Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
advisories/hardeningfeb2019 [2019_02_13 12:10] – dan | advisories:hardeningfeb2019 [2024_02_28 01:03] (current) – external edit 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== | + | ====== |
##### First published on February 13, 2019. | ##### First published on February 13, 2019. | ||
- | ##### Last edited on February | + | ##### Last edited on February |
===== Introduction ===== | ===== Introduction ===== | ||
- | Although Storage Made Easy takes extensive measures to ensure that the Enterprise File Fabric | + | |
+ | We take extensive measures to ensure that Access Anywhere | ||
===== Apache HTTPD TLS Settings and Ciphers ===== | ===== Apache HTTPD TLS Settings and Ciphers ===== | ||
- | TLS versions and cipher recommendations change as new threats are discovered. Some scanning tools will flag the availability of older ciphers and protocol versions in the EFF as minor vulnerabilities. | + | TLS versions and cipher recommendations change as new threats are discovered. Some scanning tools will flag the availability of older ciphers and protocol versions in the NAA as minor vulnerabilities. |
- | Should you wish to address those, here is how to update | + | Should you wish to address those, here is how to update |
We recommend that you use [[https:// | We recommend that you use [[https:// | ||
Line 82: | Line 84: | ||
===== Disable CloudFTP ===== | ===== Disable CloudFTP ===== | ||
- | The EFF provides legacy protocol adaptors that allow you to use FTP, FTPS or SFTP to access any storage that is connected to the EFF. These protocols are presented by the EFF's CloudFTP service. | + | The NAA provides legacy protocol adaptors that allow you to use FTP, FTPS or SFTP to access any storage that is connected to the NAA . These protocols are presented by the NAA 's CloudFTP service. |
- | To provide compatibility with a wide range of clients, SFTP and FTPS support many encryption protocols and ciphers including some that are known to be relatively insecure, and the FTP protocol does not support encryption. Unless you have a specific need for FTP, FTPS or SFTP access to your EFF, you may choose to disable CloudFTP service. | + | To provide compatibility with a wide range of clients, SFTP and FTPS support many encryption protocols and ciphers including some that are known to be relatively insecure, and the FTP protocol does not support encryption. Unless you have a specific need for FTP, FTPS or SFTP access to your NAA , you may choose to disable CloudFTP service. |
As root: | As root: | ||
Line 95: | Line 97: | ||
#### (for initial deployments of version 1901 or earlier) | #### (for initial deployments of version 1901 or earlier) | ||
- | The EFF's Apache Web server configuration allows access to a directory containing icons. | + | The NAA 's Apache Web server configuration allows access to a directory containing icons. |
As root remove the following file: | As root remove the following file: |