This guide provides comprehensive information about security-related configuration options in EvTrack, including SAML SSO setup and endpoint access control through security hardening properties.
SAML SSO Configuration
For detailed SAML Single Sign-On configuration with Azure Entra ID, refer to the comprehensive guide:
- KB Article: SAML SSO Configuration Guide
- Reply URL:
https://FQDN/login/saml2/sso/entra - Entity ID:
evtrack-visitor-management - Login Page: When SSO is enabled, users are directed to
/login/ssowhich displays the SAML login button
Endpoint Access Control
EvTrack provides fine-grained control over API endpoints through configuration properties. This allows administrators to enable or disable specific features based on security requirements.
1. Password Reset Endpoints - Disabled when SSO is enabled
- Property:
evtrack.security.config.sso.enable=truedisables password reset functionality - Endpoint path:
/auth/password-reset/** - Note: When SSO is enabled, password reset functionality is automatically disabled
2. FondVision WS Endpoint - Disabled by default
- Property:
evtrack.security.config.hardening.fond-vision-ws.enabled=false(default) - Endpoint path:
/qa/mcardsea.php - To enable: Set
evtrack.security.config.hardening.fond-vision-ws.enabled=true
3. Akuvox WS Endpoints - Disabled by default
- Property:
evtrack.security.config.hardening.akuvox-ws.enabled=false(default) - Endpoint path:
/api/device/akuvox/v1/** - To enable: Set
evtrack.security.config.hardening.akuvox-ws.enabled=true
4. Onsite API Endpoints - Disabled by default
- Property:
evtrack.security.config.hardening.onsite-api.enabled=false(default) - Endpoint paths:
/api/onsite/v1/** - To enable: Set
evtrack.security.config.hardening.onsite-api.enabled=true
5. Axis WS ACAP Endpoints - Disabled by default
- Property:
evtrack.security.config.hardening.axis-ws.enabled=false(default) - Endpoint path:
/api/device/axis/ws/v1/** - To enable: Set
evtrack.security.config.hardening.axis-ws.enabled=true
6. Axis Barcode ACAP Endpoints - Disabled by default
- Property:
evtrack.security.config.hardening.axis-barcode.enabled=false(default) - Endpoint path:
/api/device/axis/barcode/v1/** - To enable: Set
evtrack.security.config.hardening.axis-barcode.enabled=true
7. Wix Booking API Endpoints - Disabled by default
- Property:
evtrack.security.config.hardening.wix-api.enabled=false(default) - Endpoint path:
/api/wix/v1/booking/** - To enable: Set
evtrack.security.config.hardening.wix-api.enabled=true
8. Connect App API Endpoints - Disabled by default
- Property:
evtrack.security.config.hardening.connect-app-api.enabled=false(default) - Endpoint paths:
/api/app/v1/** - To enable: Set
evtrack.security.config.hardening.connect-app-api.enabled=true - Covers: the Connect mobile app’s authentication, profile, credential, document, invite, notification, event, upload, visitor and site-booking endpoints
9. Guard API Endpoints - Enabled by default
- Property:
evtrack.security.config.hardening.guard-api.enabled=true(default) - Endpoint paths:
/api/**and/api/v1/** - Note: Enabled by default for backward compatibility
- To disable: Set
evtrack.security.config.hardening.guard-api.enabled=false - Covers: guard app authentication and operational endpoints
10. Kiosk API Endpoints - Enabled by default
- Property:
evtrack.security.config.hardening.kiosk-api.enabled=true(default) - Endpoint paths:
/api/kiosk/v1/** - Note: Enabled by default for backward compatibility
- To disable: Set
evtrack.security.config.hardening.kiosk-api.enabled=false - Covers: kiosk authentication and operational endpoints
11. Driver Subsystem RPC Endpoint - Disabled by default
- Property:
evtrack.security.config.hardening.driver-subsystem.enabled=false(default) - Endpoint path:
/api/rpc/v1/driver/** - To enable: Set
evtrack.security.config.hardening.driver-subsystem.enabled=true - Purpose: Handles driver subsystem RPC messages and commands
12. Web Service API Localhost-Only Access
- Property:
evtrack.security.config.hardening.webservice-api.restrict-to-localhost=false(default) - Affected paths:
/api/ws/**and/api/onsite/**(GET, POST, PUT, DELETE) - Special behavior: When
EVTRACK_LICenvironment variable is present and property is not explicitly set, defaults totrue - Allowed connections when restricted:
- IPv4:
127.0.0.1 - IPv6:
0:0:0:0:0:0:0:1or::1
- IPv4:
- Authentication: Uses JWT authentication for localhost connections
Configuration Best Practices
-
Security Hardening: By default, most device-specific and third-party integration APIs are disabled. Enable only the endpoints required for your specific deployment.
-
SSO Integration: When SSO is enabled, ensure that password reset functionality is properly disabled to maintain security integrity.
-
API Access: Consider the security implications before enabling any disabled-by-default API endpoints. Each should be enabled only if there’s a specific business requirement.
-
Localhost Restrictions: The Web Service API can be restricted to localhost-only access for enhanced security, particularly useful in production environments with the
EVTRACK_LICenvironment variable.
Related Documentation
- SAML SSO Configuration Guide - Azure Entra ID
- SAML Single Sign-On (AD FS) - Active Directory Federation Services