Add new attachment

Only authorized users are allowed to upload new attachments.

List of attachments

Kind Attachment Name Size Version Date Modified Author Change note
jpg
hardening_csp1.jpg 607.6 kB 1 27-Jan-2025 23:32 Ada Csaba
jpg
hardening_ftp1.jpg 675.7 kB 1 27-Jan-2025 23:33 Ada Csaba
jpg
hardening_pgp1.jpg 298.0 kB 1 27-Jan-2025 23:33 Ada Csaba
jpg
hardening_pgp2.jpg 406.7 kB 1 27-Jan-2025 23:33 Ada Csaba
jpg
hardening_sftp1.jpg 637.1 kB 1 28-Jan-2025 00:31 Ada Csaba
jpg
hardening_ssl.jpg 587.1 kB 1 27-Jan-2025 23:33 Ada Csaba

This page (revision-40) was last changed on 28-Jan-2025 00:56 by Ada Csaba

This page was created on 05-Dec-2023 05:32 by Ben Spink

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Difference between version and

At line 4 removed one line
\\
At line 8 changed one line
\\
----\\
At line 11 removed one line
[{Image src='hardening_ssl.jpg' width='100%' height='..' align='left' style='..' class='..' }]
At line 13 removed 2 lines
!Hardening the HTTP headers
Usually resetting the WebInterface[CSP|CSP] page to defaults will do. When using SAML, OAUTH, or other external IDP integration, will need to add the IDP portal domain as allowed domain.\\
At line 12 added 6 lines
----\\
!Hardening the HTTP headers\\
Usually resetting the WebInterface->[CSP|CSP] page to defaults will do. When using SAML, OAUTH, or other external IDP integration, will need to add the IDP portal domain as allowed domain.\\
\\
[{Image src='hardening_csp1.jpg' width='100%' height='..' align='left' style='..' class='..' }]
\\
At line 20 added one line
----\\
At line 19 changed 2 lines
On IP/Servers page select the __SFTP__ server listener, select the {Advanced|SSH] tab, remove all weak algorithms from the list. The actual strength of various algorithms is debated, must consult your own security advisor. Usually the __NIST__ recommanded algorithms
will satisfy most security assessors.\\
On IP/Servers page select the __SFTP__ server listener, select the __Advanced__ tab, remove all weak algorithms from the list. The actual strength of various algorithms is debated, must consult your own security advisor. Usually the __NIST__ recommanded algorithms will satisfy most security assessors.\\
At line 24 added 5 lines
\\
__Hostkey algorithms:__\\
\\
Use the default __RSA__ or enable __ECDSA__ and/or __ED25519__.\\
\\
At line 41 added 16 lines
\\
----
\\
If you need __data at rest encryption:__\\
\\
1.) Go to the User Manager, default user.\\
2.) Do a quick filter on "pgp".\\
3.) Configure a public and private key for the PGP encryption. Doing it here on the default will automatically apply to all users.\\
[{Image src='hardening_pgp1.jpg' width='100%' height='..' align='left' style='..' class='..' }]
\\
[{Image src='hardening_pgp2.jpg' width='100%' height='..' align='left' style='..' class='..' }]
\\
----
\\
__IMPORTANT:__ Do not try to disable or remove the default user as the user cannot be used for logins and is just for applying settings.
Version Date Modified Size Author Changes ... Change note
40 28-Jan-2025 00:56 3.421 kB Ada Csaba to previous
39 28-Jan-2025 00:55 3.424 kB Ada Csaba to previous | to last
38 28-Jan-2025 00:49 3.423 kB Ada Csaba to previous | to last
37 28-Jan-2025 00:46 3.422 kB Ada Csaba to previous | to last
36 28-Jan-2025 00:45 3.426 kB Ada Csaba to previous | to last
35 28-Jan-2025 00:44 3.418 kB Ada Csaba to previous | to last
34 28-Jan-2025 00:42 3.267 kB Ada Csaba to previous | to last
33 28-Jan-2025 00:41 3.235 kB Ada Csaba to previous | to last
32 28-Jan-2025 00:40 3.223 kB Ada Csaba to previous | to last
31 28-Jan-2025 00:40 3.227 kB Ada Csaba to previous | to last
30 28-Jan-2025 00:39 3.211 kB Ada Csaba to previous | to last
29 28-Jan-2025 00:38 3.207 kB Ada Csaba to previous | to last
28 28-Jan-2025 00:35 2.782 kB Ada Csaba to previous | to last
27 28-Jan-2025 00:35 2.776 kB Ada Csaba to previous | to last
26 28-Jan-2025 00:32 2.68 kB Ada Csaba to previous | to last
25 28-Jan-2025 00:32 2.684 kB Ada Csaba to previous | to last
24 28-Jan-2025 00:30 2.678 kB Ada Csaba to previous | to last
23 28-Jan-2025 00:30 2.674 kB Ada Csaba to previous | to last
22 28-Jan-2025 00:29 2.664 kB Ada Csaba to previous | to last
21 28-Jan-2025 00:28 2.66 kB Ada Csaba to previous | to last
« This page (revision-40) was last changed on 28-Jan-2025 00:56 by Ada Csaba
G’day (anonymous guest)
CrushFTP11 | What's New
JSPWiki