Jump to content
View in the app

A better way to browse. Learn more.

FMForums.com

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

User Account Management System

Featured Replies

  • Newbies

I'm new to this forum but hope someone can clarify something that I am working on. I recently found a solution in Advisor magazine from 2006 for a security system. I put it together and read over ever detail but found it omitted some information to complete it. It is made with local scripts for each file and controlled by scripts in the Main FIle. It is a 3 part series. Normally there is a file download but not in this case so I can't trace down the problem. Is anyone familiar with this system? The system uses Table Occurrences in each file based on the main file fields. I am having a hard time understanding how this works. I've deconstructed the system and understand everything but that. When I put it together it did not work. Has anyone got a completed sample that works? I called the pub and they couldn't help. I'm sure it is a minor issue that needs to be addressed.

I [color:red]strongly recommend that you avoid using ersatz systems of this type. Almost always, they are profoundly insecure.

Instead, if you have multiple files and muiltiple accounts, use the external server authentication option that comes with FileMaker Server and FileMaker Pro.

Steven

  • Author
  • Newbies

You mentioned using an external server authentication. I like the idea since I'm using a dedicated G4 running Leopard which goes to sleep. I understand a remote user can wake the machine using that setting in FIlemaker which is not possible with the present Filemaker setting. Is there any documentation on how to set up the external server for this? Can it be done on the hosting machine?

RE: ESA

If someone (lets say employee going to setup a rival company) steals a set of files (lets say backups) and sets up the same user group names on there own server, can they not get access to all of the data on every level without the need for knowing passwords?

best

Stuart

I'm using a dedicated G4 running Leopard which goes to sleep.

If you're using FileMaker Pro, I recommend NOT to allow the computer cpu to sleep. Screen sleep is Ok.

If someone (lets say employee going to setup a rival company) steals a set of files (lets say backups) and sets up the same user group names on there own server, can they not get access to all of the data on every level without the need for knowing passwords?

Yes... I think it's called spoofing.

However, once somebody has physical access to the files there are lots of ways they can crack into them. Spoofing the External Authentication is probably the *hardest* way to do it: a password cracker would be easier.

IIRC it's never been recommended to externally authenticate the Full Access account, probably for this very reason.

What Vaughan said. And this is the reason we recommend never authenticating a Full Access account externally.

Steven

  • 1 year later...

Hi Steven,

Do you think FM11 has improved the structure enough to not have to use ESA?

-Karen

No, you should use External Server Authentication wherever possible. It's not a question of improving in FileMaker Pro 11.

External Server Authentication is the best way to manage multiple Accounts and Groups across multiple files.

See the Tech Brief on External Server Authentication.

Steven

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.