Coder Social home page Coder Social logo

Comments (6)

joschi avatar joschi commented on July 19, 2024

@mikkolehtisalo Thanks, that's a very good idea!

from documentation.

jalogisch avatar jalogisch commented on July 19, 2024

@mikkolehtisalo first part should be covered with 7e997f4 what is your opinion on this?

from documentation.

mikkolehtisalo avatar mikkolehtisalo commented on July 19, 2024

@jalogisch Some good things there! In any case, many companies and such raise the questions "is X secure", and "how to harden X to achieve compliance Y" as a separate step in the process of approving systems for use. Being able to find and verify all necessary (sometimes even small) details is important.

Also, my thinking is that the documentation is growing. It needs more structure, or it becomes messy. (Mostly separating basic installation from extra configuration, which can vary greatly, but this also goes for some security topics that are strictly not mandatory...)

from documentation.

jalogisch avatar jalogisch commented on July 19, 2024

@mikkolehtisalo i see your points. i personal had started to restructure the documentation a little with this #96

Divide between simple and complex setups is not that easy as we would need to rewrite most parts of the documentation and change the logical structure. But we could add some points to the documentation to have them available.

My idea would be to add:

  • how to setup and use mongo in HA (in short what needs to be done within mongo and what needs to be configured on graylog)
  • how a possible HA setup can look and how this can be secured best by design

But it looks like you @mikkolehtisalo had some insides, what would needed from someone that has not knowledge about the moving parts and how to setup. Can you please suggest in detail what would be needed to fulfill the needs of someone who is looking from a non technical point into the documentation to archive compliance.
If you give us some hints what is needed we can add this step by step to the configuration.

from documentation.

aoyawale avatar aoyawale commented on July 19, 2024

just wanted to share this for apache and nginx TLS config using stronger ciphers https://mozilla.github.io/server-side-tls/ssl-config-generator/

from documentation.

jalogisch avatar jalogisch commented on July 19, 2024

We could never cover a complete security guide as all setups are different and have different needs. In addition MongoDB and Elasticsearch are on a second page - where the later has some fundamental questions to answer before you can decide about the security (OSS Elasticsearch VS Enterprise Elasticsearch).

Will close this and we will/have already in mind to include more information how to secure something PLUS the product will improve in this section.

from documentation.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.