Security in PTC Windchill – Part 2 of 2

  • Blogs
  • PLM
  • Sort by type
  • Technologies
Published on
2017-11-03
Written by
Jesper Lundgren

In my last post on the theme security in Windchill I provided some general tips for creating a safer server environment and gave examples of what threats exist. The conclusion was that with good routines and with a complete backup we can manage most situations. Since my last post was published, major headlines around the world covered a virus called WannaCry. This was a so-called ransomware which encrypted disks and forced the owner to pay a sum of money to unlock them. Fortunately, this virus was quickly stopped, but it gave an indication of how serious this type of attack might be.

However, this post is more about what we can do in Windchill to protect us from threats outside and inside our company. Above all, it is about preventing unauthorized people from getting important information such as drawings and internal documents.

HTTP/HTTPS – Access Windchill

The risk of the usual HTTP protocol is that it does not encrypt the information that is being sent. If users log in via HTTP, it is possible for a third party to read the information sent. Including passwords and usernames. A good first step to raising security levels is to encrypt information being sent between client and server by using HTTPS.

With the HTTPS protocol, all data transmitted is encrypted and cannot be read by third parties. This prevents e.g. that passwords end up in the wrong hands. Setting up HTTPS is a relatively simple configuration and essentially requires only a signed SSL certificate.

These can be arranged by a number of different suppliers and cost no more than hundred euros per year. If there are plans to give users outside the company access to the Windchill environment, e.g. vendors, partners etc. the company should think about how these users will login to Windchill. Can anyone listen and steal their login information if we do not use HTTPS?

Login

In the simplest set of Windchill, users are locally located in Windchill’s own user database. The password is set when the user is created. Usually the password isn’t changed on a regular basis or might even be the same as the username. I have seen this many times at different customers. My recommendation is to not have passwords equal to username, it’s too easy to guess. There is a possibility to set a time limit for passwords, special character requirements or restrict password reuse. However, this is something that is usually already managed by the company’s Active Directory (AD), so a long term solution might be a link between Windchill and your Active Directory (AD).

Active Directory Connection (AD)

Instead of allowing Windchill to manage all users, passwords and policies, Windchill can be linked to the company’s AD. This allows reuse of existing frameworks, which also allow a greater control of users.

For example, accounts can be locked in too many incorrect login attempts and accounts can be disabled when users quit. It also allows users to have the same password for example for Microsoft Windows and Windchill. I can imagine that this eliminates a risk when users need to remember multiple passwords.

User Rights in Windchill

The basis of all Windchill installations is the rights the users have. The rights control everything from who will see what to who will approve what for e.g. for production. But it can also affect security in such a way that the user has too much rights. As a consequence, people will be able to see information they should not be entitled to. At worst, spread this outside the company. “Intellectual Property Theft” is becoming more common. Companies should keep in mind what roles should be able to do what. But also consider different rights for different locations in the world. Especially for those companies that are represented in several regions. One way to enforce a more flexible but yet secure solutions is what’s explained in the next section.

Security Labels

A feature in Windchill used more and more often is Security labels. The purpose is to add an extra protection and provides the ability to control documents with different security classes.

This is a simple but powerful solution and serves as an addition to the common rights in Windchill. A problem that may arise with restrictive access rights is that it reduces the possibility of collaboration, when general rights must be set. But with Security Labels (SL) we can define access individually for each object.

The objects are then classified based on a number of custom classes, such as “Secret” and “Public” or “High” and “Low”. We connect these objects with a link between each classification and a group.

As a result, all members of the group associated with “Secret” will be able to see the items stamped with this SL. This ends the theme of security.

In summary, I can say that with fairly small efforts, the risk of information being lost or ending in the wrong hands is reduced. Remember to continuously evaluate who has access to the system and what protection is available to prevent attacks from outside. Additionally, check periodically that backups are done as they should. I’ve seen too many times how it has been years since the last backup with possible data loss as a result.

Best regards
Jesper Lundgren

Read more about PTC Windchill, the brand name from PTC regarding Product Lifecycle Management (PLM).

Social media

Follow us on our social media platforms


RELATED BLOG POSTS

KeyShot 11.3 for Apple Silicon – Speed Gains and Improved Performance

Keyshot 11.3 is the latest version of Luxion's powerful 3D rendering and animation software designed for......
Read more

Materials make the world go round

The meaning of the word “material” conjures up different ideas for different people. For some, the look......
Read more

Contextual Data for IoT

Meaning of data from IoT sources If you have ever read Hitchhiker’s Guide to the Galaxy, you would know......
Read more

Using Functional Safety and Reliability for a competitive advantage

Functional Safety and Reliability is a hot topic that stimulates many discussions, depending on the......
Read more

PDSVISION and Renholmen extend their collaboration

Thoroughness drives innovation, and no detail is insignificant. Work hard to make the customers satisfied and......
Read more

Getting Started with IoT for Manufacturing

“In the beginning … the earth was formless and empty.”  – Genesis Where to begin? That is a good......
Read more

What’s new in Luxion’s Keyshot 11.2?

Keyshot 11.2! This version offers a range of powerful new features that allow users to create stunning......
Read more

PDSVISION and PTC have together helped further Electrolux Professional’s digital transformation

As a highly profitable, customer-centric business trusted by over half of Europe’s Michelin-star......
Read more

PTC Creo 9 is here – Available via PDSVISION

Creo 9  has landed with a range of updates, new features, and options designed to significantly accelerate......
Read more

PTC Creo 9 – What’s New?

There has been an addition to the PTC family of Design Solutions; PTC Creo 9 has arrived! PTC Creo 9.0 is......
Read more

Compliance within MedTech and the medical device industry

Today's product development faces several challenges, and one of the biggest challenges is regulatory......
Read more

Accelerate digitization with myPDS applications

PDSVISION launches 9 powerful applications to accelerate digitization in the manufacturing......
Read more

Short facts about KeyShot version 11.1

This version includes several new features and improvements that will make creating amazing visuals faster......
Read more

Integrate ECAD with PLM to achieve full product definition

As PLM Business Director, I meet with companies from different industries daily. It is apparent that all......
Read more

KeyShot 11 – Now Available!

The world of visualization infinitely expanded with KeyShot 11 – now available via PDSVISION KeyShot 11 is......
Read more

Enterprise Visualization in the Product and Service Lifecycle Business – one unified automated publication pipeline

As part of digital transformation roadmaps, industrial companies explore enterprise visualization to enhance......
Read more

Experts in product and packaging design company Noun chooses KeyShot and PDSVISION

Noun is a design studio based in Stockholm, Sweden, that specializes in product and packaging design. Noun......
Read more

ANSYS Discovery – Introduction

After long and sunny summer, the fall starts to kick in. Now is the time to get geared up for the winter’s......
Read more

Vuforia Instruct – Complementing PTC’s Industrial AR solutions suite!

    Vuforia, the award-winning and leading Augmented Reality reality solution-centric......
Read more

The Handyman and The Gentleman – AR #7 – Vuforia Work Instructions

To continue discussing how relevant Augmented Reality (AR) is for the industrial enterprise, in this blog, I......
Read more

Working on our ways of working – to support our customer projects in a better way

At PDSVISION we strive to be the best at what we do, and we have always been proud of our deliveries and our......
Read more

PTC Creo 8 – What’s New?

There has been an addition to the PTC family of Design Solutions, PTC Creo 8 has arrived! When an update to......
Read more

The Handyman and The Gentleman – AR #6 – Capture, Edit & Author

In my previous blogs, I have shown and discussed how the PTC Vuforia family of solutions is becoming the......
Read more

OnDosis chooses PDSVISION on their journey into improving healthcare

OnDosis develops products used for flexible and individualized dosing of oral medicines for diseases with a......
Read more

Mathcad Prime 7.0 is here!

PTC have released the seventh version of the Mathcad Prime calculation software which includes a range of......
Read more

The Handyman and The Gentleman – AR #5 – Vuforia Expert Capture – Simple, Secure and Smart

In this blog, the fifth in my series based around my Augmented Reality video series "The Handyman and The......
Read more

Creo combined with Ansys Mechanical – Your Competitive Advantage In Product Design

The challenge of designing winning products is getting more difficult by the day. The choices made in the......
Read more

The Handyman and The Gentleman – AR #4 – Vuforia Expert Capture

I’ve spoken recently in blogs on how AR applications (Augmented Reality) such as PTC Vuforia Chalk can......
Read more

Creo Parametric Behavioral Modeling Extension

Design automation for various design goals with PTC Creo Parametric Behavioral Modeling Extension......
Read more

The Handyman and The Gentleman – AR #3 – Working Hands Free

In my previous blog I explored with you how such a simple task as an onsite customer maintenance task or......
Read more

The Handyman and the Christmas StARs

"How can Augmented Reality come to my aid as I face my biggest challenge since joining PDSVISION? Making......
Read more

The Handyman and The Gentleman – AR #2 Problem Resolution

All business’ understand the importance of getting the work done correctly and to standard the first time.......
Read more

Keyshot 10 – Now Available

Keyshot 10 is here and available via PDSVISION. KeyShot 10 brings unbound creative capability to help realise......
Read more

Trimble AB Invest In Luxion Keyshot

[caption id="attachment_10854" align="alignleft" width="300"] Image: Trimble[/caption] Luxion KeyShot is the......
Read more

The Handyman and The Gentleman – AR #1 – Getting Work Done

Imagine you’re a Field Technician, sent out to a customer to perform scheduled customer maintenance.......
Read more

Ambulansproduktion and PDSVISION continue their joint journey!

Ambulansproduktion develops the markets most innovative and robust ambulances. These ambulances create safety......
Read more

Leaving Information Island

Democratizing information is a cornerstone for a successful Digital Transformation In projects that aim to......
Read more

Energy Machines and PDSVISION initiate collaboration!

Energy Machines and PDSVISION started collaboration around both CAD and PLM components, last week. This with......
Read more

The undoubted benefits of implementing a PDM system

For any product development company, the PDM System (Product Data Management) is an essential component as it......
Read more

Before you can really consider AR and VR, you need to get the conversation going!

Before you can really consider if AR and VR will have a beneficial impact on your business, you need to get......
Read more

PTC Creo Parametric ( Pro/ENGINEER) vs. Solidworks – The Second Coming

Hello, do not worry, I am not intending to discuss with you W. B. Yeat's famous poem from 1919 today! No, I......
Read more

How do I create a single part in the context of the assembly in PTC Creo Parametric?

For historical reasons, PDSVISION Germany has many customers who use Creo Elements / Direct Modelling.......
Read more

AR – Meeting the Industrial Enterprise needs in manufacturing

My clients ask, "How can AR make our production staff and manufacturing process more efficient?" Is there a......
Read more

The Need of Digital Twins to Support Circular Economy

PDSVISION has recently participated in the EU Commission funded Horizon 2020 project studying circular......
Read more

Whats new in PTC Creo 7.0?

Here in Finland, Spring returns and brings new sprouts from the ground, leaves to trees and endless sunshine......
Read more

PTC Creo vs SOLIDWORKS

Rivalry between Creo vs SolidWorks. As a senior consultant for PDSVISION I spend a lot of time with......
Read more

Getting things done remotely, in a world that almost changed overnight

Vuforia Chalk - The solution to the collaboration challenges we face within 3d design With people’s......
Read more

Ansys – More Than Just Simulation

We at PDSVISION have supplied solutions around Ansys portfolio of products for some years, especially Ansys......
Read more

5 Reasons to invest in KeyShot

Create 3D renderings, animations and interactive visuals. KeyShot is Luxions globally known stand-alone......
Read more

PDSFORUM – time well invested

PDSFORUM – time well invested "4.5 out of 5 in the score for our workshops" Participant survey "The most......
Read more

Delivering value with Augmented Reality

A conference room filled to the breaking point was the scenario when we hosted a breakfast seminar together......
Read more

Getting started with PTC Creo Simulation Live now easier than ever!

PTC Creo Simulation Live is one of the first results to come form the partnership between PTC and Ansys. It......
Read more

BoM Transformation – Product Lifecycle Data is Created in Engineering

[caption id="attachment_7471" align="alignright" width="300"] BoM Management in PTC......
Read more

Change Management – A Cornerstone

"….most design is a variation from or modification to, an already existing product or machine". (Cross,......
Read more

PTC Creo – The best CAD software on the market today

Religion, politics, what football team you cheer for, some topics can generate emotions instantly when......
Read more

Creating Inheritance Models for Manufacturing with Creo Parametric (Formerly Pro/ENGINEER)

In design, the question often arises as to how you can design so that you do not have any problems later on,......
Read more

The benefits of using myPDS Configurator

I find PTC Creo Parametric as an excellent 3D CAD solution for large, configurable assemblies. Creo......
Read more

Different Product Configuration Approaches

Product Configurators gives companies a possibility to manage product variants in an efficient way, for PTC......
Read more

Windchill 11.1 – PLM in the modern web

Windchill 11.0 has been around for the last two years. With its release PTC started a journey to renew the......
Read more

Creo 5.0 Update

The PTC Creo 5.0 release is jam packed with new features, Topology optimization studies, built in flow......
Read more

Saving Heat Treatment Steps Means Saving Costs

Cut manufacturing costs with MAGMASoft Many of our customers ask me if we can help them to cut manufacturing......
Read more

3D printing with Creo Parametric

3D printing or, a bit more technically phrased, Additive Manufacturing, may be on everyone’s lips and......
Read more

myPDS Apps – What problem do they solve?

PDSVISION has been developing for years add-on solutions for PTC software users. I am regularly asked why are......
Read more

Great features in Creo Simulate

Some hints on existing functionality that one might not be so familiar with and some features from Creo......
Read more

XML – DITA, DocBook, S1000D or Shipdex – Are you confused?

More and more, technical writers are realizing the value of XML as a format to use for their document......
Read more

Security in PLM System Windchill – Part 1 of 2

Security is something we often seem to take for granted. The problem with this is when something goes wrong,......
Read more

Take Control of your Creo Parametric modeling

Many companies are continuously expanding their utilization of 3D CAD. Both for manufacturing material but......
Read more

Five tips from our Support

Our Support team helps our customers worldwide with our solutions, Creo (3D CAD), Windchill (PLM), Simulation......
Read more

Life as a Support Engineer at PDSVISION Support

Working as a support engineer at PDSVISION Support is a varied job and no day is like the other as you get to......
Read more

11 great improvements in Windchill 11 – Part 2 of 2

PTC Windchill 11 was launched 15th of November, the top highlights - Top down support of Find Numbers......
Read more

What is your IoT strategy?

Business leaders are today aware of the potential of the Internet of Things (IoT) to fundamentally change......
Read more

11 great improvements in Windchill 11 – Part 1 of 2

This is part 1 of my Windchill blog review of the improvements in PTC Windchill 11.0 (PTC Windchill PDMLink),......
Read more