.•For the Monitoring GUI package, there is a built-in mechanism to keep the session alive,therefore the sessions never expire.
Note
If the value of the
WS Session Timeout
parameter in the operator profile is set to
0
, then the value of the global
WS Session Timeout
parameter is taken intoaccount. If the value of the
WS Session Timeout
parameter in the operator profileis other than
0
, then this value is used by the application.On Alliance Workstation, when an operator is inactive for a time period equal to the value of the
Signon Timeout
parameter, a pop-up is displayed that prompts the operator to re-enter hispassword. If the operator does not provide his password, then the pop-up disappears after aperiod of time equal to the value of the
Signoff Timeout
parameter.
Configuration and Security Parameters27 March 201565
5.2.1.11 System
List of System parameters
ComponentParameterDescriptionIPLAAllow StartingIPLA
Indicates if the Integration Platform (IPLA) component can be started.Possible values are
Yes
and
No
.Default value:
No
Changing the value from
Yes
to
No
is considered the next time thatthere is an attempt to start IPLA, either manually or when AllianceAccess starts. Changing the value from
No
to
Yes
allows starting theIPLA component manually.If the IPLA component has been stopped, it must be started manuallyeven if the value is set to
Yes
. Afterwards, the IPLA component willstart automatically.The security mechanisms of Alliance Access (such as the calculationof a database signature per data record) protect the messages andfiles processed by IPLA.
SSSAuthenticateMT971
Indicates whether MT971 must be authenticated. A change to theparameter will be taken into account immediately.Default value:
Yes
BSSDisable Period
The number of calendar days during which an enabled operator mustsign on to Alliance Access. Otherwise, the status is changed todisabled.Possible values are
0
through
999
.Default value:
0
If this parameter is set to 0, then operators are not disabledautomatically, if they do not sign on.A value of 0 cancels automatic disable. Changes to this parameterwill take effect at midnight or at the next restart of the Allianceservers.
Alliance Access 7.1 on Alliance Web Platform66Security Guide
ComponentParameterDescriptionBSSRPCAuthentication
Communication with Alliance Web Platform is always started withSSL enabled, and server authentication is required. Therefore,changes to this parameter do not affect the communication withAlliance Web Platform.For Alliance Workstation, this parameter specifies whether thecommunication between Alliance Access and Alliance Workstation isencrypted. Only when the parameter is set to "Data Integrity" or"Data Confidentiality" can the Alliance Access servers initialise thecommunication process with SSL enabled. If SSL is enabled, thenAlliance Workstation can also use Server Authentication. For moreinformation, see the System Management Guide.This parameter provides additional security checks on clientprocesses that make Remote Procedure Calls (RPC) to serverprocesses.Possible values are:•
Off
- processes making RPCs are not checked to ensure that theyare authenticated.•
Process Authenti cati on
- processes making RPCs are checkedto ensure that they are authenticated.•
Data I ntegri ty
- in addition to Process Authentication, Alliancecalculates a check value based on the character field data in theRPC call. The check value and the RPC call are passed to theserver. The server recalculates the check value from the RPCdata, and compares it to the check value that it received. Thisensures the integrity of the RPC data. If any changes have beenmade to the data, then the check values will not match.•
Data Confi denti al i ty
- in addition to Data Integrity, thefollowing RPC call data is encrypted to ensure confidentiality: – all fields that are currently encrypted in the database (such asthe operator password). – all message details that are derived from the message text.Default value:
Process Authenti cati on.
Alliance Access must be restarted for changes to this parameter totake effect.
BSSSoftware Checkat Startup
Indicates whether the system runs the Integrity Verification Tool tocheck the integrity of the software when Alliance Access is started.Default value:
Yes
Data confidentiality
If a large number of message templates are assigned to a unit, then using the higher levels ofRPC authentication affects the performance of the Message Creation entity. When the DataConfidentiality option is used, an operator who belongs to that unit will find that the MessageCreation entity opens very slowly. If more than 50 message templates are in use, then it isrecommended that you use the low speed mode setting, which allows fewer items to bedisplayed more quickly. At this setting, only 50 records are retrieved each time that a list ofitems appears.
Configuration and Security Parameters27 March 201567
Warning
The Data Confidentiality mode is CPU-intensive. When selected, it significantlydecreases the overall throughput of Alliance Access. Therefore, this mode is notrecommended for high-throughput configurations.
5.2.1.12 User Mode
List of User Mode parameters
ComponentParameterDescriptionBSSHousekeepingUser Mode
In housekeeping mode either a single operator is allowed to sign onor multiple operators are allowed to sign on.Possible values are:•
Si ngl e
•
Mul ti pl e
Default value:
Si ngl e
.Alliance Access must be restarted for changes to this parameter totake effect.
5.2.1.13 User Space
List of User Space parameters
ComponentParameterDescriptionBSSRoot Path forUser Space
Location where the User Space directories are to be created. Thesedirectories are associated to operators using the Web Platform.Maximum length: 64•Windows:
C: \ Al l i ance\ Access\ usrdata\ userspace
•UNIX or Linux:
$ALLI ANCE/ usrdata/ userspace
Alliance Access 7.1 on Alliance Web Platform68Security Guide
6User Management
6.1Management of User Accounts
Overview
Alliance Access uses various security techniques to control access to user accounts, as outlinedin the following sections.
6.1.1LDAP User Authentication
Why use LDAP authentication
LDAP allows institutions to use any existing user directories to control access to a range ofAlliance products. LDAP directories can be used to authenticate (user name and password) theusers defined in those Alliance products. LDAP offers numerous additional security rules forpassword validation, as well as several other features to meet the needs of the most demandingpassword policies. LDAP allows the implementation of specific security rules in addition to thoseoffered by default in Alliance Access.
LDAP overview
D 0 5 4 0 1 7 7
LDAPdirectory Alliance AccessserverLogon:User Interface
ResponseQueryQuery
How LDAP authentication works
LDAP is used to authenticate the users only (username and password verification). The usersare created on the Alliance Access server, but can be mapped to an LDAP identifier used forverification of the credentials. Profiles and units are assigned to users on the Alliance Accessserver.The following process occurs when LDAP authentication is used:1.A user logs on to a user interface (Alliance Workstation, or Alliance Web Platform) with thelocal operator name and the LDAP password.2.The Alliance Access server receives the logon request and checks whether the operator isauthenticated locally, through One-Time Passwords or through LDAP. If the operator isauthenticated locally or through One-Time Passwords, then the behaviour is as describedin the previous sections.3.If the operator is authenticated through LDAP, then the operator name is mapped to anLDAP identifier, if present. Otherwise, the operator nickname is forwarded to the LDAPserver.4.The password and the LDAP identifier or operator nickname are forwarded to the LDAPserver.
User Management27 March 201569