Some of the technical content on this site is only available in English.

Security tab in Space General options

Overview

The Security tab is only available for operators with admin rights (admin operator).

This section covers the password management in Space. As well as explaining the main operator password options, it also indicates how to enable the Lightweight Directory Access Protocol (LDAP) for both operators and users. Space is compatible with Service Directories which support the LDAP Protocol. The Enforce password policy is enabled by default when creating a new system.

First login for new installations from Space 6.13 onwards: When logging in to Space for the first time after installation, you must set both a new administrator username and a secure password.

  • The login screen will not show any default username or password.
  • You must choose a unique username (up to 64 characters) for the administrator account.
  • The administrator's display name will also be set to the chosen username.
  • Both username and password can be changed later from the operator profile.

Username and password fields for a new database createdPassword fields for a new database created

The initial password settings can be modified from System > General options > Security.

'Operators' panel in 'Security' tab'Operators' panel in 'Security' tab

Security tab items

ItemDescription
Enforce account lockout policyNumber of failed logon attempts that will lockout the account (5 by default).
Reset failed logon attempts that will lockout the account in minutes. If the operator tries the password with no success the attempt number will be reset after the period defined (10 minutes by default).
Define either the time the account will remain locked out after the number of attempts is exceeded or restrict the release of the account to the system administrator. By default it is set to 30 minutes.
Enforce minimum time between password changesMinimum number of days to allow the password to be changed. Disabled by default.
Password minimum lengthSets the minimum number of characters required for passwords (range: 1-128 characters). Default is 12 characters for new databases. Maximum password length is 128 characters. Passwords are also checked against a list of common/breached passwords that are not permitted.
Enforce password character requirementsFor new databases, this setting is disabled by default, allowing any combination of characters. When enabled, the first two sub-options are enabled by default and cannot be turned off individually.
The sub-options are the following:
- Require at least one uppercase and one lowercase letter
- Require at least one number or one special character: !"#$%&'()*+,-./:;<=>?@[]^_`{
Enforce password expirationNumber of days for the password to expire. Disabled by default.
Enforce password historyNumber of previous passwords to be remembered by the system so that they cannot be repeated when creating a new password.
Enforce 2FA for all operatorsWhen activating this configuration, all operators, including administrator operators, must configure two-factor authentication next time they log in. See Two-factor authentication and Logging in with two-factor authentication enabled for more information.

Password policy migration: When upgrading Space from previous versions, existing passwords remain valid until changed. The new password requirements only apply when users change their passwords after the upgrade.

For databases upgraded from previous versions:

  • If Enforce password policy was enabled: Password minimum length is set to 8 characters and Enforce password character requirements is enabled

  • If Enforce password policy was disabled: Password minimum length is set to 1 character and Enforce password character requirements is disabled

Password visibility features

Space includes password visibility options to improve usability:

  • Login screen: The password visibility icon allows users to temporarily show/hide their password while typing
  • Password change screens: Users can view both current and new passwords while entering them

These features help users ensure they're entering passwords correctly while maintaining security.

View password optionThe password visibility icon allows users to temporarily show/hide their password

LDAP for operators

You can enable the Lightweight Directory Access Protocol (LDAP) for operators from the Security tab in General options.

'LDAP' panel in 'Security' tab - Operators'LDAP' panel in 'Security' tab - Operators

Once this option is enabled, you need to fill the necessary setup to enable the connectivity with your LDAP.

To complete the configuration of LDAP for operators, also contact your technical support team. They should be able to provide more information on the technical details on your specific IT setup for using LDAP.

The synchronizing of LDAP operators allows the synchronization of operators from an Active Directory using LDAP protocol. There is no need to store operator's credentials (that is, username and password) in Space database for authentication purposes. The credentials are directly saved in the Directory Service.

Once this setup is done you must carry out a synchronization or a scheduled job.

LDAP for users

You can enable the Lightweight Directory Access Protocol (LDAP) for users from the Security tab in General options.

'LDAP' panel in 'Security' tab - Users'LDAP' panel in 'Security' tab - Users

Once this option is enabled, you need to fill the necessary setup to enable the connectivity with your LDAP.

To complete the configuration of LDAP for users, also contact your technical support team. They should be able to provide more information on the technical details on your specific IT setup for using LDAP.

The synchronizing of LDAP operators allows the synchronization of operators from an Active Directory using LDAP protocol. These users can be associated with a user access level.

Once this setup is done you must carry out synchronization a scheduled job.

Proxy configuration

You can enable and configure a Proxy client from the Proxy configuration panel in the Security tab within General options.

'Proxy configuration' panel in 'Security' tabYou can enable and configure a Proxy client from the 'Security' tab

Select Proxy client enabled and then, fill the host and the port fields.

The Authentication required checkbox will be helpful in the cases where authentication is required. When selected, the following fields are activated:

  • Username: the username you want to configure to authenticate.
  • Manager password: the password you want to configure for this username option.
  • Confirm password: enter the password again.

If you need further assistance in the Proxy configuration process, contact your technical support team.

Database backup security

The Database backup security panel allows you to configure the security settings for the database backup process.

Prerequisites

  • In new installations, default configuration will be restrictive, where backup paths must be created beforehand by an operator with admin role.
  • In new installations, a default SQL Server instance path will exist. This will be a symbolic path, as it will not be possible to specify a path manually.
  • At the security level, it will not be possible to freely define the name of the backups or the paths where backups are stored.
  • A non-configurable denylist will exist, which will prevent creating routes to sensitive system locations.

Configuring the database backup security settings

  1. Select the Enforce allowed backup locations to restrict the backup paths that can be configured in automatic scheduled backup jobs and when making a database backup. When this option is enabled, the Allowed backup locations list is displayed. This list cannot be empty, otherwise a warning is displayed requiring at least one path to be present before the configuration can be saved. The backup locations paths that can be configured when creating automatic scheduled backup jobs and database backups are restricted to the paths defined in this list.

'Database backup security' panel in 'Security' tabYou can enforce allowed backup locations from the 'Security' tab

  1. Add the required paths. Only admin operators can add paths to the allowed backup locations list using the Add path button.

  2. Once you add a path, you can validate it by clicking the Verify button to ensure that it is a valid path and that the service has the necessary permissions to write to it. A success or failure message will be displayed.

  3. Click Save to apply the changes.

Removing a path from the allowed backup locations list

Use the Remove button to remove a path from the allowed backup locations list after selecting the path.

When a path is removed, and it is being used by an automatic scheduled backup job, a warning message will be displayed to indicate that the action may cause the automatic backup job to stop working and that the configuration needs to be reviewed.

Warning message when a path is being removedWarning message when a path is being removed

Restoring the default allowed backup locations list

You can also restore the default allowed backup locations list by clicking the Restore default button. This button is only active when the default path has been deleted. If the default path already exists in the list, the button is disabled.

Salto Systems, S. L. uses third-party data storage and retrieval devices in order to allow secure browsing and gain a better understanding of how users interact with the website in order to improve our services. You can accept all cookies by clicking the "Accept cookies" button or reject their use by clicking the "Reject cookies" button. For more information, visit our Cookies Policy