Security

How we can improve security of Kentico CMS?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the “My feedback” filter and select “My open ideas”.
(thinking…)
Reset

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
    1. Changing CMSDesk Path for Security

      On our public-facing sites, we'd like to be able to change the virtual directory path for the CMSDesk, CMSSiteManager and CMSPages (ideally only the login page) from the default to help hide it from external visitors.

      45 votes
      Vote 0 votes Vote Vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service

        You'll receive a confirmation email with a link to create a password (optional).

        Signed in as (Sign out)
        You have left! (?) (thinking…)
      • Ability to plug-in 3rd party multi factor authentication

        This is the type of user authentication found on financial sites. Where a users is asked to provide the answer to a series of questions and maybe pick a picture and give it a description.
        Then each time you use a different computer you're asked to provide the answers.
        It would be nice to be able to plug in this type of authentication into Kentico using 3rd party APIs say from RSA

        21 votes
        Vote 0 votes Vote Vote
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service

          You'll receive a confirmation email with a link to create a password (optional).

          Signed in as (Sign out)
          You have left! (?) (thinking…)
          under review  ·  1 comment  ·  Admin →
        • Control Questions to reset Password

          as an altarnative for emailing new password

          18 votes
          Vote 0 votes Vote Vote
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service

            You'll receive a confirmation email with a link to create a password (optional).

            Signed in as (Sign out)
            You have left! (?) (thinking…)
          • 17 votes
            Vote 0 votes Vote Vote
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service

              You'll receive a confirmation email with a link to create a password (optional).

              Signed in as (Sign out)
              You have left! (?) (thinking…)
              under review  ·  1 comment  ·  Admin →
            • Data Encryption

              Allow option to have bizform and custom table data be stored in an encrypted format.

              13 votes
              Vote 0 votes Vote Vote
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service

                You'll receive a confirmation email with a link to create a password (optional).

                Signed in as (Sign out)
                You have left! (?) (thinking…)
              • Impersonate users when using Windows authentication

                The concept of impersonation is great except it's not available when using Windows authentication. It currently only works with Forms based authentication. We are using Kentico as our Intranet Portal so being able to see what a user sees would be very helpful is solving problems.

                6 votes
                Vote 0 votes Vote Vote
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service

                  You'll receive a confirmation email with a link to create a password (optional).

                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                • Implementation of a SAML Security Token Service for advanced login service

                  Kentico Sites support HTTP POST binding for Web Browser SSO and Webbased attribute requests according to Bindings for the OASIS Security Assertion Markup Language (SAML), V2.0.

                  1 vote
                  Vote 0 votes Vote Vote
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service

                    You'll receive a confirmation email with a link to create a password (optional).

                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                • Don’t see your idea?
                • Post a new idea…
                • Security

                  Knowledge Base and Helpdesk