Security

Bloomreach Content provides configurable access control, supports multiple authentication methods, and integrates with standard enterprise security solutions.

Authentication

Bloomreach Content supports several authentication methods and integration options to fit enterprise requirements.

The default authentication module uses JAAS (Java Authentication and Authorization Service). It supports form-based authentication for both authoring and delivery, and HTTP basic authentication for delivery. User credentials and encrypted passwords are stored in the content repository. You can optionally configure authentication and synchronization with an LDAP server.

You can extend or replace the authentication module using JAAS or the Spring Security Integration plugin.

Two-factor authentication is available through integration with Duo Security.

Single sign-on (SSO) is supported using a reverse proxy. The proxy redirects browser clients to a central SSO server for authentication. After authentication, the client receives a security token and is redirected to the requested page.

HTTPS is supported in both authoring and delivery environments. No additional application-level configuration is required.

Security architecture with proxy, application server, SSO, LDAP, and DBMS

Diagram: This diagram shows a deployment architecture where a browser client connects over HTTPS to a reverse proxy. The reverse proxy connects to an application server, which also integrates with an SSO server, LDAP server, and DBMS. SSL configuration is deployed to the reverse proxy. Authoring and Delivery WAR modules are deployed to the application server and share security configuration artifacts, including Form Authentication, JAAS, and Spring Security Integration configurations.

Authorization and Workflow

Authorization in Bloomreach Content is role-based. You can configure security domains to include or exclude any subset of content, such as channels, folders, content types, or specific fields.

The standard workflow controls the publication process. Authors prepare content, editors review it, and approved content is published to channels. Scheduled publication supports embargoed content.

Within publication channels, webmasters can configure URLs, pages, content mappings, components, and templates.

Audit Trail

Bloomreach Content maintains a complete audit trail of user activity and content changes. The system logs all login attempts (successful and unsuccessful) and all workflow operations. Each content item includes an automatically maintained version history. You can revert content to any previously published version.

DMZ Support

You can deploy Bloomreach Content in a demilitarized zone (DMZ) using content replication. In this setup, a separate cluster with a content repository and delivery tier is placed in the DMZ, while the main cluster (with content repository, authoring, and delivery) remains behind the firewall. Authoring and preview occur only behind the firewall. Only selected published content is replicated to the DMZ content repository. The delivery tier in the DMZ accesses only the replicated content.

Intranet and DMZ replication architecture with firewall-separated servers

Diagram: The diagram shows two network zones: an intranet and a DMZ, separated by a firewall. In the intranet, an authoring client connects to an authoring server, which manages authoring, delivery, and content repository functions with a DBMS. In the DMZ, a delivery server manages delivery and content repository functions with its own DBMS. A browser client connects to the delivery server in the DMZ. Content is authored in the intranet and delivered in the DMZ using replicated content.

Application Security

Bloomreach Content is regularly tested for vulnerabilities, including third-party security audits. The platform is protected against known attack methods. Use the security checklist to verify your delivery tier implementation against the OWASP Top 10 Most Critical Web Application Security Risks.

If a potential vulnerability is identified, Bloomreach follows a defined process to assess, verify, and resolve the issue, and to inform customers and the community.

Share Feedback
Page: /about/why-brxm/security-features
Section: About
Category *