「影子 IT」聽起來像是一部恐怖電影的名字,但它在現實中確實存在,並且通常是由於員工想提升工作效率、表現更好。他們會尋找幫助他們提高生產力的解決方案,但這些解決方案往往是在沒有 IT 部門監控的情況下被採用。現代「影子 IT」主要是由 IT 部門未監管的 SaaS 應用程式組成,這可能導致營運效率低下、成本增長以及安全漏洞的出現。
Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。
Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。
「我最欣賞 JumpCloud 的地方在於,它可以與各種系統和應用程式無縫整合,使我們的用戶管理變得非常輕鬆。它的靈活性和安全性令人驚嘆,且優質的支援服務讓我們在使用這個平台時充滿信心。」—— G2 用戶 Juan D.
「JumpCloud 是一個出色的平台,作為身份與存取管理工具,它讓跨系統和應用程式的用戶身份驗證和授權變得簡單。它支援多種平台與操作系統,如 Windows、MacOS 和 Linux,這對於混合環境特別有用,同時保證了安全性和合規性,多重身份驗證及基於群組的安全策略也得到了完善的支援。它的可擴展性非常出色,能隨著企業成長進行調整。」—— G2 用戶 Alex R.
「JumpCloud 是現代 IT 基礎設施的全面解決方案。作為一家網絡安全 SaaS 公司的信息安全經理,我親身體驗了 JumpCloud 帶來的眾多好處。我們使用 JumpCloud 作為 MDM 工具,其設備管理功能首屈一指。通過實施安全策略、監控裝置狀況及遙距操作,我們輕鬆維護了安全且合規的 IT 環境。」—— G2 用戶 Siddhi V.
Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。
Active Directory (AD) was introduced two decades ago to provide centralized user and rights management as well as Windows PC configurations for private networks behind firewalls. Email was the first factor to upend that model for access control, and was followed by the proliferation of cloud services and devices that transformed networks into a digital estate.
The perimeter model that AD supported worked well, until it didn’t. Its shortcomings helped lay the groundwork for the Zero Trust approach to identity and access management (IAM). Zero Trust brings access control (the perimeter) closer to identities and devices by enforcing explicit trust before granting access to resources.
JumpCloud’s open directory platform makes it possible to modernize AD for Zero Trust. It works by combining cloud IAM with universal endpoint management (UEM) and other essential services to manage today’s IT infrastructures, which are a hybrid of everything, everywhere. JumpCloud’s Active Directory Integration (ADI) feature integrates AD with the open directory.
ADI makes it possible for multi-domain environments to extend AD environments to the cloud without locking small to medium-sized enterprises (SMEs) into a suite of vertically integrated tools. That approach to AD modernization can limit freedom of choice and distract from your overall mission by making IT management significantly more difficult. This article provides an overview of what ADI is and how it works to help SMEs reestablish the strong access control that was lost when AD’s network perimeter model failed to meet today’s IT infrastructure needs.
Note: JumpCloud helps you follow Microsoft’s Zero Trust Rapid Modernization Plan (RaMP) for a privileged access strategy to secure AD.
AD Integration Deployment Models
ADI continuously syncs users, groups, and passwords between AD and JumpCloud. Its components are installed on a member server and configured to import and sync identities for each domain. It provides several options for authentication flows: bi-directional syncing and one-way syncing (in either direction). Pass-through authentication back to AD is supported to uphold security and compliance requirements for local authentication and authorization.
Note: Microsoft’s Entra ID cloud directory will not synchronize groups unless the subscription is a Premium SKU.
Bi-Directional Synchronization
Bi-directionality means that password changes that occur on the integrated platform get synchronized and changed in AD. This makes it possible for friction-free user access with single-sign on (SSO). It also enables advanced identity lifecycle management. For example, you can use JumpCloud to sync human resources systems with JumpCloud and back to AD.
AD integrations are often one-way, where AD is the source of truth and a third-party application or IT resource authenticates user access against AD. Resources such as web applications require SSO in order to meet modern security and usability requirements. A cloud directory provides SSO with the added benefit of multi-factor authentication (MFA) and conditional access to enable a Zero Trust security strategy that “assumes breach” and verifies requests.
This approach modernizes AD to extend access control to every device and resource without requiring admins to perform consolidation, migration, or deep integrations with multiple point solutions. Admins can manage users, groups, and access in either AD or JumpCloud.
There’s also an available migration path to JumpCloud, if and when it makes sense to leave AD.
Note: Microsoft requires its customers that modernize AD using Entra ID to purchase premium subscriptions for password write-back.
Pass-Through Authentication
Some sectors are required to retain oversight of their credential store for certainty and compliance. JumpCloud’s open directory can federate authentication AD through ADI, which extends AD to other resources and devices without running afoul of those rules.
Note: Outbound authentication flows from AD to JumpCloud enable AD users to access cloud resources and non-Windows devices.
Modernizing AD with JumpCloud
JumpCloud is modern, user-friendly, and makes it possible for admins to manage SSO and UEM from a single console with minimal effort. It also extends SSO to common network protocols, adding convenience, while reducing the risk of unauthorized access to infrastructure. A Zero Trust IAM strategy complements your existing investment in network perimeter security.
A crucial part of reestablishing access control over your digital estate comes from the ability to integrate AD with non-Windows systems.
Universal Endpoint Management
JumpCloud’s UEM adds the ability to integrate Android, macOS, and Linux devices into Active Directory-controlled environments with mobile device management (MDM) support for Windows. Untrusted endpoints can become a weak link in a Zero Trust strategy; UEM ensures that there’s a baseline of policies and patch management (optional) to reduce your attack surface.
End users don’t have to jump through hoops to stay compliant with password policies, password resets, and other critical functions. And, they can do this from anywhere — with no VPN. Built-in remote assist is available to support your users with both attended and unattended sessions.
ADI synced identities connect through SSO to networking infrastructure with RADIUS, cloud infrastructure and web apps with OIDC and SAML, file servers on-prem and in the cloud, legacy applications via LDAP, and more by using JumpCloud’s RESTful API.
Note:
JumpCloud offers an integrated password manager for when SSO isn’t possible.
The platform also includes JumpCloud Go™, a hardware-protected and phishing-resistant passwordless login for JumpCloud managed devices. It provides modern authentication that’s more secure and simpler and safer for your users. JumpCloud Go is supported on MacOS and Windows and integrates with device biometric authenticators (Apple Touch ID or Windows Hello) to satisfy traditional password sign-in challenges. It will provide high MFA authenticator assurance.
Modern authentication helps to harden AD against the latest security threats.
Adopting SSO and UEM is recommended for all organizations that use AD, per Microsoft’s Cybersecurity Reference Architectures (MCRA). JumpCloud provides SMEs with an alternative to Microsoft’s prescribed path by keeping your identity provider (IdP) and IT stack independent. JumpCloud has essential IAM, UEM, and system management capabilities in a single place.
Try JumpCloud ADI
Still wondering what Active Directory Integration is and how it can modernize AD? See for yourself when you sign up for a free trial of JumpCloud. It’s included with the open directory platform at no additional charge. JumpCloud has professional service options to assist with onboarding users. JumpCloud is also a Google partner and integrates with Google Workspace, making both services better together with a modern IT management and productivity package.
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.
Securing your Rocky Linux server is of paramount importance in today’s digital landscape, where cyber threats and attacks are becoming increasingly sophisticated.
Whether you are running a blog or hosting critical business applications, ensuring the security of your server is essential to protect sensitive data, maintain privacy, and prevent unauthorized access.
Servers often store valuable information that could be detrimental if compromised, including personal information, financial records, or confidential business data. A security breach can lead to data theft, identity theft, financial losses, and reputational damage for both individuals and organizations.
Securing Rocky Linux is also essential for ensuring the smooth and uninterrupted functioning of critical applications and services. A compromised server may experience downtime, leading to disruptions in services, loss of productivity, and customer dissatisfaction. By implementing robust security measures, server administrators can decrease the risk of downtime and maintain a reliable and secure environment for their users.
Next, a compromised server can be utilized for malicious purposes for further attacks, such as distributed denial-of-service (DDoS) attacks or spreading malware to other connected systems and acting as bot machines centrally managed by bad actors. By securing Rocky Linux, administrators not only protect their own infrastructure but also contribute to overall internet safety by preventing the server from being exploited in cybercriminal activities.
In this tutorial, we will walk you through the best practices and essential security steps to secure your Rocky Linux server.
We must note that the steps covered here are not exhaustive, and you should always stay updated with the latest security recommendations and patches to maintain a robust security posture.
Step 1: Log in to your Rocky Linux server via SSH
For this step, you need to make sure that you have a terminal or SSH (Secure Shell) client installed on your local machine. If you’re using Linux or macOS, you can use the built-in terminal application. For Windows users, you will most likely use the PuTTY SSH client.
Open the terminal and type the following command replacing username and server_ip_address with your own.
ssh username@server_ip_address
After you enter your password you will be logged into to your server.
Step 2: Update the server packages and set automatic security updates
It is very important to keep your server up to date, especially since there are often security updates that minimize the risk of breach or potential system crash.
We have the option to manually update packages in Rocky Linux and that allows you to carefully review and test updates before applying them to your system, ensuring compatibility and stability. Also, it is always a good idea to update your system manually when you boot a new server that you will use.
In order to check available updates on your system, you can run the following command:
sudo dnf check-update
You will get a similar output:
If you are on a new system, you can proceed with updating all listed packages by running the following command:
sudo dnf update
Press y and hit Enter to continue.
This process will download all the necessary packages from the designated repositories, upgrade to new versions, remove old packages, and perform cleanup for the package cache.
If you have a system where you already have various packages installed, specific versions that could potentially have issues if upgraded to the latest version, or that may conflict with your other packages, the better solution is to perform the minimal upgrade by running the following command:
sudo dnf upgrade-minimal
You can use this command only if you want to perform updates for packages that have essential bug fixes and various security patches, without the risk of breaking changes.
Next, we can enable automatic updates and use the special package designed to automate the installation of security patches and other crucial upgrades for your Rocky Linux server.
To set up the automatic update process, we need to install the dnf-automatic package which is not available by default on your Rocky Linux server.
This command requires higher permissions so make sure you execute it with your sudo or root user:
sudo dnf install dnf-automatic
Once the installation is complete, we need to edit the config file related to it:
sudo vi /etc/dnf/automatic.conf
In your configuration file under /etc/dnf/automatic.conf, find the line that starts with upgrade_type, and press the i key in order to enter the edit mode in your Vi editor and replace the value from default to security.
Since it is recommended to modify the default behavior to only include security upgrades, this will ensure automatic updates will not introduce breaking changes for your packages.
In order to write the changes and exit the file using Vi, press Shift and : then type wq and press Enter.
Finally, we need to make sure that dnf-automatic service is enabled by default the next time we start or reboot our system.
We can do that by running the following command:
sudo systemctl enable dnf-automatic-install.timer
The dnf-automatic-install.timer is a systemd timer unit that runs our dnf-automatic-install service. By default, it is scheduled to activate every day at 6 a.m., with a randomized delay of up to one hour.
Step 3: Add sudo users
When you boot the system for the first time, by default the root user has full control and unrestricted access to all system resources. Running daily tasks with the root user is not ideal as there is a high probability that any mistake or malicious command executed by the root user can have drastic consequences for your system. In order to minimize these risks, the concept of sudo users was introduced which gives more granular control over access potential actions that a user can run on Linux servers.
You can start by adding a new user to your Rocky Linux server:
adduser jumpcloud
Next, we will run the command so we can create a strong password for our newly created user:
passwd jumpcloud
After that, you can make sure that your user exists and has its own group if you run the id command:
id jumpcloud
You can see a similar output:
The next step consists of elevating the permissions of our jumpcloud user so it can execute sudo commands.
sudo usermod -aG wheel jumpcloud
In this case, the user “jumpcloud” will be added to the “wheel” group, providing it administrative privileges on the system.
If you’d like more details on creating sudo users and managing sudo access on Rocky Linux, check out the following tutorial: How to Create Sudo Users for Rocky Linux.
Step 4: Secure SSH
SSH (Secure Shell) provides remote access to your server and is often targeted by attackers. To enhance SSH security we can implement certain security measures.
First, we can change the default port for our SSH server by changing the config file related to it.
We advise you to create a backup of your configuration file if it gets corrupted, so you can run the following command:
SSH typically operates on the well-known port 22, making it a prime target for attackers, mainly due to the rise of highly automated attacks in recent times. To enhance security, consider changing the default SSH port. This simple step adds an extra layer of obscurity, making it harder for attackers to find and target your SSH service. By choosing an unused port between 1024 and 65535, you can significantly reduce the number of automated attacks directed at your server.
Alternatively, you could opt to set up a hardened jump box, also known as a jump host. Additional hardening and security can be layered onto the jump box instead of directly opening up ports on your server to the web.
In our case we will use port 2222, so you can scroll down and find Port 22 line:
Press i for edit, uncomment that line, and instead of 22, replace with 2222.
Press Escape and type :wq to write the changes and exit the file.
Just above the port number configuration, note that changing the SSH port requires updating the SELinux configuration. SELinux, which originates from Red Hat, is enabled by default on Rocky Linux. Its main purpose is to restrict actions that Linux processes and users can perform on the system, as that will minimize the impact of security breaches or unauthorized access. SELinux follows the principle of least privilege, granting processes and users only the essential permissions required for their intended tasks.
However, it is worth noting that the semanage command might not be readily available on Rocky Linux. To verify the necessary dependencies, we can run a check:
yum provides /usr/sbin/semanage
From here we can see that we need to install additional Python libraries, and we can do so by running the following command:
sudo yum install policycoreutils-python-utils
Type y, and hit Enter which will install the package.
Next, you can use this command which tells SELinux that the SSH service is now running on the new port 2222.
sudo semanage port -a -t ssh_port_t -p tcp 2222
Now, we need to add an exception to our firewall so we don’t get a connection refused error.
Rocky Linux uses firewalld, so we can add the rule:
Next, we should reload the firewall so it starts using the new rule we added:
firewall-cmd –reload
Now, let’s give our SSH server a restart to implement the updated configuration and initiate SSH logging via port 2222. It’s time to apply the changes and get started with enhanced security.
sudo systemctl restart sshd
Now you can try and log in to your Rocky Linux server by adding the -p option and adding our new port number.
ssh -p 2222 username@server_ip_address
We can use SSH key authorization in order to secure our server further. We will also disable logging with the password in our SSH configuration.
By following this method, the possibility of brute force attacks on passwords is completely eradicated, guaranteeing that only users that possess the matching private keys gain access to the system.
In case you don’t already have an SSH key pair on your local machine, you can create one.
To start, open a terminal on your local machine and enter the following command:
ssh-keygen -t rsa
This command will ask you to select a location to save the keys and set an optional passphrase for added security. The passphrase is also recommended.
Once you have generated your SSH key pair, you need to copy the public key to your Rocky Linux server. You can use the ssh-copy-id command to do this.
Next, this command will prompt you to enter your user password on the remote server. Once you provide the password, the public key will be copied to the ~/.ssh/authorized_keys file on the server.
Before we can log into the server, we need to change the permissions to our key file and assign them permissions with the value 400.
We can do so by running the following command in our local terminal:
This command will load the private key through the specified path on the local machine and also use the custom port that we set.
You should be able to log in without entering a password because the server is now configured to use SSH keys for authentication.
We can disable password logging and use only SSH keys by editing the configuration file again:
sudo vi /etc/ssh/sshd_config
We need to uncomment the part related to the PubkeyAuthentication and set it to yes:
Next, we need to change the PasswordAuthentication to no:
We can also disable SSH logging with the root username:
This will also enhance the security of your SSH, but keep in mind that you need to have at least one sudo user already so you don’t get locked out or become unable to perform higher privilege tasks.
Save the file, and then restart the SSH service so it loads the new configuration.
sudo systemctl restart sshd
With key-based authentication now enforced, the need to enter a password during login should be eliminated. This security enhancement ensures that only users with the appropriate SSH keys can access the server.
Step 5: Install and configure Fail2Ban
Fail2Ban is a very useful tool for protecting your Rocky Linux server from brute force attacks and unauthorized access attempts. By monitoring log files and automatically banning suspicious IP addresses, Fail2Ban adds an extra layer of security to your system.
Fail2Ban is not included in the default software repositories of Rocky Linux. Nevertheless, you can easily access it through the Enhanced Packages for Enterprise Linux (EPEL) repository, a source for third-party packages on Red Hat and Rocky Linux. If you haven’t yet added the EPEL repository to your system’s package sources, you can easily incorporate the repository using dnf, similar to installing any other package.
sudo dnf install epel-release -y
After this step, we need to install the Fail2Ban service. We can do so by running the following command:
sudo dnf install fail2ban
This will install various dependencies also related to modules that work together with SELinux, Sendmail, or the firewalld service.
Next, we can create a new file called “jail.local” where we will store our custom configuration:
sudo vi /etc/fail2ban/jail.local
Here we can build our custom config where we will override default values:
[DEFAULT] # here you can overwrite some defaults: [sshd] enabled = true port = ssh,2222 filter = sshd bantime = 30m findtime = 5m maxretry = 3
We will change the default values from the original jail.conf file.
The bantime parameter defines the duration that an IP address will be banned after multiple failed login attempts. By default, it is set to 10 minutes. We can adjust this value to 30 minutes.
bantime = 30m
The findtime parameter specifies the time window during which repeated failed login attempts will be counted. The default value is 10 minutes. Setting findtime to more than 10 minutes (600 seconds) can be beneficial in scenarios where you want to be less sensitive to temporary spikes in failed login attempts. For instance, if you have legitimate users who sometimes mistype their passwords, a longer findtime allows them more time to reattempt without getting banned.
On the other hand, setting findtime to less than 10 minutes can make Fail2Ban more responsive to potential attacks. If there’s a rapid and sustained increase in failed login attempts within a short time, a shorter findtime can trigger the ban sooner, reducing the attack surface and blocking the malicious attempts more promptly.
In our case, we will reduce the time to five minutes.
findtime = 5m
The maxretry parameter defines the number of consecutive failed login attempts allowed before banning an IP address. By default, it is set to 5. We can adjust it so that it is limited to three attempts.
maxretry = 3
After editing and saving the configuration file, we can enable the service so that it starts every time we boot the system:
sudo systemctl enable fail2ban
We can start the service by running the following command:
sudo systemctl start fail2ban
While we are logged in to our SSH session, we can use another terminal and try to log in with some non-existent username and without an SSH key:
ssh -p 2222 jumpcloud3@194.195.240.58
After three bad attempts, our IP address will be banned temporarily for further login attempts:
For the last attempt, we get the “Connection refused” error, which is clearly the ban action of our service that honors our configuration parameters.
By default, the log file related to the Fail2Ban service is stored in /var/log/fail2ban.log and we can check the latest Fail2Ban events:
sudo tail /var/log/fail2ban.log
We can see logged events about our IP address and the exact timestamp when the Fail2Ban service banned our IP address from further attempts.
The ban applies to subsequent connection attempts from that IP address. For test purposes, if you are still logged into the server from your initial SSH session, it will not be affected by the ban. However, if you log out and try to establish a new SSH connection, the new connection attempt might be blocked by the ban.
Conclusion
In this tutorial we covered multiple ways to enhance the security of your Rocky Linux server, from patch management to user privilege and access management, to securing SSH and event logging. You should also learn how to enable full-disk encryption as well.
If you’re an IT admin or MSP provider managing multiple Linux instances, putting these best practices into place can quickly become an overly time-consuming, manual process. That’s where a truly unified endpoint management solution like JumpCloud can help.
With JumpCloud’s open directory platform in place, you can apply key security configurations and policies to various groups of users and devices all at once, regardless of whether your fleet consists of Linux, macOS, Windows, iOS, or Android systems.
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.