Drupal Security - installing Drupal on an institutions servers

Events happening in the community are now at Drupal community events on www.drupal.org.
shambler's picture

Hi there

I've currently been testing Drupal on my own hosting space which has been fine.

I did this because at the Unversity I work at it can be a pain to get software installed - the server guys+gals are not that happy to see me put new software on our servers (we have two dedicated to our department) - understandably their concerns are security support issues etc. I wanted to see if Drupal was for us before I went through the process of getting it installed.

After deciding on Drupal as the way forward and putting my ticket in for installation on our testing server it is apparent they are very nervous about Drupal in terms of security and the time it may take to get set up.

We are running a WIMP stack (I guess that means windows IIS MySqL. PHP?) which I suppose does have its own challenges (I know MS do a Acquia install thing ) - is there any guidance or posts out there (I've done a bit of searching) that can help me with my discussions with the network people in terms of convincing them that Drupal is secure?

The situation does seem a bit frustrating when I can have Drupal up and running relatively quickly on commercial hosting, but obviously things are different when it comes to doing anything where I have very little in the way of admin rights to the servers (i.e. I would have to put in a request to change directory permissions). Anyone been in a similar postion?

Sorry if the post title is rubbish BTW!

Comments

I have been on both sides of

Anthony Gettig's picture

I have been on both sides of this. Here's what has worked well for me.

Build your solution either on WAMP/MAMP (or in your case, WIMP) on your local machine. If you can do it in a virtual machine, even better. Setup a time with whoever is in charge of deploying new apps/servers at your institution and show them the overall site, what is under the hood, and then the permissions that are setup. If you have a virtual machine, you may be able to just give them a copy of the entire VM to hammer on for themselves.

Make sure you have a plan for keeping the core and modules up to date. Track down whatever listserv or RSS you need to so you are informed when updates are released. I would even create a document that shows these update information sources that I could show to the approving parties. Make sure you get the point across that you are serious about security and stability as well.

Finally, solicit their input on your solution. Ask them if they know how to make it more secure and stable. They probably won't, but the stroke to their ego won't hurt your proposal. :) And if they do know of things that can help, then great! You just made your solution that much better and they become a minor stakeholder.

All that said, there have been times when I have said it's just not worth the effort and end up keeping it on an external hosting service. Pick your battles carefully!

FWIW. YMMV. Good luck!

Thanks for the advice

shambler's picture

Thanks for the advice Anthony. If I learn anything, I'll share.

Yeah.. same issue w/ paranoid

btopro's picture

Yeah.. same issue w/ paranoid network admins in the past. I'm not really sure what you can say to quell fears other then maybe to point to statistics like how long vulnerabilities stay active (less then 2 weeks typically I think) and how many sites are using it.

Also be aware that they'll probably trim the feature set and access levels from what you'd like to have. Definitely had those issues in the past as well. They might also require private downloads as I know some have here before for security's sake (again, mostly paranoia). I'm not sure of your setup but our sites/machines are only accessible if you login via Co-sign / Webaccess so throwing it behind a centrally supported authentication system also helped quell fears.

If worse comes to worse just say the Big 10 is in love with it and that should work ;)

Drupal in Education

Group organizers

Group notifications

This group offers an RSS feed. Or subscribe to these personalized, sitewide feeds: