Previous Table of Contents Next


Secure Web Serving

As more companies have attached their AS/400s to the World Wide Web, the issue of network security has become an important topic. We discuss network computing in Chapter 11, but a few words on security are appropriate here. Many of the techniques we just discussed to make an AS/400 secure in a client/server environment also apply when attaching the AS/400 to open networks of any kind. A couple of special considerations, however, apply to the Internet.

Before we look at security implications, a short introduction to the AS/400 Internet support is in order. Internet Connection, introduced in early 1996 as part of OS/400, bundled a Web server, a 5250-to-Hypertext Markup Language (HTML) gateway, and HTML database tools. The Web server is called the Internet Connection Server: it communicates with Web clients using the Hypertext Transport Protocol (HTTP). The HTML gateway is a transformation that will convert the 5250 datastream to HTML on the fly. This allows a 5250 application to run over the Internet. The HTML database tools allow queries to be build against DB2/400 using HTML and SQL. These facilities, and the enhancements that were added in later releases, turned the AS/400 into a full-service Internet server.

HTML is the datastream used between the Web server and a Web browser in the network-attached clients. HTML is not a programming language; it is a full-fledged page-description language, similar to PostScript. HTML comes from the print-publishing industry’s Standard Generalized Markup Language, and it describes the general arrangement of text and graphics on the screen. The Web browser on a client submits a request to a server in the form of a universal resource locator (URL). The URL takes the form “http://name-of-server/name-of-HTML-document.”

HTTP is simply the transport protocol used across the TCP/IP connection between the Web server in the AS/400 and the Web clients. The external connections can be leased lines or the asynchronous dial-up TCP/IP access, known as Serial Link Internet Protocol (SLIP). Support for point-to-point protocol (PPP) is also provided. In addition to using the Web server, network clients can use the TCP/IP File Transfer Protocol (FTP) to access the AS/400’s integrated file system. Anonymous FTP support is provided to allow any “anonymous” network user to access the system using FTP.

A Web user on a network client can ask the server in the AS/400 to run an HTML Common Gateway Interface (CGI) program. CGI is a standard Web-server protocol that lets server-based programs interact directly with a Web browser on a network client. When the program starts, it receives information from the invoking HTML document, user name, TCP/IP address, and any user-supplied input. By using SQL commands with the HTML, the client also can directly query DB2/400 using the Web browser. The CGI program performs whatever operations are requested, including the requested queries to DB2/400, and outputs HTML text, which the Web server in the AS/400 sends directly to the requesting browser.

The AS/400 Web-serving product uses the AS/400’s security to make sure any sensitive data within the AS/400 is protected. A couple of new user profiles and some configuration options keep private data private and make public only those files that need to be public.

The Web server in the AS/400 normally runs under the new QTMHHTTP user profile. When using this user profile, the Web server operates in system state. To limit the files that the Web server can access, and therefore the files in DB2/400 that a Web client can access, you limit the object authority given to the QTMHHTTP user profile. A second user profile is used when the user on the Web client asks the Web server to run a CGI program. The Web server switches to the QTMHHTP1 user profile, drops the state from system to user, and does not pass the server’s adopted authorities to the CGI program. The QTMHHTP1 user profile has no authority to anything and can access only objects that have public authority.

Because users on the Internet are not usually enrolled on the AS/400, the Web server does not even check a user’s authority. Note that any given AS/400 installation may require a user ID and a password to access certain URL pages; however, the typical URL pages for any business will be open to any Internet user. Therefore, this Internet user can access anything the Web server is allowed to access. For this reason, the public authority to objects in the system needs to be carefully controlled. For example, if some library contains sensitive information, you might want to set the public authority to EXCLUDE and allow access only through private or group authorities. In this way, the Web server cannot access the library. If a library requires some higher level of public authority, you might consider explicitly excluding QTMHHTTP and QTMHHTP1 from accessing the library if you don’t want it available to Web users.

The Web server can use libraries to which it is authorized, but it does not use library lists. As we discussed earlier, using a library list opens up the possibility of putting a Trojan horse in a library that precedes the library that contains the legitimate program. By not using library lists, we eliminate this Trojan-horse threat.

Another way to secure the system is through the use of exit programs. A customer-written program in the AS/400 is identified as an exit program. Whenever a network client, for example, uses FTP to attempt a file transfer to or from the AS/400, the exit program is called first, before the file operation is performed. This exit program can deny specific operations based on the user profile being used or the file being accessed. In a similar way, exit programs can be called when other operations, such as server log-on, are requested. Exit programs also can be used for remotely attached PCs or for accesses to the system that are made through the HTML gateway.

To transact any electronic commerce across a network that is inherently nonsecure, there is a need to secure the transport of data and to provide for secure payment transactions. The AS/400 uses industry-standard network protocols to support both of these requirements. The Secure Sockets Layer (SSL) is used for the secured-transport facility, and the Secure Electronics Transaction (SET) protocol is used to secure payment transactions. We discuss SSL later in Chapter 11. SET is the protocol defined by Visa/MasterCard for securing credit-card transactions on the Internet. In addition, where needed, the AS/400 provides a very extensive hardware-assisted, data-encryption facility.


Previous Table of Contents Next

Copyright © NEWS/400 Books