{"id":2114,"date":"2018-11-30T18:20:03","date_gmt":"2018-11-30T12:50:03","guid":{"rendered":"https:\/\/www.idslogic.com\/blog\/?p=2114"},"modified":"2025-02-25T12:16:16","modified_gmt":"2025-02-25T06:46:16","slug":"securing-sitefinitys-administrative-user-interface-is-easy-with-these-tips","status":"publish","type":"post","link":"https:\/\/www.idslogic.com\/blog\/securing-sitefinitys-administrative-user-interface-is-easy-with-these-tips","title":{"rendered":"Securing Sitefinity\u2019s Administrative User Interface Is Easy with These Tips"},"content":{"rendered":"<p><span style=\"font-size: 14pt;\">Sitefinity is a powerful CMS that allows business owners to create a powerful web presence and offers personalized customer experience. It helps to deliver intuitive content that engages, converts and also retains the customers. Maintaining the security of your site is very important to gain the trust of your users.<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">And if you already have a Sitefinity website, then adding some extra layers of security to your site is needed to protect your site and its data.<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Here is how you can add that extra security to your administrative UI. Let me discuss the points in details:<\/span><\/p>\n<p><span style=\"color: #008000; font-size: 18pt;\"><strong>Set a Strong Password Policy: <\/strong><\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Hackers often use password cracking tools that are available in the market that helps to try various web login and password configurations. These login attempts are super fast and within a few hours or days, the automated tool is finally successful with a valid combination. <\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Since passwords that contain common keywords are often easier to guess, a good password makes it difficult to stumble on the combination of letters and numbers.\u00a0 So, take the step to enforce a strong password policy for your administrator and other users so that your access security is tight.<\/span><\/p>\n<hr \/>\n<p><span style=\"color: #008000; font-size: 18pt;\"><strong>Design Your Password Strength Policy: <\/strong><\/span><\/p>\n<p><span style=\"font-size: 14pt;\">To make your password strong increase the minimum required password length as this will help to determine the minimum characters or numbers that you need to set a new password. You can also set it to alphanumeric characters so that your password cannot be easily guessed. <strong><a href=\"\/sitefinity-support\/\">Sitefinity CMS supports<\/a><\/strong> storing the password in a clear, hashed or encrypted format.<\/span><\/p>\n<hr \/>\n<p><span style=\"color: #008000; font-size: 18pt;\"><strong>Add Signing Certificate for IdentityServer: <\/strong><\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Sitefinity comes with the implementation of IdentityServer since the version 10.x. This offers a lot of flexibility and security improvements and by default, the <strong><a href=\"\/content-management-system\/\">CMS<\/a><\/strong> uses an X.509 certificate to sign the Identity.<\/span><\/p>\n<p><a href=\"https:\/\/www.idslogic.com\/dedicated-sitefinity-developer\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-2971 size-full\" src=\"https:\/\/www.idslogic.com\/blog\/wp-content\/uploads\/2017\/02\/Hire-Sitefinity-Developer.png\" alt=\"Hire Sitefinity Developer\" width=\"790\" height=\"94\" srcset=\"https:\/\/www.idslogic.com\/blog\/wp-content\/uploads\/2017\/02\/Hire-Sitefinity-Developer.png 790w, https:\/\/www.idslogic.com\/blog\/wp-content\/uploads\/2017\/02\/Hire-Sitefinity-Developer-300x36.png 300w, https:\/\/www.idslogic.com\/blog\/wp-content\/uploads\/2017\/02\/Hire-Sitefinity-Developer-768x91.png 768w, https:\/\/www.idslogic.com\/blog\/wp-content\/uploads\/2017\/02\/Hire-Sitefinity-Developer-560x67.png 560w\" sizes=\"auto, (max-width: 790px) 100vw, 790px\" \/><\/a><\/p>\n<p><span style=\"font-size: 14pt;\"><br \/>\nThis is great and helps to prevent the attackers from changing or counterfeiting the security tokens that are needed to gain an unauthorized access to the resources. For extra benefits, you can also configure your Sitefinity CMS to use a private security certificate instead of the default one.<\/span><\/p>\n<hr \/>\n<p><span style=\"color: #008000; font-size: 18pt;\"><strong>Limit Access to the Backend UI<\/strong><\/span><\/p>\n<p><span style=\"font-size: 14pt;\">If you want to follow the best security practices, then a CI\/CD process implementation for your website will mean that you are not making any changes to the content or configuration on the live site. <\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Sitefinity CMS offers a centralized system to control whether the backend UI is on a website instance or not.\u00a0 This is an advanced security mechanism that covers the login page and also the dialogs, backend routes and etc.<\/span><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: 14pt; color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"\/how-sitefinity-cms-helps-to-change-the-business-environment\/\">Change The Business Environment with Sitefinity<\/a><\/span><\/p>\n<hr \/>\n<p><span style=\"color: #008000; font-size: 18pt;\"><strong>Use SSL for the Login Page: <\/strong><\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Sitefinity CMS offers a greater flexibility when it is about enforcing SSL. You can configure the login page and also different areas of the site that is to be served under SSL, the backend, frontend and so on.\u00a0 <\/span><\/p>\n<p><span style=\"font-size: 14pt;\">It is recommended to enforce SSL for the entire website. Serving your site under the https:\/\/ is a must to boost administrative security.<\/span><\/p>\n<hr \/>\n<p><span style=\"color: #008000; font-size: 18pt;\"><strong>Use the Powerful Web Security Module:\u00a0 <\/strong><\/span><\/p>\n<p><span style=\"font-size: 14pt;\"><span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"\/sitefinity-development\/\"><strong>Sitefinity CMS<\/strong><\/a> <\/span>offers a powerful Web Security Module with fine-tuned security settings. It was introduced in version 11 and is a default program. In case your security module is not activated, do it immediately as it offers advanced protection against MITM, XSS, content sniffing and other malicious security attacks.<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Thus to conclude, a strong password together with Sitefinity\u2019s default settings will be enough to restrict unauthorized users and attackers to access the site. But for advanced and some more security, apply the above-recommended tips for best results.<\/span><\/p>\n<blockquote>\n<p style=\"box-shadow: 0 0 16px #cccccc; padding: 10px;\"><span style=\"font-size: 14pt;\"><span style=\"color: #800000;\"><strong>Related Blog:<\/strong>\u00a0<\/span><a href=\"\/blog\/how-to-make-sitefinity-backend-more-secure\"><span style=\"color: #ff0000;\">How to Make Sitefinity Backend More Secure<\/span><\/a><\/span><\/p>\n<\/blockquote>\n<hr \/>\n<div class=\"newsletter_form\">\n<h2>Sign up our Newsletter!<\/h2>\n<div class=\"emaillist\" id=\"es_form_f0-n1\"><form action=\"\/blog\/wp-json\/wp\/v2\/posts\/2114#es_form_f0-n1\" method=\"post\" class=\"es_subscription_form es_shortcode_form  es_ajax_subscription_form\" id=\"es_subscription_form_6a3a52ab6f9fd\" data-source=\"ig-es\" data-form-id=\"0\"><div class=\"es-field-wrap\"><label>Name<br \/><input type=\"text\" name=\"esfpx_name\" class=\"ig_es_form_field_name\" placeholder=\"\" value=\"\" \/><\/label><\/div><div class=\"es-field-wrap\"><label>Email*<br \/><input class=\"es_required_field es_txt_email ig_es_form_field_email\" type=\"email\" name=\"esfpx_email\" value=\"\" placeholder=\"\" required=\"required\" \/><\/label><\/div><input type=\"hidden\" name=\"esfpx_form_id\" value=\"0\" \/><input type=\"hidden\" name=\"es\" value=\"subscribe\" \/>\n\t\t\t<input type=\"hidden\" name=\"esfpx_es_form_identifier\" value=\"f0-n1\" \/>\n\t\t\t<input type=\"hidden\" name=\"esfpx_es_email_page\" value=\"2114\" \/>\n\t\t\t<input type=\"hidden\" name=\"esfpx_es_email_page_url\" value=\"https:\/\/www.idslogic.com\/blog\/securing-sitefinitys-administrative-user-interface-is-easy-with-these-tips\" \/>\n\t\t\t<input type=\"hidden\" name=\"esfpx_status\" value=\"Unconfirmed\" \/>\n\t\t\t<input type=\"hidden\" name=\"esfpx_es-subscribe\" id=\"es-subscribe-6a3a52ab6f9fd\" value=\"e12a72702e\" \/>\n\t\t\t<label style=\"position:absolute;top:-99999px;left:-99999px;z-index:-99;\" aria-hidden=\"true\"><span hidden>Please leave this field empty.<\/span><input type=\"email\" name=\"esfpx_es_hp_email\" class=\"es_required_field\" tabindex=\"-1\" autocomplete=\"-1\" value=\"\" \/><\/label><input type=\"submit\" name=\"submit\" class=\"es_subscription_form_submit es_submit_button es_textbox_button\" id=\"es_subscription_form_submit_6a3a52ab6f9fd\" value=\"Subscribe\" \/><span class=\"es_spinner_image\" id=\"spinner-image\"><img decoding=\"async\" src=\"https:\/\/www.idslogic.com\/blog\/wp-content\/plugins\/email-subscribers\/lite\/public\/images\/spinner.gif\" alt=\"Loading\" \/><\/span><\/form><span class=\"es_subscription_message \" id=\"es_subscription_message_6a3a52ab6f9fd\" role=\"alert\" aria-live=\"assertive\"><\/span><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Sitefinity is a powerful CMS that allows business owners to create a powerful web presence and offers personalized customer experience. It helps to deliver intuitive content that engages, converts and also retains the customers. Maintaining the security of your site&#8230;<\/p>\n","protected":false},"author":1,"featured_media":9534,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[251],"tags":[271,647,285,226],"class_list":["post-2114","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sitefinity","tag-certified-sitefinity-developers","tag-sitefinity-admin-ui","tag-sitefinity-cms","tag-sitefinity-development"],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/posts\/2114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/comments?post=2114"}],"version-history":[{"count":5,"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/posts\/2114\/revisions"}],"predecessor-version":[{"id":10753,"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/posts\/2114\/revisions\/10753"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/media\/9534"}],"wp:attachment":[{"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/media?parent=2114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/categories?post=2114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.idslogic.com\/blog\/wp-json\/wp\/v2\/tags?post=2114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}