Since lawyers deal with particularly sensitive data, the security of the timeSensor LEGAL database is an especially serious matter. The article below provides information on how to ensure the safe operation of the database.
This FAQ article is limited to information with regard to the security settings concerning the 4D database itself. Regardless of these settings, you must also ensure the security of your infrastructure. For example, the network must be protected by a firewall and the workstations must be updated with the latest software. We highly recommend that the security of your infrastructure is periodically checked by an independent expert!
In multi-user mode, the client application communicates permanently with the 4D database. In order to prevent data traffic between the client and the 4D Server from being intercepted, you should encrypt the communication between the client and the 4D Server. To do this, please proceed as follows:
In order to enable the clients on the individual workstations to log on with SSL encryption in future, you must now change the connection type on the workstations. (You will only need to do this once.) Please proceed as follows:
Note for administrators: if you manage a larger number of workstations, you can also roll out a preconfigured client via your deployment tool. The client application folder has a sub-folder called "Database", in which you will find the file "EnginedServer.4Dlink". The exact path is as follows:
This XML file should be edited as shown in the example below. Here it is also important to place a circumflex before the database name (i.e. ^timeSensor).
User passwords have no longer been stored in the database since tSL 7.0/Build 2139, so even the Administrator can no longer read user passwords, since only a hash code is stored in the database. However, this improvement in security is only effective if all users choose secure passwords. With this in mind, please ensure that your users choose passwords that are sufficiently strong.
If an incorrect password is entered three times successively in a user account, the password dialogue closes and the corresponding user receives a ticket informing him/her of the unsuccessful access attempt.
Administrators can also choose to be informed about such incidents by activating the "Send tickets for security-relevant messages" checkbox in their user account. We recommend that you make use of this option and define a process that takes effect when such incidents occur in your law practice. After any unsuccessful access attempt, it should at least be clarified whether the user had forgotten his/her password or whether it was in fact an attempt by a third party to access the account.
When logging on to the database, the user first encounters the timeSensor LEGAL login dialogue box. timeSensor LEGAL offers several security levels for this dialogue box that can be selected in the Settings section under "Admin"/"Special". To adjust the security for this dialogue box, click the Security tab and set the Login Dialogue slider to the desired level: