Secure a Master Data Manager Web Application
Applies to: SQL Server - Windows only Azure SQL Managed Instance
You can secure the Master Data Manager web application with HTTPS.
Note
The Master Data Manager web application can use either HTTP or HTTPS, but not both.
Prerequisites
To perform the procedure:
You must be an administrator on the web server where Master Data Manager is installed.
MDS must be installed on the web server, and a web application must exist. For more information, see Install Master Data Services and Create a Master Data Manager Web Application (Master Data Services).
IIS Extended Protection for Windows authentication should not be enabled.
Configure the web server to listen on all available IP addresses. Do not configure the Web server to listen on a specific IP address.
To secure the Master Data Manager web application with HTTPS
After you have confirmed that the Master Data Manager web application is configured correctly with HTTP, create a certificate in IIS. For more information, see Configuring Server Certificates in IIS 7.
In the Connections pane, under Sites, click the site that hosts the Master Data Manager web application.
In the Actions pane, click Bindings.
Click Add.
From the list, select https.
Select the TLS/SSL certificate.
Click OK.
Optional. To remove HTTP so that users can access the site with HTTPS only, from the list, click the row with http. Click Remove and on the confirmation dialog box, click Yes.
Important
You must change basicHttp and wsHttpBinding configurations after removing HTTP.
To close the Site Bindings dialog box, click Close.
Now open the web.config file from drive:\Program Files\Microsoft SQL Server\130\Master Data Services\WebApplication.
Find the string
<security mode="Message">
and change it to<security mode="Transport">
.Change
<serviceMetadata httpGetEnable="true" httpsGetEnabled="false">
to<serviceMetadata httpGetEnable="false" httpsGetEnabled="true">
to prevent issues that may appear in the Silverlight client.Save and close the file. If you get an error, it could be because you have UAC enabled. Users should now be able to use HTTPS to access the site.
See Also
Create a Master Data Manager Web Application (Master Data Services)