{"id":12130,"date":"2023-10-09T00:58:47","date_gmt":"2023-10-09T07:58:47","guid":{"rendered":"https:\/\/www.coretechnologies.com\/blog\/?p=12130"},"modified":"2023-12-08T13:02:30","modified_gmt":"2023-12-08T21:02:30","slug":"version-14-7","status":"publish","type":"post","link":"https:\/\/www.coretechnologies.com\/blog\/alwaysup-web-service\/version-14-7\/","title":{"rendered":"Get Enhanced Authentication Controls &#038; Improved Security with AlwaysUp Web Service 14.7"},"content":{"rendered":"<div align=\"center\"><img loading=\"lazy\" decoding=\"async\" class=\"no-lazy-load\" src=\"\/blog\/images\/alwaysup-web-service-14-7-software-update-300x200.png\" style=\"margin-bottom:20px;\" title=\"AlwaysUp Web Service 14.7: Session Controls &#038; Improved Security\" alt=\"AlwaysUp Web Service 14.7: Session Controls &#038; Improved Security\" border=\"0\" width=\"300\" height=\"200\" \/><\/div>\n<p>AlwaysUp Web Service version 14.7 was released on October 1 2023.<\/p>\n<p>This time around, our team focused on improving the software in a couple of areas &mdash; to give you greater control over authentication and to improve security.<\/p>\n<h2 class=\"blog-caption\">New authentication and session timeout options<\/h2>\n<p>Authentication was mandatory in previous versions of AlwaysUp Web Service. You were forced to enter a password before interacting with your AlwaysUp applications in the browser.<\/p>\n<p>But while protecting the web service is the right approach for the vast majority of our customers, we also heard that having to constantly log in was a nuisance. And introducing an additional layer of authentication was unnecessary when access to the web service URL was already restricted by another gating mechanism (such as network isolation or IP filtering).<\/p>\n<p>So, to help customers who weren&#8217;t happy with the current system, we introduced the following enhancements.<\/p>\n<ol style=\"margin-bottom:24px\">\n<li>\n<p><b>Authentication is optional.<\/b><\/p>\n<p> You can now avoid logging in to access the web service.<\/li>\n<li>\n<p><b>The session timeout is configurable.<\/b><\/p>\n<p> You can now set the web session timeout value to up to 24 hours, to have the web service keep you logged in even when you&#8217;ve been idle for a long time.<\/li>\n<\/ol>\n<p>The new options are available on the <b>Settings<\/b> page in AlwaysUp Web Service Control Panel:<\/p>\n<div align=\"center\"><a href=\"\/blog\/images\/alwaysup-web-service-control-panel-authentication-settings.png\" class=\"zoomPopup\" title=\"AlwaysUp Web Service Control Panel: Authentication Settings\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"image-padding\" src=\"\/blog\/images\/alwaysup-web-service-control-panel-authentication-settings.png\" title=\"AlwaysUp Web Service Control Panel: Authentication Settings (click to enlarge)\" alt=\"AlwaysUp Web Service Control Panel: Authentication Settings\" border=\"0\" \/><\/a><\/div>\n<p>Of course, <b>please think carefully before relaxing security in your environment<\/b>. We recommend sticking with the defaults (password required; session timeout of 30 minutes) unless you have good reasons to change them. <a href=\"https:\/\/en.wikipedia.org\/wiki\/Caveat_emptor\" target=\"_blank\" rel=\"noopener\">Caveat emptor!<\/a><\/p>\n<h2 class=\"blog-caption\">Protection against known vulnerabilities<\/h2>\n<p>As a web application that might be available on the Internet, it&#8217;s important for AlwaysUp Web Service to be as secure as possible. Indeed, it must resist the thousands of malicious actors and bots that are constantly probing network ports, trying to hijack computers.<\/p>\n<p>We apply security updates regularly, to keep AlwaysUp Web Service ahead of the attackers. In this release, we:<\/p>\n<ol style=\"margin-bottom:24px\">\n<li>\n<p><b>Introduced support for TLS 1.3.<\/b><\/p>\n<p> The latest version of the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Transport_Layer_Security\" target=\"_blank\" rel=\"noopener\">TLS protocol<\/a> &mdash; which strengthens encrypted SSL connections &mdash; ensures that your data is always secure in transit.<\/li>\n<li>\n<p><b>Dropped support for TLS 1.1 and earlier.<\/b><\/p>\n<p> Unfortunately those older protocols are no longer secure. <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/tls-1-0-and-tls-1-1-soon-to-be-disabled-in-windows\/ba-p\/3887947\" target=\"_blank\" rel=\"noopener\">Even Microsoft started disabling them in September 2023<\/a>.<\/li>\n<\/ol>\n<p>And with those improvements in place, AlwaysUp Web Service received an A+ grade from <a href=\"https:\/\/www.immuniweb.com\/ssl\/\" target=\"_blank\" rel=\"noopener\">ImmuniWeb&#8217;s popular SSL Security test<\/a>:<\/p>\n<div align=\"center\"><a href=\"\/blog\/images\/immuniweb-ssl-security-test-audit-09-2023.png\" class=\"zoomPopup\" title=\"ImmuniWeb SSL Security test results\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"image-padding\" src=\"\/blog\/images\/immuniweb-ssl-security-test-audit-09-2023.png\" title=\"ImmuniWeb SSL Security test results (click to enlarge)\" alt=\"ImmuniWeb SSL Security test results\" border=\"0\" width=\"520\" \/><\/a><\/div>\n<p>The full report (PDF) is <a href=\"\/blog\/files\/immuniweb-ssl-security-test-audit-09-2023.pdf\" target=\"_blank\" rel=\"noopener\">available here<\/a>.<\/p>\n<h2 class=\"blog-caption\">Additional enhancements<\/h2>\n<p>As usual, please review the <a href=\"\/products\/AlwaysUp\/AlwaysUpWebService\/VersionHistory.html\">release notes<\/a> for the full list of features, fixes and improvements included in AlwaysUp Web Service version 14.7.<\/p>\n<p style=\"margin-top:24px\">\nEnjoy!\n<\/p>\n<div style=\"margin-top:30px\" align=\"center\">\n<div class=\"cta-button-1\">\n<table role=\"presentation\" cellspacing=\"0\" cellpadding=\"0\" border=\"0\" align=\"left\">\n<tbody>\n<tr>\n<td align=\"center\"><a href=\"\/blog\/tag\/alwaysup-web-service\/\" title=\"More articles about AlwaysUp Web Service\"><span><nobr>More about AlwaysUp Web Service&#8230;<\/nobr><\/span><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<!-- relpost-thumb-wrapper --><div class=\"relpost-thumb-wrapper\"><!-- filter-class --><div class=\"relpost-thumb-container\"><style>.relpost-block-single-image, .relpost-post-image { margin-bottom: 10px; }<\/style><h3>You may also like...<\/h3><div style=\"clear: both\"><\/div><div style=\"clear: both\"><\/div><!-- relpost-block-container --><div class=\"relpost-block-container relpost-block-column-layout\" style=\"--relposth-columns: 3;--relposth-columns_t: 2; --relposth-columns_m: 2\"><a href=\"https:\/\/www.coretechnologies.com\/blog\/windows\/windows-server-2022\/\"class=\"relpost-block-single\" ><div class=\"relpost-custom-block-single\"><img decoding=\"async\" loading=\"lazy\" class=\"relpost-block-single-image\" alt=\"Windows Server 2022: A Few Improvements, but No Changes to Windows Services\"  src=\"https:\/\/www.coretechnologies.com\/blog\/wp-content\/uploads\/windows-server-2022-standard-150x150-1.png\" style=\"aspect-ratio:1\/1\" style=\"aspect-ratio:1\/1\"><\/img><div class=\"relpost-block-single-text\"  style=\"height: 75px;font-family: Arial;  font-size: 12px;  color: #333333;\"><h2 class=\"relpost_card_title\">Windows Server 2022: A Few Improvements, but No Changes to Windows Services<\/h2><\/div><\/div><\/a><a href=\"https:\/\/www.coretechnologies.com\/blog\/alwaysup\/version-14-released\/\"class=\"relpost-block-single\" ><div class=\"relpost-custom-block-single\"><img decoding=\"async\" loading=\"lazy\" class=\"relpost-block-single-image\" alt=\"AlwaysUp 14: Improved Performance, Support for Emby Server, Java WAR Files\"  src=\"https:\/\/www.coretechnologies.com\/blog\/wp-content\/uploads\/new-release-green-150x150-1.webp\" style=\"aspect-ratio:1\/1\" style=\"aspect-ratio:1\/1\"><\/img><div class=\"relpost-block-single-text\"  style=\"height: 75px;font-family: Arial;  font-size: 12px;  color: #333333;\"><h2 class=\"relpost_card_title\">AlwaysUp 14: Improved Performance, Support for Emby Server, Java WAR Files<\/h2><\/div><\/div><\/a><a href=\"https:\/\/www.coretechnologies.com\/blog\/service-protector\/version-7-released\/\"class=\"relpost-block-single\" ><div class=\"relpost-custom-block-single\"><img decoding=\"async\" loading=\"lazy\" class=\"relpost-block-single-image\" alt=\"Service Protector 7.0: Informative Email Alerts, Sanity Check Options and More\"  src=\"https:\/\/www.coretechnologies.com\/blog\/wp-content\/uploads\/new-version-2-150x150-1.png\" style=\"aspect-ratio:1\/1\" style=\"aspect-ratio:1\/1\"><\/img><div class=\"relpost-block-single-text\"  style=\"height: 75px;font-family: Arial;  font-size: 12px;  color: #333333;\"><h2 class=\"relpost_card_title\">Service Protector 7.0: Informative Email Alerts, Sanity Check Options and More<\/h2><\/div><\/div><\/a><\/div><!-- close relpost-block-container --><div style=\"clear: both\"><\/div><\/div><!-- close filter class --><\/div><!-- close relpost-thumb-wrapper -->","protected":false},"excerpt":{"rendered":"<p>AlwaysUp Web Service version 14.7 was released on October 1 2023. This time around, our team focused on improving the software in a couple of areas &mdash; to give you greater control over authentication and to improve security. New authentication &hellip; <a href=\"https:\/\/www.coretechnologies.com\/blog\/alwaysup-web-service\/version-14-7\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":12135,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[201,326,109,143,327],"class_list":["post-12130","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alwaysup-web-service","tag-alwaysup-web-service","tag-immuniweb-ssl-security-test","tag-new-release","tag-security","tag-tls"],"_links":{"self":[{"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/posts\/12130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/comments?post=12130"}],"version-history":[{"count":20,"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/posts\/12130\/revisions"}],"predecessor-version":[{"id":12256,"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/posts\/12130\/revisions\/12256"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/media\/12135"}],"wp:attachment":[{"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/media?parent=12130"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/categories?post=12130"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.coretechnologies.com\/blog\/wp-json\/wp\/v2\/tags?post=12130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}