<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://docs.opendap.org/index.php?action=history&amp;feed=atom&amp;title=NetworkServerSecurity</id>
	<title>NetworkServerSecurity - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://docs.opendap.org/index.php?action=history&amp;feed=atom&amp;title=NetworkServerSecurity"/>
	<link rel="alternate" type="text/html" href="https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;action=history"/>
	<updated>2026-06-10T12:02:34Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8880&amp;oldid=prev</id>
		<title>Jimg: /* For our web sites */</title>
		<link rel="alternate" type="text/html" href="https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8880&amp;oldid=prev"/>
		<updated>2012-07-30T19:24:59Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;For our web sites&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 19:24, 30 July 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l22&quot;&gt;Line 22:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 22:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;makes it public knowledge, albeit somewhat obscure.&amp;lt;/blockquote&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;makes it public knowledge, albeit somewhat obscure.&amp;lt;/blockquote&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Private web sites, or private areas of a web site, &amp;#039;&amp;#039;must&amp;#039;&amp;#039; &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;also &lt;/del&gt;be protected with a password.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Private web sites, or private areas of a web site, &amp;#039;&amp;#039;must&amp;#039;&amp;#039; be protected with a password.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==  Incident Response Policies ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==  Incident Response Policies ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Jimg</name></author>
	</entry>
	<entry>
		<id>https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8879&amp;oldid=prev</id>
		<title>Jimg: /* Policy */</title>
		<link rel="alternate" type="text/html" href="https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8879&amp;oldid=prev"/>
		<updated>2012-07-30T19:24:22Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Policy&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 19:24, 30 July 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l5&quot;&gt;Line 5:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 5:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is our policy regarding the security of the software we distribute.  The intent of this policy is to increase the security of that software and to document the steps we have taken to produce that increase. It is a public policy to promote transparency.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is our policy regarding the security of the software we distribute.  The intent of this policy is to increase the security of that software and to document the steps we have taken to produce that increase. It is a public policy to promote transparency.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, because we run many sites which are used to provide access to our source code, other collaborative tools and also provide the main venue for software downloads by users, site security is also a component of this &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;interim &lt;/del&gt;policy.  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, because we run many sites which are used to provide access to our source code, other collaborative tools and also provide the main venue for software downloads by users, site security is also a component of this policy.  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This policy does not apply to third-party distribution of our software.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This policy does not apply to third-party distribution of our software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Jimg</name></author>
	</entry>
	<entry>
		<id>https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8878&amp;oldid=prev</id>
		<title>Jimg: /* Policy */</title>
		<link rel="alternate" type="text/html" href="https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8878&amp;oldid=prev"/>
		<updated>2012-07-30T19:24:07Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Policy&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 19:24, 30 July 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l7&quot;&gt;Line 7:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 7:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, because we run many sites which are used to provide access to our source code, other collaborative tools and also provide the main venue for software downloads by users, site security is also a component of this interim policy.  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, because we run many sites which are used to provide access to our source code, other collaborative tools and also provide the main venue for software downloads by users, site security is also a component of this interim policy.  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;interim &lt;/del&gt;policy does not apply to third-party distribution of our software.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This policy does not apply to third-party distribution of our software.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== For software we develop ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== For software we develop ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Jimg</name></author>
	</entry>
	<entry>
		<id>https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8877&amp;oldid=prev</id>
		<title>Jimg: /* Interim Policy */</title>
		<link rel="alternate" type="text/html" href="https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=8877&amp;oldid=prev"/>
		<updated>2012-07-30T19:23:50Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Interim Policy&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 19:23, 30 July 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== OPeNDAP Security Policy and Procedures ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== OPeNDAP Security Policy and Procedures ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Interim &lt;/del&gt;Policy ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Policy ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;an interim &lt;/del&gt;policy regarding the security of the software we distribute.  The intent of this policy is to increase the security of that software and to document the steps we have taken to produce that increase. It is a public policy to promote transparency.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;our &lt;/ins&gt;policy regarding the security of the software we distribute.  The intent of this policy is to increase the security of that software and to document the steps we have taken to produce that increase. It is a public policy to promote transparency.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, because we run many sites which are used to provide access to our source code, other collaborative tools and also provide the main venue for software downloads by users, site security is also a component of this interim policy.  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, because we run many sites which are used to provide access to our source code, other collaborative tools and also provide the main venue for software downloads by users, site security is also a component of this interim policy.  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Jimg</name></author>
	</entry>
	<entry>
		<id>https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=7563&amp;oldid=prev</id>
		<title>Jimg: Created page with &quot;== OPeNDAP Security Policy and Procedures ==  == Interim Policy ==  This is an interim policy regarding the security of the software we distribute.  The intent of this policy is ...&quot;</title>
		<link rel="alternate" type="text/html" href="https://docs.opendap.org/index.php?title=NetworkServerSecurity&amp;diff=7563&amp;oldid=prev"/>
		<updated>2012-03-08T01:47:14Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== OPeNDAP Security Policy and Procedures ==  == Interim Policy ==  This is an interim policy regarding the security of the software we distribute.  The intent of this policy is ...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== OPeNDAP Security Policy and Procedures ==&lt;br /&gt;
&lt;br /&gt;
== Interim Policy ==&lt;br /&gt;
&lt;br /&gt;
This is an interim policy regarding the security of the software we distribute.  The intent of this policy is to increase the security of that software and to document the steps we have taken to produce that increase. It is a public policy to promote transparency.&lt;br /&gt;
&lt;br /&gt;
In addition, because we run many sites which are used to provide access to our source code, other collaborative tools and also provide the main venue for software downloads by users, site security is also a component of this interim policy. &lt;br /&gt;
&lt;br /&gt;
This interim policy does not apply to third-party distribution of our software.&lt;br /&gt;
&lt;br /&gt;
=== For software we develop ===&lt;br /&gt;
&lt;br /&gt;
We will have someone in the group review any changes we make before any software is released. The person performing the review must not be the person who wrote the software. This must be done for each release.&lt;br /&gt;
&lt;br /&gt;
=== For our web sites ===&lt;br /&gt;
&lt;br /&gt;
We will act as though all of our web sites, even those used for the SCM portal, are completely open.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;Since our project is open-source, it&amp;#039;s easy for people outside to see what we are doing and why. In most cases, &lt;br /&gt;
that&amp;#039;s good, but when we are addressing a security problem that is not yet general knowledge, putting a description &lt;br /&gt;
of that in Trac (in a ticket, for example, which might be referenced in a public mail list and thus indexed by Google)&lt;br /&gt;
makes it public knowledge, albeit somewhat obscure.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Private web sites, or private areas of a web site, &amp;#039;&amp;#039;must&amp;#039;&amp;#039; also be protected with a password.&lt;br /&gt;
&lt;br /&gt;
==  Incident Response Policies ==&lt;br /&gt;
&lt;br /&gt;
When/if OPeNDAP learns of an incident or vulnerability, all communication regarding that will be conducted using secure channels until we are prepared to make a general-audience announcement regarding the issue. When/if an organization reports such an incident or vulnerability, they will not be identified to other parties. An exception may be made if the notifier explicitly authorizes the use of their name or organization name (e.g., US CERT might notify us of a vulnerability and authorize us to refer to their vulnerability database in a general announcement we send to users).&lt;br /&gt;
&lt;br /&gt;
Because OPeNDAP represents a community of users, we will maintain a community communication tool so that announcements can be sent to interested parties in a timely manor. This tool will take the form of an email list and the use of the list will be restricted to security items or items which are likely to be of interest to the overwhelming majority or community members when those items relate directly to software which we have authored. The intent is to use the list frequently enough to ensure it is a robust social tool but still re-enforce the attitude that the information presented there is critically important.&lt;br /&gt;
&lt;br /&gt;
Announcements should alert users to the affected versions and provide any other information needed to reduce confusion. Users who do not have to upgrade should understand that.&lt;br /&gt;
&lt;br /&gt;
==  Procedures ==&lt;br /&gt;
&lt;br /&gt;
=== Code reviews ===&lt;br /&gt;
&lt;br /&gt;
All software must undergo thorough source-code reviews prior to public release. These reviews will include peer-reviews, performed by a designated Security Officer (SO) and automated reviews. Additionally, major changes in the architecture of the software will be reviewed by an external source qualified to conduct such a review.&lt;br /&gt;
&lt;br /&gt;
==== Peer Review ====&lt;br /&gt;
&lt;br /&gt;
Peer review of all software will be conducted by the SO and all vulnerabilities found will be addressed prior to release of the affected software. Until we develop our own internal guidelines, these reviews will be conducted using the [https://www.securecoding.cert.org/confluence/display/seccode/CERT+Secure+Coding+Standards CERT Secure Coding Standards], [https://www.securecoding.cert.org/confluence/pages/viewpage.action?pageId=637 CERT C++ Programming Language Secure Coding Standard] and the US CERT [https://buildsecurityin.us-cert.gov/daisy/bsi-rules/home.html Security Rules].&lt;br /&gt;
&lt;br /&gt;
Another aspect of Peer Review is checking the tools we use to build binaries to make sure that the platforms we build on are not using tools that will introduce security holes in those binaries. Look at [http://secunia.com/ Secunia] to check on reported issues for build tools.&lt;br /&gt;
&lt;br /&gt;
==== Automated Review ====&lt;br /&gt;
&lt;br /&gt;
Automated review of source code will also be conducted by either the SO or developer of the software (in the later case with oversight by the SO) and all vulnerabilities addressed prior to public release. [N.B. We are considering a tool which categorize issues found as &amp;#039;&amp;#039;critical&amp;#039;&amp;#039;, &amp;#039;&amp;#039;important&amp;#039;&amp;#039; and &amp;#039;&amp;#039;informational&amp;#039;&amp;#039;. We will amend this policy to reflect this distinction since the &amp;#039;&amp;#039;informational&amp;#039;&amp;#039; issues are often noise, but merit examination.] An automated static source review tool must be integrated into the nightly build process but those results will not be made available outside OPeNDAP (unlike the normal nightly builds&amp;#039; results) unless the OPeNDAP Board of Directors decides to amend this interim policy.&lt;br /&gt;
&lt;br /&gt;
==== External Review ====&lt;br /&gt;
&lt;br /&gt;
External reviews will be limited to major changes in the architecture of the software, with the exception that the SO may determine that such a review is in the best interests of OPeNDAP and/or its users. Because these reviews are very expensive and OPeNDAP is a non-profit entity with a very limited budget, use of an external audit will be limited. However, OPeNDAP is currently pursuing, and will continue to work toward, relationships that enable such reviews as part of its budget.&lt;br /&gt;
&lt;br /&gt;
=== Site Review/Setup ===&lt;br /&gt;
&lt;br /&gt;
When a new site is established within OPeNDAP, it should be &amp;#039;hardened&amp;#039; to reduce the likelihood that software such as MySQL, et c., can be compromised. Existing sites should be reviewed periodically to make sure they are still robust. This is because even though they were setup securely, software additions might introduce vulnerabilities and new vulnerabilities might crop up in old software (i.e.,  the vulnerability was really there all along, but was unknown).&lt;br /&gt;
&lt;br /&gt;
=== Personnel ===&lt;br /&gt;
&lt;br /&gt;
The Security Officer (SO) will be appointed/designated by the OPeNDAP CEO. The SO will provide final acceptance of all software before public release and such acceptance will constitute authorization to release the software.&lt;br /&gt;
&lt;br /&gt;
To improve the efficiency of the various review processes, OPeNDAP will obtain reasonable training for software developers.&lt;br /&gt;
&lt;br /&gt;
==== Secure Communication ====&lt;br /&gt;
&lt;br /&gt;
All OPeNDAP personnel will obtain GPG public/private keys and share their public key with all other OPeNDAP personnel or make their public key available on a public key server. OPeNDAP personnel are responsible for ensuring the integrity of their private keys and notifying people at once if they believe that integrity has been violated.&lt;br /&gt;
&lt;br /&gt;
=== Software Distribution ===&lt;br /&gt;
&lt;br /&gt;
All software released publicly after 1 June 2007 will be paired with a MD5 and/or SHA1 digest. The digest files will be available in an obvious location so that users can reasonably be expected to access them. The MD5 and SHA1 algorithms have been chosen because they represent a reasonable level of security while still being likely to be used by those who download the software (whereas digital signatures are &amp;#039;more secure&amp;#039; but less likely to be used).&lt;br /&gt;
&lt;br /&gt;
=== Terms ===&lt;br /&gt;
&lt;br /&gt;
;public release: A release of software which is made available for people outside of OPeNDAP. Internal releases of software do not need to undergo the full automated and peer review process (although the policy to maintain secure web sites must still be followed).&lt;br /&gt;
&lt;br /&gt;
;security: The likelihood that computers which run the data servers will compromised by network-based attacks such as Denial of Service attacks, remote command execution or other forms of electronic vandalism. Higher security reduces the likelihood.&lt;br /&gt;
&lt;br /&gt;
;software: In the context of these procedures, the term &amp;#039;&amp;#039;software&amp;#039;&amp;#039; refers to computer programs which are used by people to provide access to data. These programs are commonly called &amp;#039;servers&amp;#039; to distinguish them from &amp;#039;client&amp;#039; programs, which are used to access view/manipulate/ingest data which are served.&lt;br /&gt;
&lt;br /&gt;
;third-party distributions: Examples of third-party distributions are found on RPMFIND (http://rpmfind.userfriendly.net/) and other sites.&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
* See the [http://docs.opendap.org/index.php/Security#Resources Resources] section of the Security Working Group for more online info.&lt;/div&gt;</summary>
		<author><name>Jimg</name></author>
	</entry>
</feed>