FileMaker tips, techniques, and news.

By Michael Westendorf  Posted on  May 10th, 2016  in  FileMaker, Hosting

FileMaker 15 Security Enhancements

FileMaker has done it again. They are constantly improving the security features of the FileMaker platform to better serve its users. Now that FileMaker 15 has arrived lets review those changes.

Pro / Pro Advanced 15 Features

FileMaker 15 SSL Certificate Error

First a new warning will appear whenever a connection is made to a hosted file and the connection cannot be validated. This mainly applies to deployments of server that are using the self-signed certificate when SSL is first enabled. FileMaker has always been clear with their message: the self-signed certificate is for testing and development only. If you don't wish to see this notification and need SSL enabled a signed certificate is the best way to remove it. Servers that have a regular (custom) certificate or have SSL disabled will never display this message. Keep reading to see how FileMaker Server 15 has improved this process.

FileMaker Permitted Hosts

One alternative is to check the "Always permit connection to this host". This will then add the server as a permitted host in your FileMaker Preferences.











FileMaker Data Viewer Security

The Data Viewer has been updated; in the past users with FileMaker Pro Advanced could gain access to any information in your application. No more! Now a full access account is required to use this feature. Certainly a welcome change that matches the Script Debugger and Current tab of the data viewer itself.











FileMaker 15 Concealed Edit Box

Gathering passwords from users is now even easier. A new control style, the "concealed edit box", has been added to mask any sensitive data. FileMaker now provides a sleek way to protect sensitive information entered by a user.








Go 15

FileMaker Go Security Connection WarningFileMaker Go Manage Permitted Hosts

Just like its desktop counterpart, FileMaker Go will warn you when trying to connect to servers/files that are not secure.

The Always Permit Connection is a welcome feature. Users will likely be familiar with this concept from browsing websites. Just like on Pro users can manage their list of permitted hosts directly within FM Go.

Server 15

Create Certificate Signing RequestWith FileMaker Server 15 you can now create your certificate signing request, serverRequest.pem and serverKey.pem files directly from the admin console. Previous versions required this to be done from the command line or terminal. This file is then used with your certificate authority to generate the certificate. Just be sure to follow the process outlined with your certificate authority. As a bonus we can now also view the certificate once it has been properly installed.

Security Require Password Protected Databases
FileMaker Server now has the option to require password-protected databases. A database that has a Guest account using the Full Access privilege set, a Full Access account with an empty password, or a Full Access account with the password stored in the database using the File Options dialog box "Log in Using" option is insecure and will not be opened.

Keep In Mind

  • Extended Privileges – To prevent Applescript or ActiveX from performing FileMaker scripts, use the new fmscriptdisabled extended privilege.
  • FMS SSL Certificate – You will still need to use the command line/terminal to delete a custom certificate.
  • FileMaker Go – You can now log in to your application using Touch ID.

Watch on Youtube: FileMaker 15 Security Features

In Conclusion

With all the focus on protecting data these days, it is nice to see FileMaker's continued improvement in the security realm. I know this developer will be pushing more clients to use FileMaker 15's new security features, including custom SSL certificates, ensuring a smooth deployment.

Did you know we are an authorized reseller for FileMaker Licensing?
Contact us to discuss upgrading your FileMaker software.

Michael Westendorf thumbnail
Michael Westendorf

Michael is a FileMaker Certified Developer who joins DB Services with nearly a decade of experience as an Information Technology Manager in the printing industry. Originally from San Diego, he moved to Iowa during his teens and earned his Bachelor's Degree in Management Information Systems from Iowa State University.

FileMaker 18 Certified Developer
FileMaker 17 Certified Developer
FileMaker 16 Certified Developer
FileMaker 15 Certified Developer
FileMaker 14 Certified Developer
FileMaker 13 Certified Developer
FileMaker 12 Certified Developer
FileMaker 11 Certified Developer
"We were actually able to add more features than we thought would be possible within our budget. We always experienced a ‘can do’ attitude and DB Services was incredibly patient and easy to work with."
Courtney Hartman
Art Director
"The new FileMaker custom website interface is very user-friendly and easy to follow for our clients. In addition, it is much faster than the old Instant Web Publishing (IWP) interface. Thank you and all the others who have helped us out at DB Services. I am very grateful for the excellent service you provide us. Its nice to know we can call you for help if we have an issue."
Wayne Capek
President
"We needed a solution that would simplify the administration of our responsibilities under our contract with the State of Indiana. We have seen a dramatic increase across the state in the number of potential foster and adoptive parents that have begun the preparation and training process. This increase has resulted in a significant opportunity for children available for adoption. That’s a big win for everyone! And it’s all because we can refer potential parents to the proper state contacts efficiently and quickly."
Chris Morrison
Executive Director
"Thank you for all of your expertise and valuable help. I am so grateful to have found DB Services."
Linda Findlay
Owner
"Thank you for our new database system. We transitioned from a carbon copy paper based system to a digital database. The software has saved us time and money. We used to archive all our jobs in cabinets, now we can look up a job in seconds from anywhere. The software allows us to easily email estimates to our customers in pdf format. In a year there was a return on investment just from eliminating the purchasing of our carbon forms."
Todd Cartmel
Owner
"The new system allows us to create and track jobs for customers along with inventory, something we had been doing with separate word and spreadsheet files. Because it’s now so intuitive, new staff members are able to begin using the database immediately without our usual training session and ‘cheat sheets’ for getting around within the file."
Tom Andrews
President