Permissions, roles, and administration. Security in data processing.
Recently active
I have a workbench that reads/writes CSV files to a network location. It works fine from my desktop but when published to FME Flow i get permission errors reading and writing. What user is FME Flow using to read/write to the network? any other workaround
Is this a bug in FME Flow 2023.1 Build 23619 - win64?
I want to encrypt generated output shapefile via PGP encryption in FME. How we can achieve this?
We (APA) are facing issues with security certificate installed on our FME Server.The certificate has expired and we are not able to update it with new valid cert. We have followed the workflow mentioned here: https://community.safe.com/s/article/Configuring-FME-Server-for-HTTPS-Updating-an-expired-CertificateWe completed all these steps but still not successful.when we connect we still see old expired cert on browser.
I have an FME Server (Flow) 2022.2.5 installation on a Windows server and I have application-level user security enabled (not Windows-level security). Sometimes I need to do maintenance on the server and I'd like to be able to see who is currently logged in via the web interface. I've looked everywhere in the web interface for something like this but no luck. Thanks.
Are FME Desktop 2017 and 2020 vulnerable for Apache ActiveMQ CVE-2023-46604? Thank you
I have a private AWS server. I have a customer who uses power app to create rest api calls to fme server installed on this server. They need the server to be at a security level of https. They access fme server using the URL of the server through a gateway with an enabled port. Aws has its own security certificate but it charges a lot of money for a private CA. There are free websites out there but they want the domain registered. I can't register the domain of the AWS as it's a private server I went through the safe http to https tutorial using a self signed cert (pfx) section. However, while I managed to get the fme server to use https an untrusted error comes up, even if I add the cert to trusted certificates. I suspect it's because it is a self signed cert. I've had to roll back fme server to http as the users couldn't access the rest API anymore. This is my first dabble with security certificates but I can't see a solution around this. thanks for any adv
Is FME Server / Flow vulnerable for Apache ActiveMQ CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604
Hi!We have configured FME Flow (2022.2.8) for OKTA SAML Authentication as per https://community.safe.com/s/article/Configuring-FME-Server-for-OKTA-SAML-Authentication On signing in with a username, password and MFA it redirects us back to the password page.The restV4.log or fmesaml.log never shows that we attempted to login. We tried to configure FME Flow for Azure AD SAML Authentication, but got the same outcome. Any ideas, please? Regards,Dmitry
I want to automate a rest call to the FME FLOW API for schedule information, like https://myfmeserver/fmerest/v3/schedules?includeAutomations=true&limit=1000&offset=0 What are the minimum FME permissions needed to be assigned to role or system user to be able to run that API call ?
At the moment I get a token with a normal HTTPCaller with username and password as User parameters. However, I would like to store username and password secure. For this reason I tried to use a Web Connection. Unfortunately this didn't work. Any recommendation hwo this should be done? This is my HTTPCaller that works fine but with the drawback that username and password are defined as user parameters in plaintext.
How to enable anonymous access to FME Flow (2023) services? Guest account is enabled and given permissions on repository and services OK. Trying to call a service always prompts for credentials. Can login as Guest and it works so permissions are OK.
For an automation running on FME Flow is there a method save the parameters used to send an email? Currently we have many email services set up and are switching email servers around. It would be nice to be able to update the credentials for one source opposed to having to edit the parameters in each automation individually.
Hi, I would like to list all FME Flow users that are currently disabled using the rest API or any other method. Is this possible? Thanks,Marc
A recent vulnerability scan where i work identified both Log 4j and Apache TomCat vulnerabilities with our FME Server applications. I am currently running FME Server 2019.1, I know that particular version of FME does not utilize Log4j , but the files exist as a part of the installation. Can we simply mitigate these vulnerabilities by removing the log4j and TomCat installation, or do we need to upgrade those install to a more current version? If we install newer versions of both log4j & TomCat will the FME Server 2019.1 application continue to function as expected?
We have a series of API calls to a Bentley API which have been working fine until recently and are still working fine in Postman. We have a GET request in FME which returns a “HTTP/1.1 403 Forbidden” error. We have been through this with Bentley support and have found the source of the issue is related to the Content-Transfer-Encoding header. Bentley's API’s security rules have recently been updated to block requests which contain the ‘Content-Transfer-Encoding’ header. This is because the header has been deprecated and has the potential to be a security vulnerability. FME seems to default send "Content-Transfer-Encoding: binary" with the GET request and there doesn't appear to be an option to change it. Does anyone have any ideas about how we can get round this? Thanks in advance!
开始转换...行“已卸载包 '%0'”在消息文件“C:\\Program Files\\FME\\messages\\zh\\fmemessages_zh.fms”中没有分隔符“,”FME 2023.0.0.3(20230613 - 内部版本 23319 - WIN64)FME表格固定(节点锁定-crc)临时许可证:剩余 28 天。计算机主机名为:ss操作系统:Microsoft Windows 10 64 位(内部版本 18363)版权所有 (c) 1994 - 2023,安全软件公司。安全软件公司246020 格式的共享文件夹是 : FME 2023.0.0.3 (20230613 - 内部版本 23319 - WIN64)246022 坐标系共享文件夹是 : 20230827005921246012 FME_HOME是'C:\\Program Files\\FME\\'FME表格固定(节点锁定-crc)246013 坐标系共享文件夹异常 : 0临时许可证:剩余 28 天。计算机主机名为:ss246026 场所:zh_CN246024 操作系统区域设置编码:GBK246027 系统编码: UTF-8246034 FME API 版本:“4.0 20230418”246017 FME配置: FME_BASE 是 'no'246016 操作系统:Microsoft Windows 10 64 位 (内部版本 18363)246025 FME平台:WIN64246014 系统状态:FME临时文件夹下还有 80.88 GB硬盘空间可用246001 系统状态:15.99 GB 可用物理内存246015 系统状态: 63.97 GB 可用的虚拟内存246031开始 - 进程 ID: 1976, 峰值进程内存使用: 43264 kB, 当前进程内存使用: 43264 kB871015 创建该格式的读模块: Esri 地理数据库(文件 Geodb)871007 尝试查询一个DYNAMIC插件给命名的读模块'GEODATABASE_FILE'23016 加载模块'GEODATABASE_FILE'从文件'C:\\Program Files\\FME\\plugins/..\\地理数据库9.dl
Is there any way to encrypt file in PGP in FME?
I'm working on a server app where users have to upload a photo taken with their phone. There's no need for them to browse the resource folders and so I've disabled access to the resources for that security token (except write access for the temporary folder where the images are stored). However, the users still have the option to browse the resource system: Ideally I'd want that "Browse resources" button to be gone and just have "Upload file". Is there any way to do that (other than write an app of my own)?
Error executing SQL command ('TRUNCATE TABLE "quali"."wa_hydrant"'): 'ERROR: permission denied for table wa_hydrant'Error truncating table 'quali.wa_hydrant'. Assuming table exists and attempting to appendError executing SQL command ('COPY "quali"."wa_hydrant" ("gis_id", "gesellschaft_bd", "gemeinde", "standortwerk", "_rbe", "_fehler_nr", "_fehler", "_pruefdatum", "_fme_prozess", "_temptext1", "_temptext2", "_temptext3", "_temptext4", "_temptext5", "_temptext6", "_temp_num1", "_temp_num2", "_temp_num3", "_temp_num4", "_temp_num5", "_temp_num6", "fstatus_id", "geom_pt") FROM STDIN USING DELIMITERS ':' WITH NULL AS 'NULL''): 'ERROR: current transaction is aborted, command
I am having problems trying to do the above. Documentation for the token request is here: https://bitbucket.org/ikegps/office-api/src/master/ It is requiring a application/x-www-form-urlencoded content-type. I have setup the HTTPCaller like this: The 'mulitpart' upload also includes the additional fields from their doc for 'audience', 'username' and 'password'. I used the example Curl command in Windows list on their docs and was able to get a token. I am getting a '401 error' running this in a workspace. Any help on this or suggestions would be greatly appreciated. I have been fighting with it for a while, and have searched for examples/help here, but haven't gotten it to work.
FMEworkbench wil not start after an update from Windows 11 last week.It starts with the start-screen but after "Initializing main window" stops the startup I'm working with version 2022.2.5 build 22795 I got the details in the following errorlog (in dutch):Logboeknaam: ApplicationBron: Application ErrorDatum: 12-5-2023 10:19:51Gebeurtenis-id:1000Taakcategorie: Toepassingscrash-gebeurtenissenNiveau: FoutTrefwoorden: Gebruiker: Computer: Beschrijving:Naam van toepassing met fout: fmeworkbench.exe, versie: 2022.7.45.22795, tijdstempel: 0x6424fcdcNaam van module met fout: Qt6WebEngineCore_fme.dll, versie: 6.2.4.0, tijdstempel: 0x625ef5dcUitzonderingscode: 0x80000003Foutmarge: 0x0000000002645d96Id van proces met fout: 0x0x4388Starttijd van toepassing met fout: 0x0x1D984AA82E9B0ABPad naar toepassing met fout: C:\\Program Files\\FME\\fmeworkbench.exePad naar module met fout: C:\\Program Files\\FME\\Qt6WebEngineCore_fme.dllRapport-id: feefc3f6-3f26-44
When connecting FME Flow to Azure (Configuring Azure Active Directory with FME Server (safe.com) - the app needs permission to:Microsoft Graph > Application permissions > Group.Read.All, User.Read.AllMicrosoft Graph > Delegated permissions > User.Read However when using Azure AD and FME Form the following permissions are needed: Microsoft Graph User.Read Delegated Is it possible to limit the FME Flow permissions to be the same as FME Desktop - or is there a reason you also need Group.Read.All and User.Read.All ?
We have processes in place for ArcGIS Enterprise patching but none for FME Server. Occasionally there is a hotfix that is released that is security related. Or last month there was an update from our vendor on their website related to CVEs and upgrading. Is there a central place that we can get this information from? Preferably without having to do a manual check on a website page etc. I have signed up our support email to the Stay Informed email list on safe.com/downloads. Would this email list suffice or are there any other feeds that we could check in relation to security patches?
Hi, I am trying to connecto to an API that supports only POST method to generate the tokens via OAuth2. After some testing and fiddling, I can see that FME Desktop (2022.2) sends first a GET request when trying to get the token. So this request is declined by the server and I cannot continue further. Is there a way to enforce POST for the whole OAuth2 flow in Desktop/Server?