QlikView Security Overview Marcus Spitzmiller
EXCELSQLSAPERP ORACLE SALESFORCE DATA WAREHOUSE INFORMATICA Finance Marketing Sales Operations Presentation QLIKVIEW WEBSERVER BUSINESS DISCOVERY APPS Application QLIKVIEW PUBLISHER BUSINESS USERS IT Admins Authoring OPERATIONAL DATA SOURCES Data Access QlikView Business Discovery Platform QLIKVIEW SERVER Data / Business Analysts Developers QLIKVIEW MANAGEMENT CONSOLE QLIKVIEW DEVELOPER Windows IIS
Security Overview QV Server QV Publisher Web Server Users Authentication Active Directory Single Sign On Integration Custom Integration Session created in QlikView Authorization Active Directory LDAP ODBC Authentication Authorization Lookup Apply
Section Access - Dynamic Reduction
Section Access – Row and Column Entitlements Associate with Data Model to drive data visibility Data Model Entitlements
Section Access – Row and Column Sourced from Management Console Sourced from Database Data Layer
Loop and Reduce - Physical Reduction
Loop and Reduce + Section Access RegionUserDepartment NorthJohnSales NorthGeorgeHR SouthMaryFinance WestJillSales RegionUserDepartment NorthJohnSales NorthGeorgeHR RegionUserDepartment SouthMaryFinance RegionUserDepartment WestJillSales Section Access Sales.qvw Sales_South.qvw Sales_North.qvw Sales_West.qvw Data Model Loop and Reduce
Audit Logging refers to the process of capturing user actions in QlikView Auditable Activities –Open Document –Navigate Sheet –Selections Captured Information –User –Timestamp –Application –Type of Action (application open, sheet open, selection, etc.) –Value No Response Time or Server Resource Impact Auditing
Ports QV Server QV Publisher Web Server Users AD: 389 Authorization Lookup Apply HTTP / HTTPS (80 / 443) Sessions: 4747 (Encrypted) Publish: 4747 (Encrypted) /SMB AD: 389 EDW ODBC
Data QlikView Applications (.qvw) Binary, compressed, difficult to read, not encrypted Customers requiring encryption can leverage Windows EFS QlikView Data (.qvd) Binary, difficult to read, not encrypted Customers requiring encryption can leverage Windows EFS QlikView Publisher QlikView Server Folder access controlled by Windows ACLs Publish
Authentication –Active Directory –Single Sign On Integration (HTTP Headers) –Custom Integration (GetWebTicket API) Application Authorization –Possible via Users / Groups –Active Directory –LDAP –ODBC Data Access –Physical and Dynamic Segmentation (i.e., Loop and Reduce / Section Access) –Secure to Row and Column –Can be secured in motion and at rest Summary
Thank You!