Mobile App Security Recommendations

To ensure security, the system administrator must apply the following precautions when configuring the management platform and the mobile device to work with the mobile app.

Internet or Intranet Deployment

The IIS web server of the Desigo CC deployment can be configured to communicate with mobile app clients within an intranet (WLAN) or over the internet (using Wi-Fi or 3G/4G).

See Mobile App Deployment Overview for more information about deployment scenarios.

info

If the mobile app is connected to the management platform over the internet, one or more of the following precautions are recommended:

- Configure the management station Web Services in view-only mode.

- Set up a Virtual Private Network (VPN) connection between the router and the mobile device. Or, as an alternative to a VPN, use a remote IIS Web server in a perimeter network (DMZ) with firewalls.

- Use the IIS Client Certificate Mapping Authentication method to ensure that only mobile devices with a valid certificate can connect to the Web Service Interface.
The vendor does not accept responsibility for misuse of the app in a non-secure environment.

Secure the Connection Between IIS Web Server and Mobile App

The mobile app connects to Desigo CC through a web application hosted on an IIS web server. This communication is secured (https://) with a security certificate that can be:

See Preparing Certificates for the Mobile App for more about information about configuring the certificate used to communicate with the mobile app.

info

It is recommended to always use a public CA host certificate to have the best performance in terms of IT security, especially when the app connects to Desigo CC over the internet.

Secure the Connection Between the Desigo CC Server and the IIS Web Server

For deployments with a remote IIS web server (that runs on a separate computer from the Desigo CC server), communication between the Desigo CC server and the IIS web server computer must be secured with a certificate. For instructions see Preparing Certificates for Web Services.

Secure the Device Wi-Fi Connection

The Wi-Fi channel used by the mobile device must be always protected with WPA2 encryption. To ensure this:

Lock Down the Mobile Device Configuration

The mobile device on which the mobile app is installed must be dedicated exclusively to that purpose, with a software configuration that is tightly controlled and locked down. The user must not, for example, install other apps or alter any of the device settings.

As a security feature, the mobile app will not start on jailbroken or rooted mobile devices, nor will it start if the Android Developer Options are enabled. (See System Requirements).

Protect the mobile devices by appropriate security measures.

For more details, contact customer support.

Protect User Credentials