en:h2k:doc:5
Различия
Показаны различия между двумя версиями страницы.
| Предыдущая версия справа и слеваПредыдущая версия | |||
| en:h2k:doc:5 [2023/07/31 10:38] – anel | en:h2k:doc:5 [2024/09/09 08:20] (текущий) – внешнее изменение 127.0.0.1 | ||
|---|---|---|---|
| Строка 1: | Строка 1: | ||
| + | ====== Security ====== | ||
| + | ====Properties==== | ||
| + | * protection against unauthorized physical access to information; | ||
| + | * bind to the host where the virtual machine is running; | ||
| + | * external outbound network rules allow communication only with 3 fixed nodes (HTTPS), 2 [[en: | ||
| + | * external inbound network rules allow only SSH connections to the console; | ||
| + | * the console authorizes through Open [[https:// | ||
| + | * the internal firewall repeats the external network rules. | ||
| + | |||
| + | ---- | ||
| + | |||
| + | ====HCL Notes==== | ||
| + | |||
| + | The Domino® security model is based on the principle of securing resources, such as the Domino® server itself, databases, workstation data, and documents. The resources or objects that are protected are configured to define user access and edit rights to the object. Information about access rights and privileges is stored with each protected resource. That way, a given user or server can have different sets of access rights depending on the resources to which this user or server needs access. | ||
| + | |||
| + | ---- | ||
| + | |||
| + | ====Creating a BlackBox==== | ||
| + | |||
| + | * Create an image on a [[en: | ||
| + | * Transfer of the image to the working site; | ||
| + | * [[en: | ||
| + | * The initial Domino configuration phase is administered from a neighboring clean machine; | ||
| + | |||
| + | ---- | ||
| + | |||
| + | ====Solution | ||
| + | ===OS=== | ||
| + | * VMware virtual machine; | ||
| + | * Oracle Linux operating system; | ||
| + | * The partition is encrypted; | ||
| + | * On a restart, a partition decryption password is required; | ||
| + | * Bind to a virtual machine. | ||
| + | |||
| + | ===Domino=== | ||
| + | * Server id password; | ||
| + | * Encryption of the databases used (server id keys; | ||
| + | * There are only 2 Management Servers cross-certificates in the address book; | ||
| + | * Encryption of the traffic at the Domino network port level; | ||
| + | |||
| + | ---- | ||
| + | |||
| + | [[en: | ||
| + | |||
| + | However public nodes can connect to one of the three external fixed nodes, provided that no data is stored on it, so in case of hacking, data leakage will not occur. | ||