Config Tomcat SSL
<Connector port="8080" protocol="HTTP/1.1"
compression="on"
compressionMinSize="1024"
connectionTimeout="20000"
redirectPort="8443" />
<Connector port="8443" maxHttpHeaderSize="8192"
enableLookups="false" maxThreads="150"
disableUploadTimeout="true" acceptCount="100" scheme="https"
secure="true" SSLEnabled="true" clientAuth="false" protocol="org.apache.coyote.http11.Http11NioProtocol"
sslProtocol="TLS" keystoreFile="<PATH to .jks>"
keystorePass="PASSWORD" />
Hide tomcat info
Open the server.xml file located in the <tomcat directory>/conf.
Enter the following value in the <Host tag:
<Valve className="org.apache.catalina.valves.ErrorReportValve" showReport="false" showServerInfo="false"/>
Create pem certificate
Creating a .pem with the Private Key and Entire Trust Chain
Log into your DigiCert Management Console and download your Intermediate (DigiCertCA.crt) and Primary Certificates (your_domain_name.crt).
Open a text editor (such as wordpad) and paste the entire body of each certificate into one text file in the following order:
The Private Key - your_domain_name.key
The Primary Certificate - your_domain_name.crt
The Intermediate Certificate - DigiCertCA.crt
The Root Certificate - TrustedRoot.crt
Unlock ESXi root account
1. Access ESXi console with remote or direct KVM or ILO
2. Login to ESXi console (F2) with root account (it won't be locked at this level)
3. Navigate to Troubleshooting Options
4. In first line you should see either Disable or Enable ESXi Shell. If its Enable, hit enter once.
5. Then use combination Alt+F1 to switch to ESXi shell
6. Login with root account (it won't be locked at this level)
7. Run following command. This will show number of failed login attempts
pam_tally2 --user root
8. To reset the failures, run following command
pam_tally2 --user root --reset
Now you can access the ESXi with shell and Web UI (vSphere Client).
Run 'pam_tally2 --user root' couple of times to check if there are new failed login attempts.
Install MSIX with powershell
Add-AppxPackage -Path "C:\Users\MyUserName\Downloads\affinity-designer-2.0.0.msix" -DependencyPath "https://aka.ms/Microsoft.VCLibs.x64.14.00.Desktop.appx"
How do I find files that do not contain a given string pattern?
If your grep has the -L (or --files-without-match) option:
$ grep -riL "foo" * -L, --files-without-match
each file processed.
-R, -r, --recursive
Recursively search subdirectories listed.
-i, --ignore-case
Perform case insensitive matching.
If you use l (lowercased) you will get the opposite (files with matches)
-l, --files-with-matches
Only the names of files containing selected lines are written
SSH 2FA
Neste tutorial, exploraremos como configurar a autenticação de dois fatores (2FA) em um servidor Debian Linux usando o aplicativo Microsoft Authenticator. A autenticação de dois fatores é uma camada adicional de segurança que ajuda a proteger suas contas contra acessos não autorizados, exigindo não apenas uma senha, mas também um código gerado por um aplicativo autenticador instalado em um dispositivo móvel.
O Microsoft Authenticator é um aplicativo de autenticação amplamente utilizado e compatível com vários serviços e sistemas. Ao seguir este guia passo a passo, você aprenderá como habilitar o 2FA para usuários em seu servidor Debian Linux e como vincular suas contas ao aplicativo Microsoft Authenticator para garantir uma autenticação segura e protegida.
Para configurar a autenticação de dois fatores (2FA) em um servidor Debian Linux e usar o Microsoft Authenticator como aplicativo de autenticação, siga estas etapas:
Atualize os pacotes e instale os pacotes necessários:
sudo apt update sudo apt upgrade sudo apt install libpam-google-authenticator
Configure o Google Authenticator para cada usuário que deseja habilitar 2FA:
Faça login como o usuário que deseja configurar o 2FA e execute o comando “google-authenticator“. Siga as instruções na tela e anote o código QR, as chaves de recuperação e o código secreto.
google-authenticator
Adicione a conta no aplicativo Microsoft Authenticator:
Abra o aplicativo Microsoft Authenticator em seu dispositivo móvel e siga as etapas para adicionar uma nova conta. Selecione a opção “Outra conta (Google, Facebook, etc.)” e escaneie o código QR ou insira manualmente o código secreto fornecido na etapa anterior.
Configure PAM (Pluggable Authentication Modules) para usar o Google Authenticator:
Edite o arquivo PAM de autenticação SSH. Neste exemplo, usaremos o “nano” como editor de texto, mas você pode usar o editor de sua preferência.
sudo nano /etc/pam.d/sshd
Adicione a seguinte linha ao arquivo, logo abaixo da linha
“@include common-auth:“
auth required pam_google_authenticator.so
Salve e feche o arquivo.
Configure o SSH para solicitar a autenticação 2FA:
Edite o arquivo de configuração do SSH:
sudo nano /etc/ssh/sshd_config
Procure a linha “ChallengeResponseAuthentication”
e altere seu valor para “yes“. Se a linha
estiver comentada (iniciando com um “#“),
remova o comentário. Se a linha não existir, adicione-a ao arquivo:
ChallengeResponseAuthentication yes
Salve e feche o arquivo.
Reinicie o serviço SSH para aplicar as alterações:
sudo systemctl restart ssh
Teste a autenticação 2FA:
Tente fazer login no servidor via SSH. Você deverá ser solicitado a fornecer sua senha e o código de verificação gerado pelo Microsoft Authenticator.
Lembre-se de que a autenticação 2FA agora está habilitada para os usuários configurados e que a perda do dispositivo com o aplicativo Microsoft Authenticator pode bloquear o acesso à conta. Portanto, guarde as chaves de recuperação geradas na etapa 2 em um local seguro.
Source: https://dolutech.com/configurando-a-autenticacao-de-dois-fatores-2fa-em-um-servidor-debian-linux-com-microsoft-authenticator-um-guia-passo-a-passo/
Verify certificates
3. Verify that the Public Keys contained in the Private Key file and the Main/Server Certificate are the same:
openssl x509 -in certificate.pem -noout -pubkey
openssl rsa -in ssl.key -pubout
The output of these two commands should be the same.
4. Check that the Valid From and Valid To dates of the certificate are correct:
openssl x509 -noout -in certificate.pem -dates
Ensure that the current date is between the certificate's Not Before and Not After dates.
5. Check the validity of the Certificate Chain:
openssl verify -CAfile certificate-chain.pem certificate.pem
If the response is OK, the check is valid.
Certificate expire date:
openssl x509 -enddate -noout -in server.crt
https://acquia.my.site.com/s/article/360004119234-Verifying-the-validity-of-an-SSL-certificate
https://forums.openvpn.net/viewtopic.php?t=18671
Remove computer from Azure Arc
To fully remove a computer from Azure Arc-enabled servers, follow the official steps in the Uninstall the Azure Connected Machin...
Mais vistos
-
Find Users Who Have Never Logged On Use the following PowerShell Command; Get-ADUser -Filter { LastLogonDate -notlike "*" -and En...
-
Java Keytool Command These commands allow you to generate a new Java Keytool keystore file, create a CSR, and import certificates. A...
-
First you have to configure a wpad site in your IIS Open the proxypac.pac file you have previously created and save as wpad.dat. Copy wpa...