Tyler Technologies presents: What you need to know about upcoming changes to your New World ERP technical environment in 2018.1 Scott Alan Miller MCP, Security+ Tyler System Management - Team Lead Ray Mah | Architect, ERP Development
Certificate Requirements in 2018.1 Tyler Identity Tyler Hub Agenda Browser Support Certificate Requirements in 2018.1 Tyler Identity Tyler Hub Security changes in New World ERP Server environments
Browser Support The more, the better!
The following browsers are support in New World ERP 2018.1 Edge Chrome Browser Support The following browsers are support in New World ERP 2018.1 Edge Chrome Safari (Mac) Firefox Internet Explorer 11 - The above browsers are still supported in eSuite - For best performance, we recommend Chrome or Edge - Microsoft has ceased development of IE 11 and is replacing it with Edge
Certificate Requirements Certificates for use with SSL/TLS protocols
Digital Certificates “An SSL Certificate (Secure Sockets Layer), also called a Digital Certificate, creates a secure link between a website and a visitor's browser. By ensuring that all data passed between the two remains private and secure….” SOURCE: Network Solutions – What is an SSL Certificate Creates a secure link between a website and a visitor’s browser
SSL and TLS Deployment Best Practices “SSL/TLS is a deceptively simple technology. It is easy to deploy, and it just works-- except when it does not.” https://github.com/ssllabs/research/wiki/SSL-and-TLS-Deployment-Best-Practices SSL/TLS is a deceptively simple technology. It is easy to deploy, and it just works--except when it does not. The main problem is that encryption is not often easy to deploy correctly. To ensure that TLS provides the necessary security, system administrators and developers must put extra effort into properly configuring their servers and developing their applications.
2018.1 Digital Certificates are required in 2018.1 Support for certificates available now! Don’t wait! Talk to your certificate vendor! Self-Signed = Not Supported Digital Cert: Must have certificates in 2018.1 Required 2048 bit length Chrome will complain about SHA1 algorithm. Support: You can install them now. Don’t wait: Run it in TEST first! Just link the MIU. ALWAYS DO IT IN TEST FIRST! Always test in test. SSL Configuration Tool Talk to your vendor: Your vendor will have instructions on how to get it added to the server.
The GOOD! See the lock and how the address bar is NOT red? This tells you the URL matches the certificate. Here is where your DNS must match the certificate name This Photo by Unknown Author is licensed under CC BY-SA
The bad This MAY still work but your employees will need to click extra items. You may have get more calls from employees asking what’s up? Within the software, using FQDN that produce errors in browsers will cause the software to fail as well
Your own authority? Acceptable and how we run internally at Tyler Client and Server Authentication required
What is it and why do I need it? Tyler Identity What is it and why do I need it?
New application for authentication Single sign-on Separate Install What is Tyler Identity? New application for authentication Single sign-on Separate Install Benefits User authentication that allows for single sign-on with other Tyler applications Separate application requiring its own installation Benefits Additional password policies Forgot password process User email verification Single sign-on Hub Tyler Content Manager (future) Energov (future) Executime (future)
Tyler Identity – Impact to End Users New sign-in page
Tyler Identity – Impact to End Users Tyler Identity web page used for password maintenance
Tyler Identity – Password Options (Non-AD) Tyler Identity web page used for password maintenance
Tyler Identity – Email Notifications Tyler Identity web page used for password maintenance
Tyler Identity – Impact to Administrators Add a new user in NWERP is slightly different User migration Add a new user in NWERP is slightly different No password set when user is created User migration Preparing for migration: add a unique email address to all active users
Tyler Identity – Migration One-time, simple interface Simulation or live mode Copy existing users from ERP to TID Add a new user in NWERP is slightly different No password set when user is created User migration Preparing for migration: add a unique email address to all active users
Security Enhancements
Added a “forgot username” process eSuite Added a “forgot username” process Utilities users now required to register for an account Admin site users are now required to have an email address
Tyler Identity integration Excel add-ins NWERP Tyler Identity integration Excel add-ins Budget UDF mass update Revenue collections receipt void process also uses Tyler Identity authentication
Tyler Identity integration Can now use AD account in myInspections app
NWERP About page is now secured There was enough information here to make our penetration testers nervous. (Yes we do that!)
What is it and why do I need it? Tyler Hub What is it and why do I need it?
What is Tyler Hub? Included in maintenance High level data visualization Monitoring and alerting SSO with NWERP Optional separate installation through Octopus deploy High level data visualization similar to DSS Dashboards Monitoring and alerting These are items that may require actions Single Sign-on along with NW ERP via Tyler Identity Optional install
Server Environments
Current Hardware Configuration 3 server setup
Recommended Configuration If you have other tyler products, we recommend that all of those items run on the Common server. This is not required. You can run it on the NW ERP App server (more RAM my be required)
1 more required application (Tyler Identity) Optional Tyler Apps Flexibility in 2018.1 1 more required application (Tyler Identity) Optional Tyler Apps Could use one server for everything Review the installation guide prior to upgrading. Backup the new Identity and Hub databases in maintenance. 1 more required application (Tyler Identity) Optional Apps (Tyler Hub, Tyler Content Manager, Tyler Forms, etc.) With enough resources (CPU, memory) one server for everything is still possible Review the installation guide prior to upgrading.
2018.1 Installer Odds and Ends Tyler Identity pre-req for ERP CD installer no longer required (unless you have myInspections) Elastic Search + Java upgraded as pre-req to ERP install Erlang and RabbitMQ remain at prior versions. Patches continue to come through the MIU. Help is no longer installed internally Help Central
2018.1 Event Viewer Changes Consolidated to one log. Change the size to get more events.
Questions?