Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, October 22, 2018

Securing CentOS With Unattended Yum-Cron Security Updates

to do unattended security upgrades on CentOS, yum-cron can be used.

install yum-cron:
sudo yum install yum-cron

configure yum-cron and update the following:
update_cmd = security apply_updates = yes

start and enable yum-cron service:
sudo systemctl start yum-cron sudo systemctl enable yum-cron

if, in case you have problem installing because of conflicting files from yum-cron and yum installations, with a similar message as below:


do a yum update then try installing yum-cron again:
sudo yum update
sudo yum install yum-cron

(src: https://serversforhackers.com/c/automatic-security-updates-centos)

Thursday, August 24, 2017

AWS S3 Encryption Options




Here are options for AWS S3 encryption...
(ref: http://docs.aws.amazon.com/AmazonS3/latest/dev/UsingEncryption.html)

Fastest implementation is using SSE-S3, most secure implementation is using CSE-KMS, middle ground implementation is using SSE-KMS.

Overview of Types:

    Server Side Encrypyion (SSE) - this ensures encrypted files in storage
               
                Key Management Options:
               
                    - SSE-S3 Managed Keys - keys handled by S3
                                          - enable through AWS Management Console or HTTP request header
                   
                    - SSE-KMS (Key Management Service) - master encryption key is used to encrypt encryption keys
                                                       - keys managed by AWS-KMS
                                                       - specify id of aws-kms-key to use for encryption

                    - SSE-C (Client) - master encryption key is used to encrypt encryption keys
                                     - keys managed by client
     
    Client Side Encryption (CSE) - this ensures encrypted files before being sent to storage
                     
                Key Management Options:
               
                    - CSE-KMS (Key Management Service) - master keys are managed by AWS-KMS
                   
                    - CSE-C (Client) - master keys are managed by the client
                   

AWS KMS cost is $1 per key and $0.03 / 10,000 requests, as of writing.

As stated earlier, SSE-S3 for quickest, and CSE-KMS for most secure, and SSE-KMS for middle ground implementation.

SSH : No matching host key type found. Their offer: ssh-rsa,ssh-dss

Got this while connecting to my mikrotik router via ssh   Unable to negotiate with <ip address> port <ssh port>: no matching hos...