13.07.2015 Views

EPiServer Operator's Guide - EPiServer World

EPiServer Operator's Guide - EPiServer World

EPiServer Operator's Guide - EPiServer World

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

6 | <strong>EPiServer</strong> <strong>Operator's</strong> <strong>Guide</strong>Timeout for LogoutIf the Web site uses forms authentication, the users that are logged on will be automatically logged out by .NETafter a certain period of inactive time. This period of time can be changed in web.config by setting the timeoutattribute, which states timeout in minutes, on the forms part under authentication.Release ModeMake sure that the .dll files in the bin directory that belongs to the Web site are compiled in Release mode. A .dllfile that is compiled in Debug mode is larger, uses more memory and is slower than the one compiled in Releasemode.Dynamic pages and user controls also have script-like code, which is compiled when needed by ASP.NET. Inorder for this to be compiled in Release mode, change web.config by changing the value for the debug attributeto "false". If it is a problem that pages compile when required, e.g. loss of performance, you can also state that allthe pages should be compiled at once during compilation. This is done by setting the batch attribute to true.<strong>EPiServer</strong> Configuration<strong>EPiServer</strong>'s installation program automatically applies a configuration template at first time installation. This,among other things, sets file access rights and certain settings in IIS. Refer to the <strong>EPiServer</strong> Configuration Toolchapter for further information.All settings configured by an administrator are saved in the web.config file. Some of these settings are alsoavailable in Admin mode under System settings and can also be displayed for all installed <strong>EPiServer</strong> sites in<strong>EPiServer</strong> Manager.Roles and AuthorityIn web.config, you can define which roles will have access to which parts of <strong>EPiServer</strong>. There are mainly twoparts that need to be secured: Edit and Admin. These are limited to the roles WebEditors and WebAdmins asstandard, but these settings can be changed as you wish. A role is normally the same as a group, if you log onwith Windows or an <strong>EPiServer</strong> user.Encrypt web.config<strong>EPiServer</strong> has built-in support for encryption of sensitive information in web.config. From System Settings inAdmin mode, select the Encrypt the web.config file check box to encrypt the information for the databaseconnection, which also has a database login and password, and the user information to connect to the LDAPserver. These settings will be saved in encrypted format.You can also enforce encryption of approved settings in web.config under the section, byediting web.config in a text editor. To activate encryption for a setting, add the text ENCRYPT in the valueattribute before the value in question, e.g. to encrypt the Upload directory (EPsUploadDir), changetoGo to System Settings and save the settings. If you now look in web.config, you will see that the line haschanged toCopyright © ElektroPost Stockholm AB - www.episerver.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!