Administrator’s Guide

Table Of Contents
Chapter 5
|
Configuring FileMaker Server 41
Defining groups for use with security features (Windows)
If you are serving files that use External Server accounts, in order to
use administrator authentication, client authentication, or to filter the
display of database files for local or domain users, you must:
1. Define a group on the local system or domain controller. See
Windows Help for more information on defining groups.
Important For administrator authentication, this account must be
named
fmsadmin.
2. Assign to this group the user accounts that will use external server
authentication.
Authenticating client log in
Client access to hosted databases is determined by accounts defined in
FileMaker
Pro. You can choose how FileMaker Pro clients are
authenticated when they connect to databases hosted by FileMaker
Server.
If you choose FileMaker accounts only, the clients’ access privileges are
determined by the accounts defined in the hosted databases.
If you choose FileMaker and External Server Accounts, the clients’
access privileges are determined by the accounts defined in the hosted
databases and by accounts that are set up on the same computer as
FileMaker Server (locally) or on an authentication server such as
Mac
OS X Server or a Windows Domain server. This allows you to
use your existing authentication server to control access to databases
without having to manage an independent list of accounts in each
hosted database file. See “Creating accounts that authenticate via an
external server” in FileMaker Pro Help and www.filemaker.com/
server for more information.
Windows: If you choose FileMaker and External Server Accounts,
records of all logon attempts are logged in the Windows Security Log.
For more information about the Security Log, see your Windows
documentation.
To prevent clients from viewing or modifying data, scripts, and
layouts in FileMaker
Pro, create a privilege set in each of the hosted
files in FileMaker
Pro. See “Protecting databases with accounts and
privilege sets” in FileMaker
Pro Help for more information.
Filtering the display of files
You can limit the list of FileMaker Server-hosted databases displayed
in FileMaker
Pro to only those databases that each client can access.
If you choose
Display only the databases each user is authorized to
access
, the list of databases displayed is determined by the client’s
access privileges to each hosted database. If you choose
Display all
databases
, all FileMaker Server hosted databases are displayed to the
client.
Note This setting only affects the display of databases hosted by
FileMaker Server. Databases hosted peer-to-peer using
FileMaker
Pro are not affected.
Securing connections to FileMaker Server
To protect sensitive data, you can encrypt data passed between
FileMaker Server and clients. If
Secure connections to FileMaker Server
is enabled, all FileMaker Server client connections use the Secure
Sockets Layer, except ODBC and JDBC connections. For more
information about data security, see the
FileMaker Security Guide.
Important Secure connections are slower because of data encryption.
Data transfer rates are affected by the number of clients and the amount
of data transferred.
Note Restart FileMaker Server if the secure connections property is
changed.