Security

Setup HTTPS

Transport Layer Security (TLS) is a cryptographic protocol that provides communications security over a computer network. Websites, like the Web Management Console, are able to use TLS to secure all communications between their servers and web browsers.

The TLS protocol aims primarily to provide confidentiality (privacy) and data integrity between two communicating computer applications.

Info

HTTPS is not enabled by default. As a consequence sessions between the wizard's backend and the browser may be insecure.

Steps to setup this feature:

  1. Go to Inventory> Certificates

  2. Click Add certificate

    1. To add a certificate using a file path, choose Add by path and enter the location of both the certificate and its corresponding private key file.

    2. To upload certificate file, select Upload file.


Certificate YML sample file:

---
private_key: |
-----BEGIN PRIVATE KEY-----
MIIJQwIBADANBgkqhkiG9w0BAQEFAASCCS0wggkpAgEAAoICAQCjYtuWaICCY0tJ
PubxpIgIL+WWmz/fmK8IQr11Wtee6/IUyUlo5I602mq1qcLhT/kmpoR8Di3DAmHK
nSWdPWtn1BtXLErLlUiHgZDrZWInmEBjKM1DZf+CvNGZ+EzPgBv5nTekLWcfI5ZZ
toGuIP1Dl/IkNDw8zFz4cpiMe/BFGemyxdHhLrKHSm8Eo+nT734tItnHKT/m6DSU
0xlZ13d6ehLRm7/+Nx47M3XMTRH5qKP/7TTE2s0U6+M0tsGI2zpRi+m6jzhNyMBT
J1u58qAe3ZW5/+YAiuZYAB6n5bhUp4oFuB5wYbcBywVR8ujInpF8buWQUjy5N8pS
Np7szdYsnLJpvAd0sibrNPjC0FQCNrpNjgJmIK3+mKk4kXX7ZTwefoAzTK4l2pHN
uC53QVc/EF++GBLAxmvCDq9ZpMIYi7OmzkkAKKC9Ue6Ef217LFQCFIBKIzv9cgi9
fwPMLhrKleoVRNsecBsCP569WgJXhUnwf2lon4fEZr3+vRuc9shfqnV0nPN1IMSn
zXCast7I2fiuRXdIz96KjlGQpP4XfNVA+RGL7aMnWOFIaVrKWLzAtgzoGMTvP/Au
ehKXncBJhYtW0ltTioVx+5yTYSAZWl+IssmXjefxJqYi2/7QWmv1QC9psNcjTMaB
QLN03T1Qelbs7Y27sxdEnNUth4kI+wIDAQABAoICAFWe8MQZb37k2gdAV3Y6aq8f
qokKQqbCNLd3giGFwYkezHXoJfg6Di7oZxNcKyw35LFEghkgtQqErQqo35VPIoH+
  1. Go to Settings > Security

  2. On the Secure Connection section, click Details

  3. Select Enable Certificate , then select your certificate added in step 2.


Warning

Applying HTTPS settings may take some time. During this process, the MetaDefender Cluster Control Center web console will be temporarily unavailable.

Password policies

Password Policy settings are accessible under Settings > Securitytab.

Info

These password policies changes only apply to new user creations and future password changes. Existing users' passwords are unaffected.

Local users' password can be enforced to meet requirements set by administrators, which includes following constraints:

  • Enforce password policy:

    • Determines the number of unique new passwords that must be associated with a user account before an old password can be reused

    • Range: [0-24]

    • Default: 0 (to disable enforcement)

  • Minimum password length:

    • The least number of characters that can make up a password for a user account

    • Range: [0-30]

    • Default: 0 (to disable enforcement)

  • Password must meet complexity requirements:

    • Determines whether passwords must meet a series of guidelines that are considered important for a strong password.

    • Default: unchecked


Session policies

Administrators can enforce session policies for local users to ensure compliance with organizational requirements, using the following settings:

  • Enable idle session timeout:

    • Idle timeout automatically terminates a user's session based on how long since their last recorded activity.

    • Default: 300 seconds.

  • Enable session timeout

    • Absolute timeout terminates an individual user's session after a fixed duration, regardless of any user activity.

    • Default: 0 (to disable enforcement)

  • Allow Duplicate Sessions

    • Permit the same user to log in and operate multiple sessions at once.

    • Default: Enabled.

  • Allow Cross IP Sessions

    • Permit requests from sources other than the authenticated origin.

    • Default: Disabled.