Skip to content

JumpCloud 宣布推出全新的 SaaS 管理工具 助公司企業對抗揭露「影子 IT」(Shadow IT)

在日常運營中,您已經需要處理大量的核心任務:管理員工和承包商的入職和離職,維護網絡和共享資源,解決終端用戶的技術問題,抵禦安全威脅……這些工作不勝枚舉。只要您能掌握問題的全貌,並擁有應對的工具,任何難題都不會難倒一個組織良好的團隊。

然而,問題在於 IT 可能在背後悄悄運作。

「影子 IT」聽起來像是一部恐怖電影的名字,但它在現實中確實存在,並且通常是由於員工想提升工作效率、表現更好。他們會尋找幫助他們提高生產力的解決方案,但這些解決方案往往是在沒有 IT 部門監控的情況下被採用。現代「影子 IT」主要是由 IT 部門未監管的 SaaS 應用程式組成,這可能導致營運效率低下、成本增長以及安全漏洞的出現。

為了幫助您的公司企業更好地管理這些未經授權的 SaaS 應用程式,JumpCloud 宣布推出全新的 SaaS 管理工具。

這款新工具能幫助 IT 管理員發現所有受管理設備上使用的 SaaS 應用程式,讓您清楚知道哪些應用被使用,以及使用者是誰。JumpCloud 的 SaaS 管理工具有助於控制 SaaS 增長,防止「影子 IT」,擴大單一登錄(SSO)的覆蓋,降低 SaaS 成本,確保公司企業內部的 SaaS 使用安全、合規並經過優化。

為什麼選擇 JumpCloud SaaS 管理?

如今,許多公司企業難以管理跨部門使用的 SaaS 應用程式。由於 SaaS 工具的採用相對簡單,這些應用的數量容易失控,導致 SaaS 應用的過度擴散以及潛在的安全問題。未知或未授權的 SaaS 應用,通常被稱為「影子 IT」,可能會繞過安全政策,造成安全風險、合規性問題和不必要的開支。

對於中小企業(SMEs)和為其提供服務的管理服務供應商(MSPs)來說,這些挑戰尤為明顯。有限的資源使他們很難實施和維護 SaaS 管理。中小企業和 MSP 通常缺乏專門的 IT 人員和工具來有效地跟蹤和管理眾多的 SaaS 應用程式,導致數據洩露、知識產權的損失以及難以滿足監管要求。

儘管一些 MSP 使用防火牆或路由器報告等解決方案來應對這些風險,但隨著混合辦公和遙距工作的普及,這些方法變得不再那麼有效。JumpCloud 提供的幾乎實時的 SaaS 使用信息,能幫助 IT 管理員更好地掌控 SaaS 使用情況,並與客戶共享。

JumpCloud 的 SaaS 管理解決方案使 IT 團隊能夠有效保護和管理公司企業內的 SaaS 應用程式。公司企業可以利用 JumpCloud 簡化 SaaS 應用的發現,防止「影子 IT」,擴展 SSO 覆蓋範圍,並在一個綜合平台上實現合規要求。

SaaS 管理的關鍵優勢

可視化和控制
通過 JumpCloud 的 SaaS 探索和監控功能,您可以在安全性和生產力之間找到最佳平衡。


您可以全面了解已授權和未授權的應用程式,包括 SSO 登錄,從而掌控公司企業內部的數據散佈,幫助 IT 管理員將傳統的手動 SaaS 跟蹤方法轉變為精確的自動化流程。

改善 SaaS 成本
JumpCloud 讓 IT 管理員可以輕鬆檢測未授權或未充分利用的 SaaS 應用程式。

通過整合和追蹤授權,IT 管理員可以協商更好的合同條款,了解使用趨勢,重新分配資源,減少不必要的開支,確保每個 SaaS 應用程式都與公司企業的目標和預算相符。

保護 SaaS 訪問與使用
確保員工的工作不被打斷,並在無縫的工作體驗中享受安全保障。

IT 管理員可以在用戶存取未經批准的 SaaS 網域時自動警告或直接阻止,並提供安全的替代方案。用戶可以安全、順暢地存取經授權的 SaaS 工具。

主要功能

發現「影子 IT」
管理員可通過 JumpCloud 瀏覽器擴展來識別和追蹤 SaaS 應用程式及帳戶
阻止訪問未授權應用
管理員可阻止對未經 IT 部門批准的應用程式的存取,並建議替代方案。透過警示和政策來引導員工採取適當行動,降低安全與合規風險
擴展 SSO 覆蓋範圍
管理員可確定哪些應用已與 JumpCloud SSO 整合,並識別可新增的應用以擴展安全 SSO 存取
追蹤 SaaS 使用
管理員可監控 SaaS 應用程式的使用情況,並報告員工的參與度,從而減少在未充分利用的應用程式上的不必要支出

註: JumpCloud SaaS 管理工具目前支援 JumpCloud Go 擴展功能。


立即使用 JumpCloud SaaS 管理工具

現有的 JumpCloud 客戶和 MSP 合作夥伴現在即可開始使用 JumpCloud SaaS 管理功能,無需額外費用,並且可以獲得 Platform Prime 的更多功能。

如果您是 JumpCloud 的新用戶,請註冊免費試用,親身體驗 JumpCloud SaaS 管理工具的優勢。

 

關於 JumpCloud

JumpCloud® 提供一個統一的開放式目錄平台,使 IT 團隊和 MSP 能夠輕鬆、安全地管理公司企業中的身份、裝置和存取權限。通過 JumpCloud,用戶能夠從任何地方安全工作,並在單一平台上管理其 Windows、Apple、Linux 和 Android 裝置。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

JumpCloud 推出「流動裝置信任」功能 提升員工生產力並保障安全

JumpCloud Inc. 正式宣布推出「流動裝置信任」(Mobile Device Trust)功能。透過此功能,JumpCloud 的客戶現在可以限制使用者僅能透過安全的企業擁有裝置(COD)和個人自帶裝置(BYOD)存取公司資源。這項功能不僅提升了公企業的安全防護,也提高了使用者的工作效率。

JumpCloud 產品總監 Khanh Tran 表示:「我們很高興能夠推出許多客戶期待的流動裝置信任功能。企業需要確保員工隨時隨地安全地存取敏感資源,而 IT 管理員則希望擁有能靈活管理企業擁有裝置的工具。同時,終端用戶也需要簡單易用、無干擾的流動體驗。JumpCloud 的流動裝置信任功能滿足了這些需求,秉持我們提供安全、便捷存取的承諾。」

未受管理的流動裝置是企業安全的主要漏洞之一。流動裝置信任功能利用 JumpCloud GoTM 提供抗釣魚憑證,加強了流動裝置的安全性。用戶可在 Apple MDM 或 Android EMM 註冊的裝置上安裝 JumpCloud ProtectTM 應用,透過 JumpCloud Go 註冊裝置,並建立信任關係。該功能還透過取消密碼需求,改善用戶體驗,提升企業安全性,同時不影響員工的工作效率。

主要功能與優勢包括:

  • 裝置管理條件:這些預設政策確保 JumpCloud 可以管理裝置並驗證其可信度。IT 管理員可以強制執行密碼規範,並在裝置遺失、被盜或員工離職時移除公司資料或取消存取權限
  • 作業系統限制:允許 IT 管理員根據經批准的作業系統限制裝置的資源存取
  • 磁碟加密增強:確保裝置具備所需的磁碟加密(基於文件或元數據)
  • 裝置證明:保護裝置免受以下威脅:
    ○ 裝置遭破壞後偽報其狀態
    ○ 裝置使用過期的證明信息
    ○ 裝置冒用其他裝置的識別碼
    ○ 提取私鑰供惡意裝置使用
  • 裝置信任儀表板:此儀表板為桌面、iOS 和 Android 裝置的設置提供可見性,讓 IT 管理員輕鬆查看企業中設置的策略,並強調運用裝置管理條件的條件式存取策略。

流動裝置信任功能現已向所有 Platform Prime 客戶開放。對於希望從單一平台管理 Android 和 iOS / iPadOS 裝置的企業,現在可以向 Version 2 申請免費演示。

關於 JumpCloud

JumpCloud® 提供一個統一的開放式目錄平台,使 IT 團隊和 MSP 能夠輕鬆、安全地管理公司企業中的身份、裝置和存取權限。通過 JumpCloud,用戶能夠從任何地方安全工作,並在單一平台上管理其 Windows、Apple、Linux 和 Android 裝置。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

JumpCloud 秋季 G2 評分 展示卓越的 IT 簡化能力

JumpCloud 在 G2 秋季 2024 Grid® 報告中,榮獲 98 個領導者位置,這一成就源於來自超過 2,700 位 G2 驗證用戶的評價。G2 的季度 Grid 報告根據用戶評價、網上資源及社交網絡數據對產品進行排名。產品必須獲得用戶的高度評價和強大的市場存在感才能獲得領導者徽章。

JumpCloud 在以下九大類別中強化了其領導者地位: 

  • 雲端目錄服務
  • 身份與存取管理 (IAM)
  • 流動裝置管理 (MDM)
  • 特權訪問管理 (PAM)
  • 密碼政策執行
  • 遙距支援
  • 單一登入 (SSO)
  • 統一端點管理 (UEM)
  • 用戶配置與管理工具

JumpCloud 同時在 G2 的可用性、實施簡便性、客戶關係及成果指數報告中榮登榜首。

JumpCloud 巿場推廣總監 Micha Hershman 表示:「獲得近 100 個 Grid 報告中的領導者徽章,對我們來說不只是數字,這反映了超過 2,700 位用戶認同 JumpCloud 在簡化 IT 管理上的能力。我們在 G2 排名中的持續領先,證明了我們致力於成為身份與裝置管理行業領導者的使命。」

G2 用戶評論摘錄:

「我最欣賞 JumpCloud 的地方在於,它可以與各種系統和應用程式無縫整合,使我們的用戶管理變得非常輕鬆。它的靈活性和安全性令人驚嘆,且優質的支援服務讓我們在使用這個平台時充滿信心。」—— G2 用戶 Juan D.

「JumpCloud 是一個出色的平台,作為身份與存取管理工具,它讓跨系統和應用程式的用戶身份驗證和授權變得簡單。它支援多種平台與操作系統,如 Windows、MacOS 和 Linux,這對於混合環境特別有用,同時保證了安全性和合規性,多重身份驗證及基於群組的安全策略也得到了完善的支援。它的可擴展性非常出色,能隨著企業成長進行調整。」—— G2 用戶 Alex R.

「JumpCloud 是現代 IT 基礎設施的全面解決方案。作為一家網絡安全 SaaS 公司的信息安全經理,我親身體驗了 JumpCloud 帶來的眾多好處。我們使用 JumpCloud 作為 MDM 工具,其設備管理功能首屈一指。通過實施安全策略、監控裝置狀況及遙距操作,我們輕鬆維護了安全且合規的 IT 環境。」—— G2 用戶 Siddhi V.

完整的用戶評論以及數千位其他用戶的評價可在 G2 上查看。

關於 JumpCloud

JumpCloud® 提供一個統一的開放式目錄平台,使 IT 團隊和 MSP 能夠輕鬆、安全地管理公司企業中的身份、裝置和存取權限。通過 JumpCloud,用戶能夠從任何地方安全工作,並在單一平台上管理其 Windows、Apple、Linux 和 Android 裝置。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What is Active Directory Integration (ADI)?

Active Directory (AD) was introduced two decades ago to provide centralized user and rights management as well as Windows PC configurations for private networks behind firewalls. Email was the first factor to upend that model for access control, and was followed by the proliferation of cloud services and devices that transformed networks into a digital estate.

The perimeter model that AD supported worked well, until it didn’t. Its shortcomings helped lay the groundwork for the Zero Trust approach to identity and access management (IAM). Zero Trust brings access control (the perimeter) closer to identities and devices by enforcing explicit trust before granting access to resources.

JumpCloud’s open directory platform makes it possible to modernize AD for Zero Trust. It works by combining cloud IAM with universal endpoint management (UEM) and other essential services to manage today’s IT infrastructures, which are a hybrid of everything, everywhere. JumpCloud’s Active Directory Integration (ADI) feature integrates AD with the open directory.

ADI makes it possible for multi-domain environments to extend AD environments to the cloud without locking small to medium-sized enterprises (SMEs) into a suite of vertically integrated tools. That approach to AD modernization can limit freedom of choice and distract from your overall mission by making IT management significantly more difficult. This article provides an overview of what ADI is and how it works to help SMEs reestablish the strong access control that was lost when AD’s network perimeter model failed to meet today’s IT infrastructure needs.

Note: JumpCloud helps you follow Microsoft’s Zero Trust Rapid Modernization Plan (RaMP) for a privileged access strategy to secure AD.

AD Integration Deployment Models

AD integration

ADI continuously syncs users, groups, and passwords between AD and JumpCloud. Its components are installed on a member server and configured to import and sync identities for each domain. It provides several options for authentication flows: bi-directional syncing and one-way syncing (in either direction). Pass-through authentication back to AD is supported to uphold security and compliance requirements for local authentication and authorization.

Note: Microsoft’s Entra ID cloud directory will not synchronize groups unless the subscription is a Premium SKU.

Bi-Directional Synchronization

JumpCloud Architecture

Bi-directionality means that password changes that occur on the integrated platform get synchronized and changed in AD. This makes it possible for friction-free user access with single-sign on (SSO). It also enables advanced identity lifecycle management. For example, you can use JumpCloud to sync human resources systems with JumpCloud and back to AD.

AD integrations are often one-way, where AD is the source of truth and a third-party application or IT resource authenticates user access against AD. Resources such as web applications require SSO in order to meet modern security and usability requirements. A cloud directory provides SSO with the added benefit of multi-factor authentication (MFA) and conditional access to enable a Zero Trust security strategy that “assumes breach” and verifies requests.

This approach modernizes AD to extend access control to every device and resource without requiring admins to perform consolidation, migration, or deep integrations with multiple point solutions. Admins can manage users, groups, and access in either AD or JumpCloud.

There’s also an available migration path to JumpCloud, if and when it makes sense to leave AD.

Note: Microsoft requires its customers that modernize AD using Entra ID to purchase premium subscriptions for password write-back.

Pass-Through Authentication

synchronization

Some sectors are required to retain oversight of their credential store for certainty and compliance. JumpCloud’s open directory can federate authentication AD through ADI, which extends AD to other resources and devices without running afoul of those rules.

Note: Outbound authentication flows from AD to JumpCloud enable AD users to access cloud resources and non-Windows devices.

Modernizing AD with JumpCloud

JumpCloud is modern, user-friendly, and makes it possible for admins to manage SSO and UEM from a single console with minimal effort. It also extends SSO to common network protocols, adding convenience, while reducing the risk of unauthorized access to infrastructure. A Zero Trust IAM strategy complements your existing investment in network perimeter security.

A crucial part of reestablishing access control over your digital estate comes from the ability to integrate AD with non-Windows systems.

modernize AD flow chart

Universal Endpoint Management

JumpCloud’s UEM adds the ability to integrate Android, macOS, and Linux devices into Active Directory-controlled environments with mobile device management (MDM) support for Windows. Untrusted endpoints can become a weak link in a Zero Trust strategy; UEM ensures that there’s a baseline of policies and patch management (optional) to reduce your attack surface.

End users don’t have to jump through hoops to stay compliant with password policies, password resets, and other critical functions. And, they can do this from anywhere — with no VPN. Built-in remote assist is available to support your users with both attended and unattended sessions.

Note:

Agents provide telemetry and reporting on device and user activity.

SSO and Modern Authentication 

ADI synced identities connect through SSO to networking infrastructure with RADIUS, cloud infrastructure and web apps with OIDC and SAML, file servers on-prem and in the cloud, legacy applications via LDAP, and more by using JumpCloud’s RESTful API.

Note:

JumpCloud offers an integrated password manager for when SSO isn’t possible.

The platform also includes JumpCloud Go™, a hardware-protected and phishing-resistant passwordless login for JumpCloud managed devices. It provides modern authentication that’s more secure and simpler and safer for your users. JumpCloud Go is supported on MacOS and Windows and integrates with device biometric authenticators (Apple Touch ID or Windows Hello) to satisfy traditional password sign-in challenges. It will provide high MFA authenticator assurance.

JumpCloud Go
Modern authentication helps to harden AD against the latest security threats.

Adopting SSO and UEM is recommended for all organizations that use AD, per Microsoft’s Cybersecurity Reference Architectures (MCRA). JumpCloud provides SMEs with an alternative to Microsoft’s prescribed path by keeping your identity provider (IdP) and IT stack independent. JumpCloud has essential IAM, UEM, and system management capabilities in a single place.

Try JumpCloud ADI

Still wondering what Active Directory Integration is and how it can modernize AD? See for yourself when you sign up for a free trial of JumpCloud. It’s included with the open directory platform at no additional charge. JumpCloud has professional service options to assist with onboarding users. JumpCloud is also a Google partner and integrates with Google Workspace, making both services better together with a modern IT management and productivity package.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About JumpCloud
At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.

How to Secure Your Rocky Linux Server

Securing your Rocky Linux server is of paramount importance in today’s digital landscape, where cyber threats and attacks are becoming increasingly sophisticated. 

Whether you are running a blog or hosting critical business applications, ensuring the security of your server is essential to protect sensitive data, maintain privacy, and prevent unauthorized access.

Servers often store valuable information that could be detrimental if compromised, including personal information, financial records, or confidential business data. A security breach can lead to data theft, identity theft, financial losses, and reputational damage for both individuals and organizations.

Securing Rocky Linux is also essential for ensuring the smooth and uninterrupted functioning of critical applications and services. A compromised server may experience downtime, leading to disruptions in services, loss of productivity, and customer dissatisfaction. By implementing robust security measures, server administrators can decrease the risk of downtime and maintain a reliable and secure environment for their users.

Next, a compromised server can be utilized for malicious purposes for further attacks, such as distributed denial-of-service (DDoS) attacks or spreading malware to other connected systems and acting as bot machines centrally managed by bad actors. By securing Rocky Linux, administrators not only protect their own infrastructure but also contribute to overall internet safety by preventing the server from being exploited in cybercriminal activities.

In this tutorial, we will walk you through the best practices and essential security steps to secure your Rocky Linux server.

We must note that the steps covered here are not exhaustive, and you should always stay updated with the latest security recommendations and patches to maintain a robust security posture. 

Step 1: Log in to your Rocky Linux server via SSH

For this step, you need to make sure that you have a terminal or SSH (Secure Shell) client installed on your local machine. If you’re using Linux or macOS, you can use the built-in terminal application. For Windows users, you will most likely use the PuTTY SSH client.

Open the terminal and type the following command replacing username and server_ip_address with your own.

ssh username@server_ip_address

After you enter your password you will be logged into to your server.

tutorial screenshot

Step 2: Update the server packages and set automatic security updates

It is very important to keep your server up to date, especially since there are often security updates that minimize the risk of breach or potential system crash.

We have the option to manually update packages in Rocky Linux and that allows you to carefully review and test updates before applying them to your system, ensuring compatibility and stability. Also, it is always a good idea to update your system manually when you boot a new server that you will use.

In order to check available updates on your system, you can run the following command:

sudo dnf check-update

You will get a similar output:

tutorial screenshot

If you are on a new system, you can proceed with updating all listed packages by running the following command:

sudo dnf update

tutorial screenshot

Press y and hit Enter to continue.

This process will download all the necessary packages from the designated repositories, upgrade to new versions, remove old packages, and perform cleanup for the package cache.

tutorial screenshot

If you have a system where you already have various packages installed, specific versions that could potentially have issues if upgraded to the latest version, or that may conflict with your other packages, the better solution is to perform the minimal upgrade by running the following command:

sudo dnf upgrade-minimal

You can use this command only if you want to perform updates for packages that have essential bug fixes and various security patches, without the risk of breaking changes.

Next, we can enable automatic updates and use the special package designed to automate the installation of security patches and other crucial upgrades for your Rocky Linux server. 

To set up the automatic update process, we need to install the dnf-automatic package which is not available by default on your Rocky Linux server. 

This command requires higher permissions so make sure you execute it with your sudo or root user:

sudo dnf install dnf-automatic

tutorial screenshot

Once the installation is complete, we need to edit the config file related to it:

sudo vi /etc/dnf/automatic.conf

In your configuration file under /etc/dnf/automatic.conf, find the line that starts with upgrade_type, and press the i key in order to enter the edit mode in your Vi editor and replace the value from default to security.

tutorial screenshot

Since it is recommended to modify the default behavior to only include security upgrades, this will ensure automatic updates will not introduce breaking changes for your packages.

In order to write the changes and exit the file using Vi, press Shift and : then type wq and press Enter. 

Finally, we need to make sure that dnf-automatic service is enabled by default the next time we start or reboot our system. 

We can do that by running the following command:

sudo systemctl enable dnf-automatic-install.timer

tutorial screenshot

The dnf-automatic-install.timer is a systemd timer unit that runs our dnf-automatic-install service. By default, it is scheduled to activate every day at 6 a.m., with a randomized delay of up to one hour.

Step 3: Add sudo users

When you boot the system for the first time, by default the root user has full control and unrestricted access to all system resources. Running daily tasks with the root user is not ideal as there is a high probability that any mistake or malicious command executed by the root user can have drastic consequences for your system. In order to minimize these risks, the concept of sudo users was introduced which gives more granular control over access potential actions that a user can run on Linux servers.

You can start by adding a new user to your Rocky Linux server:

adduser jumpcloud

Next, we will run the command so we can create a strong password for our newly created user:

passwd jumpcloud

After that, you can make sure that your user exists and has its own group if you run the id command:

id jumpcloud

You can see a similar output:

tutorial screenshot

The next step consists of elevating the permissions of our jumpcloud user so it can execute sudo commands.

sudo usermod -aG wheel jumpcloud

In this case, the user “jumpcloud” will be added to the “wheel” group, providing it administrative privileges on the system.

If you’d like more details on creating sudo users and managing sudo access on Rocky Linux, check out the following tutorial: How to Create Sudo Users for Rocky Linux.

Step 4: Secure SSH 

SSH (Secure Shell) provides remote access to your server and is often targeted by attackers. To enhance SSH security we can implement certain security measures.

First, we can change the default port for our SSH server by changing the config file related to it.

We advise you to create a backup of your configuration file if it gets corrupted, so you can run the following command:

sudo cp /etc/ssh/sshd_config /etc/ssh/sshd_config_backup

Next, we will edit the configuration file.

sudo vi /etc/ssh/sshd_config

SSH typically operates on the well-known port 22, making it a prime target for attackers, mainly due to the rise of highly automated attacks in recent times. To enhance security, consider changing the default SSH port. This simple step adds an extra layer of obscurity, making it harder for attackers to find and target your SSH service. By choosing an unused port between 1024 and 65535, you can significantly reduce the number of automated attacks directed at your server.

Alternatively, you could opt to set up a hardened jump box, also known as a jump host. Additional hardening and security can be layered onto the jump box instead of directly opening up ports on your server to the web. 

In our case we will use port 2222, so you can scroll down and find Port 22 line:

tutorial screenshot

Press i for edit, uncomment that line, and instead of 22, replace with 2222.

tutorial screenshot

Press Escape and type :wq to write the changes and exit the file.

Just above the port number configuration, note that changing the SSH port requires updating the SELinux configuration. SELinux, which originates from Red Hat, is enabled by default on Rocky Linux. Its main purpose is to restrict actions that Linux processes and users can perform on the system, as that will minimize the impact of security breaches or unauthorized access. SELinux follows the principle of least privilege, granting processes and users only the essential permissions required for their intended tasks.

However, it is worth noting that the semanage command might not be readily available on Rocky Linux. To verify the necessary dependencies, we can run a check:

yum provides /usr/sbin/semanage

tutorial screenshot

From here we can see that we need to install additional Python libraries, and we can do so by running the following command:

sudo yum install policycoreutils-python-utils

tutorial screenshot

Type y, and hit Enter which will install the package.

Next, you can use this command which tells SELinux that the SSH service is now running on the new port 2222.

sudo semanage port -a -t ssh_port_t -p tcp 2222

Now, we need to add an exception to our firewall so we don’t get a connection refused error.

Rocky Linux uses firewalld, so we can add the rule: 

sudo firewall-cmd –zone=public –add-port=2222/tcp –permanent

Next, we should reload the firewall so it starts using the new rule we added:

firewall-cmd –reload

Now, let’s give our SSH server a restart to implement the updated configuration and initiate SSH logging via port 2222. It’s time to apply the changes and get started with enhanced security.

sudo systemctl restart sshd

Now you can try and log in to your Rocky Linux server by adding the -p option and adding our new port number.

ssh -p 2222 username@server_ip_address

We can use SSH key authorization in order to secure our server further. We will also disable logging with the password in our SSH configuration.

By following this method, the possibility of brute force attacks on passwords is completely eradicated, guaranteeing that only users that possess the matching private keys gain access to the system. 

In case you don’t already have an SSH key pair on your local machine, you can create one.

To start, open a terminal on your local machine and enter the following command:

ssh-keygen -t rsa

This command will ask you to select a location to save the keys and set an optional passphrase for added security. The passphrase is also recommended.

tutorial screenshot

Once you have generated your SSH key pair, you need to copy the public key to your Rocky Linux server. You can use the ssh-copy-id command to do this. 

In our case we will run the following command:

ssh-copy-id -p 2222 -i ~/.ssh/jumpcloud_rockylinux.pub jumpcloud@194.195.240.58

You will get a similar output:

tutorial screenshot

Next, this command will prompt you to enter your user password on the remote server. Once you provide the password, the public key will be copied to the ~/.ssh/authorized_keys file on the server.

Before we can log into the server, we need to change the permissions to our key file and assign them permissions with the value 400. 

We can do so by running the following command in our local terminal:

chmod 400 ~/.ssh/jumpcloud_rockylinux

Next, we will connect with our server:

ssh -i ~/.ssh/jumpcloud_rockylinux -p 2222 jumpcloud@194.195.240.58

This command will load the private key through the specified path on the local machine and also use the custom port that we set.

You should be able to log in without entering a password because the server is now configured to use SSH keys for authentication.

tutorial screenshot

We can disable password logging and use only SSH keys by editing the configuration file again:

sudo vi /etc/ssh/sshd_config

We need to uncomment the part related to the PubkeyAuthentication and set it to yes:

tutorial screenshot

Next, we need to change the PasswordAuthentication to no:

tutorial screenshot

We can also disable SSH logging with the root username:

tutorial screenshot

This will also enhance the security of your SSH, but keep in mind that you need to have at least one sudo user already so you don’t get locked out or become unable to perform higher privilege tasks.

Save the file, and then restart the SSH service so it loads the new configuration.

sudo systemctl restart sshd

With key-based authentication now enforced, the need to enter a password during login should be eliminated. This security enhancement ensures that only users with the appropriate SSH keys can access the server.

Step 5: Install and configure Fail2Ban

Fail2Ban is a very useful tool for protecting your Rocky Linux server from brute force attacks and unauthorized access attempts. By monitoring log files and automatically banning suspicious IP addresses, Fail2Ban adds an extra layer of security to your system. 

Fail2Ban is not included in the default software repositories of Rocky Linux. Nevertheless, you can easily access it through the Enhanced Packages for Enterprise Linux (EPEL) repository, a source for third-party packages on Red Hat and Rocky Linux. If you haven’t yet added the EPEL repository to your system’s package sources, you can easily incorporate the repository using dnf, similar to installing any other package.

sudo dnf install epel-release -y

After this step, we need to install the Fail2Ban service. We can do so by running the following command:

sudo dnf install fail2ban

tutorial screenshot

This will install various dependencies also related to modules that work together with SELinux, Sendmail, or the firewalld service.

Next, we can create a new file called “jail.local” where we will store our custom configuration:

sudo vi /etc/fail2ban/jail.local

Here we can build our custom config where we will override default values:

[DEFAULT]
# here you can overwrite some defaults:
[sshd]
enabled = true
port     = ssh,2222
filter   = sshd
bantime  = 30m
findtime  = 5m
maxretry = 3

We will change the default values from the original jail.conf file.

The bantime parameter defines the duration that an IP address will be banned after multiple failed login attempts. By default, it is set to 10 minutes. We can adjust this value to 30 minutes.

bantime = 30m  

The findtime parameter specifies the time window during which repeated failed login attempts will be counted. The default value is 10 minutes. Setting findtime to more than 10 minutes (600 seconds) can be beneficial in scenarios where you want to be less sensitive to temporary spikes in failed login attempts. For instance, if you have legitimate users who sometimes mistype their passwords, a longer findtime allows them more time to reattempt without getting banned.

On the other hand, setting findtime to less than 10 minutes can make Fail2Ban more responsive to potential attacks. If there’s a rapid and sustained increase in failed login attempts within a short time, a shorter findtime can trigger the ban sooner, reducing the attack surface and blocking the malicious attempts more promptly. 

In our case, we will reduce the time to five minutes.

findtime = 5m

The maxretry parameter defines the number of consecutive failed login attempts allowed before banning an IP address. By default, it is set to 5. We can adjust it so that it is limited to three attempts.

maxretry = 3 

After editing and saving the configuration file, we can enable the service so that it starts every time we boot the system:

sudo systemctl enable fail2ban

tutorial screenshot

We can start the service by running the following command:

sudo systemctl start fail2ban

While we are logged in to our SSH session, we can use another terminal and try to log in with some non-existent username and without an SSH key:

ssh -p 2222 jumpcloud3@194.195.240.58

After three bad attempts, our IP address will be banned temporarily for further login attempts:

tutorial screenshot
tutorial screenshot

For the last attempt, we get the “Connection refused” error, which is clearly the ban action of our service that honors our configuration parameters. 

By default, the log file related to the Fail2Ban service is stored in /var/log/fail2ban.log and we can check the latest Fail2Ban events: 

sudo tail /var/log/fail2ban.log

We can see logged events about our IP address and the exact timestamp when the Fail2Ban service banned our IP address from further attempts. 

tutorial screenshot

The ban applies to subsequent connection attempts from that IP address. For test purposes, if you are still logged into the server from your initial SSH session, it will not be affected by the ban. However, if you log out and try to establish a new SSH connection, the new connection attempt might be blocked by the ban.

Conclusion

In this tutorial we covered multiple ways to enhance the security of your Rocky Linux server, from patch management to user privilege and access management, to securing SSH and event logging. You should also learn how to enable full-disk encryption as well.

If you’re an IT admin or MSP provider managing multiple Linux instances, putting these best practices into place can quickly become an overly time-consuming, manual process. That’s where a truly unified endpoint management solution like JumpCloud can help.

With JumpCloud’s open directory platform in place, you can apply key security configurations and policies to various groups of users and devices all at once, regardless of whether your fleet consists of Linux, macOS, Windows, iOS, or Android systems. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About JumpCloud
At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.