DMP Security UX Browser Session Authentication
Topic
Why does the DMP-8000 user interface now display a login page when accessed from a web browser?
DMP browser session authentication adds login protection to the DMP user interface. When a user navigates to the DMP UX from a browser, the DMP presents a login page before allowing the user to view or navigate the interface.
This enhancement prevents unauthenticated users from opening the DMP UX and viewing configuration or system information.
Environment
- DMP-8000
- DMP web user interface
- Browser-based access
- DMP software version that includes browser session authentication
Steps
What Changed
After a DMP is updated to a version that supports browser session authentication:
- Open the DMP address in a supported web browser.
- The DMP 8000 – Please log in page appears.
- Enter the applicable DMP username and password.
- Select Log In to access the DMP UX.
No configuration change is required to enable the browser login page. The authentication behavior is applied by the supported DMP software version.
Figure 1: DMP-8000 browser session authentication login page.
Important Distinction: Browser Authentication and GET Authentication
Browser session authentication and GET authentication are separate security behaviors.
Browser session authentication:
- Requires a user to log in before navigating the DMP UX in a browser.
- Does not require a configuration change to enable.
- Does not change the existing GET authentication configuration setting.
- Is designed so applications that do not yet support GET authentication continue to function.
GET authentication:
- Is controlled separately through the DMP configuration.
- Must be explicitly enabled if authentication is required for applicable API calls.
- Is not automatically enabled by the appearance of the browser login page.
- Important: Successfully logging in to the DMP UX does not mean that API calls require authentication. API calls do not require authentication unless GET authentication is explicitly enabled in the DMP configuration.
Why This Change Was Made
Previously, a person who could reach the DMP address could navigate through the UX and view information without first authenticating. Browser session authentication places a login requirement in front of the UX to restrict that access.
Expected Behavior
The following behavior is expected after installing a DMP version that contains this enhancement:
|
Scenario |
Expected result |
|
A user opens the DMP UX in a browser |
The DMP login page appears. |
|
Browser session authentication is introduced through the supported DMP version |
No configuration change is required. |
|
An integrated application does not support GET authentication |
The browser-session change is designed not to break that application. |
|
An application sends an API call while GET authentication is disabled |
The API call does not require authentication as a result of the browser login feature alone. |
|
GET authentication is explicitly enabled in the DMP config |
Applicable API calls require authentication according to that configuration. |
KB ID: 000032476
DISCLAIMER: Use of this content may void the equipment warranty, please read the disclaimer prior to performing any service of the equipment.
DAKTRONICS DOES NOT PROMISE THAT THE CONTENT PROVIDED HEREIN IS ERROR-FREE OR THAT ANY DEFECTS WILL BE CORRECTED, OR THAT YOUR USE OF THE CONTENT WILL PROVIDE SPECIFIC RESULTS. THE CONTENT IS DELIVERED ON AN "AS-IS" AND "AS-AVAILABLE" BASIS. ALL INFORMATION PROVIDED IN THIS ARTICLE IS SUBJECT TO CHANGE WITHOUT NOTICE. DAKTRONICS DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTIES OF ACCURACY, NON-INFRINGEMENT, MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. DAKTRONICS DISCLAIMS ANY AND ALL LIABILITY FOR THE ACTS, OMISSIONS AND CONDUCT OF YOU OR ANY THIRD PARTIES IN CONNECTION WITH OR RELATED TO YOUR USE OF THE CONTENT. ADJUSTMENT, REPAIR, OR SERVICE OF THE EQUIPMENT BY ANYONE OTHER THAN DAKTRONICS OR ITS AUTHORIZED REPAIR AGENTS MAY VOID THE EQUIPMENT WARRANTY. YOU ASSUME TOTAL RESPONSIBILITY FOR YOUR USE OF THE CONTENT AND ANY LINKED CONTENT. YOUR SOLE REMEDY AGAINST DAKTRONICS FOR DISSATISFACTION WITH THE CONTENT IS TO STOP USING THE CONTENT. THIS LIMITATION OF RELIEF IS A PART OF THE BARGAIN BETWEEN THE PARTIES.
The above disclaimer applies to any property damage, equipment failure, liability, infringement, or personal injury claim arising out of or in any way related to your use or application of the content, whether such claim is for breach of contract, tort, negligence or any other cause of action.