Commit Graph

108 Commits

Author SHA1 Message Date
ac857c91c3 actually run the 2fa script. 2025-07-14 10:31:22 -05:00
a632e7d514 Implement comprehensive two-factor authentication for SSH and web services
- Complete rewrite of secharden-2fa.sh with full 2FA implementation
- SSH 2FA using Google Authenticator with publickey + TOTP authentication
- Cockpit web interface 2FA with custom PAM configuration
- Webmin 2FA support with automatic detection and configuration
- User setup automation with QR codes and backup codes generation
- Gradual rollout support using nullok for phased deployment
- Automatic configuration backup and restore procedures
- Add 2fa-validation.sh security test for comprehensive validation
- Create TSYS-2FA-GUIDE.md with complete implementation documentation
- Add DEVELOPMENT-GUIDELINES.md with coding standards and best practices
- Optimize package installation with single apt-get commands for performance

The 2FA implementation provides enterprise-grade security while maintaining
usability and proper emergency access procedures. Includes comprehensive
testing, documentation, and follows established security best practices.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-14 10:23:07 -05:00
0c736c7295 Enforce HTTPS for all downloads to eliminate security vulnerabilities
- Convert 16 HTTP URLs to HTTPS across 3 critical scripts
- Dell OMSA script: Ubuntu archive and Dell repository URLs now use HTTPS
- Proxmox legacy script: Download URLs converted to secure connections
- SSL stack script: Apache source URLs updated to official archive
- Update documentation to reflect resolved security issues
- Mark HTTPS enforcement as completed in todo lists

This addresses the second critical security concern from the security review,
eliminating man-in-the-middle attack vectors during package downloads.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-14 09:22:32 -05:00
6609d7d9e3 sigh. 2025-07-11 11:52:28 -05:00
0588b2dd60 ifdev for dev boxes, they have less hardened ssh config because vscode remote etc 2025-07-11 11:48:53 -05:00
f399308b2d allow root to login to cockpit 2025-07-10 10:47:21 -05:00
45b53efe11 working on v1.1, secrets management/bootstrap 2025-07-10 10:28:00 -05:00
b0d1ae0a3e . 2025-07-10 10:13:23 -05:00
a2ff47e5d2 . 2025-07-10 10:11:50 -05:00
b5d09e64f0 we want a bit of observability here.. 2025-07-10 10:09:58 -05:00
edc3ca26ad . 2025-07-10 10:06:52 -05:00
a272764d66 . 2025-07-10 10:05:51 -05:00
97b67ea1fc . 2025-07-10 10:04:23 -05:00
a86b2ea09b and agian... sigh 2025-07-10 10:03:12 -05:00
54cfcf669f fixed agian 2025-07-10 10:01:30 -05:00
28c18a2bda . 2025-07-10 10:00:25 -05:00
168456ee7f fixed 2025-07-10 09:59:35 -05:00
d6364eac7a typo 2025-07-10 09:58:28 -05:00
d2100d1146 dont' need vm management in vms.. 2025-07-10 09:56:18 -05:00
5c20f167b2 adding cockpit 2025-07-10 09:48:01 -05:00
3b705a23ba don't install rsyslog on librenms server
fixed some formatting
2025-07-09 11:24:20 -05:00
319cd61ad4 all the instrumentation/diagnostics... 2025-07-07 12:05:26 -05:00
1e458f0fae being able to use growpart is quite nice 2025-07-05 20:49:40 -05:00
0bf88e3d8c More ubuntu fixes 2025-07-05 17:48:41 -05:00
bf4efcdf5a oops 2025-07-02 22:23:16 -05:00
f9f556111b lldpd enablement for librenms mapping goodness 2025-07-02 22:12:01 -05:00
7e5302b5e6 This allows for chattr +i of snmpd.conf on hosts we don't want to put the standard snmpd.conf on 2025-07-02 21:20:47 -05:00
885487fce5 so close... 2025-07-02 21:12:37 -05:00
ba8efdfa0b more ntp fixes 2025-07-02 21:08:39 -05:00
1d14c9c9a2 netboot is the frontend to take the hit, it forwards to pfvsvrpi. 2025-07-02 20:19:19 -05:00
d3e4fb5014 . 2025-07-02 20:18:28 -05:00
001faf76a3 . 2025-07-02 20:08:07 -05:00
52e8ecf779 we don't want to update the ntp config on our stratum1 ntp server 2025-07-02 20:07:36 -05:00
24946292e7 more ntp tweaks 2025-07-02 20:00:10 -05:00
cb10cdf1cc ntp fix now 2025-07-02 19:44:15 -05:00
f2dc2ce29e automation. no prompts! 2025-07-02 18:52:43 -05:00
d1ef7118d5 debian fails... let's see if this fixes it. 2025-07-02 18:47:21 -05:00
160d1b26cc fixed in ubuntu. will test on debian next. 2025-07-02 18:44:46 -05:00
ce5bb0be6f . 2025-07-02 18:43:18 -05:00
ce1bf7d220 i think this is right... 2025-07-02 18:41:58 -05:00
0175a00458 got to handle the other condition... 2025-07-02 18:25:31 -05:00
0f52d19229 remove debugging 2025-07-02 18:21:56 -05:00
0937036155 had inverse logic. fixed. still shouldn't have caused script to error though... hmm... 2025-07-02 18:15:03 -05:00
02a874f713 . 2025-07-02 18:10:47 -05:00
259a4f07b7 got further . hmm... 2025-07-02 18:09:06 -05:00
f06d8b1fe5 ok. i think this is the last of the regressions. 2025-07-02 18:06:26 -05:00
d76613c0dc . 2025-07-02 18:00:01 -05:00
5deaecd79f . 2025-07-02 17:57:44 -05:00
c58c3f116e . 2025-07-02 17:55:56 -05:00
e4e1c66111 . 2025-07-02 17:52:14 -05:00