{"id":137,"date":"2017-06-28T04:12:34","date_gmt":"2017-06-28T04:12:34","guid":{"rendered":"http:\/\/lance.conryclan.com\/home\/?p=137"},"modified":"2017-06-28T04:12:34","modified_gmt":"2017-06-28T04:12:34","slug":"securing-allmon-on-vklink-nodes","status":"publish","type":"post","link":"https:\/\/lance.conryclan.com\/home\/securing-allmon-on-vklink-nodes\/","title":{"rendered":"Securing AllMon on VKLink nodes"},"content":{"rendered":"<p>By default the <a href=\"https:\/\/github.com\/lorentedford\/allmon\">AllMon<\/a>\u00a0installation with VKNode is not encrypted. \u00a0What does this mean? \u00a0If you have your AllMon page publicly accessible, you are sending your admin username and password over the internet in plan text, in the open. \u00a0That&#8217;s bad. \u00a0Really bad.<\/p>\n<p>This post will detail the steps required to secure your install so that all communication between your node and browser is encrypted.<\/p>\n<p><a href=\"http:\/\/lance.conryclan.com\/home\/wp-content\/uploads\/2017\/06\/securing-your-belongings-copy-633x4361.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-138\" src=\"http:\/\/lance.conryclan.com\/home\/wp-content\/uploads\/2017\/06\/securing-your-belongings-copy-633x4361.jpg\" alt=\"\" width=\"633\" height=\"436\" srcset=\"https:\/\/lance.conryclan.com\/home\/wp-content\/uploads\/2017\/06\/securing-your-belongings-copy-633x4361.jpg 633w, https:\/\/lance.conryclan.com\/home\/wp-content\/uploads\/2017\/06\/securing-your-belongings-copy-633x4361-300x207.jpg 300w\" sizes=\"auto, (max-width: 633px) 100vw, 633px\" \/><\/a><\/p>\n<p><!--more--><\/p>\n<h2>Generate your SSL certificates<\/h2>\n<p><a href=\"https:\/\/letsencrypt.org\/\">Let&#8217;s Encrypt<\/a>\u00a0is changing the world. \u00a0They offer free certificates with an amazing API that lets you easily automate the process of generation and renewal.<\/p>\n<p>I use the\u00a0<a href=\"https:\/\/github.com\/Neilpang\/acme.sh\">acme.sh<\/a>\u00a0script to generate my keys. \u00a0Have a look at their documentation for how to generate keys in your scenario. \u00a0Because I don&#8217;t use port 80 or 443, I have use challenge TXT DNS records.<\/p>\n<p>To start, install acme.sh.<\/p>\n<pre>curl https:\/\/get.acme.sh &lt;span class=&quot;pl-k&quot;&gt;|&lt;\/span&gt; sh<\/pre>\n<p>Now generate a certificate. \u00a0Your use will no doubt be different. \u00a0Check the <a href=\"https:\/\/github.com\/Neilpang\/acme.sh\/blob\/master\/README.md\">docco<\/a>.<\/p>\n<pre>.acme.sh\/acme.sh --issue --dns dns_dreamhost -d domainname.com<\/pre>\n<p>Your certificates will be created and installed to<\/p>\n<ul>\n<li>.acme.sh\/domainname.com\/domainname.com.key<\/li>\n<li>.acme.sh\/domainname.com\/domainname.com.cer<\/li>\n<\/ul>\n<h2>Installing the certificates<\/h2>\n<p>We now need to concatenate the key and certificate into a single .pem file and install in the lighttpd (the installed http server) config folder.<\/p>\n<pre>sudo cat .acme.sh\/domainname.com\/domainname.com.key .acme.sh\/domainname.com\/domainname.com.cer \/etc\/lighttpd\/domainname.com.pem\r\n<\/pre>\n<p>**At this point you should create a script to generate and install the certificate, and add it as a daily cron job. \u00a0That way when your certificate is close to expiry, it will automatically renew and install. \u00a0If you&#8217;d like an example, I have my script saved to <a href=\"https:\/\/github.com\/RhinoLance\/VKNode\/blob\/dev\/Config\/installCert.sh\">GitHub<\/a>.<\/p>\n<h2>Update lighttpd config<\/h2>\n<p>Add the following lines the the bottom of your \/etc\/lighttpd\/lighttpd.conf<\/p>\n<pre>$SERVER[&quot;socket&quot;] == &quot;:443&quot; {\r\n        ssl.engine = &quot;enable&quot;\r\n        ssl.pemfile = &quot;\/etc\/lighttpd\/domainname.com.pem&quot;\r\n}\r\n<\/pre>\n<p>Restart lighttpd<\/p>\n<pre>sudo \/etc\/init.d\/lighttpd restart\r\n<\/pre>\n<h2>Update AllMon files<\/h2>\n<p>While you can now connect to AllMon with https, it won&#8217;t show as secure as several of the files are hard coded as http. \u00a0 We&#8217;ll need to change them.<\/p>\n<h3>Downloading remote files<\/h3>\n<p>For some inexplicable reason, the background image, logo and style-sheets are hosted on vklink.com.au. \u00a0As that server doesn&#8217;t support https (tut tut), we&#8217;ll need to download them locally.<\/p>\n<pre>cd \/var\/www\r\nsudo mkdir css\r\nsudo mkdir images\r\ncd css\r\nsudo wget http:\/\/vklink.com.au\/css\/allmon.css\r\ncd ..\/images\r\nsudo wget http:\/\/vklink.com.au\/manual\/images\/vklinklogo.png\r\nsudo wget http:\/\/vklink.com.au\/images\/bg.png<\/pre>\n<h3>Change AllMon source files<\/h3>\n<p>We need to update source files to point to the correct files.<\/p>\n<pre>#change for files that are now local\r\nsudo sed -i -e &#039;s\/http:\\\/\\\/vklink\\.com\\.au\\\/\/\/g&#039; \/var\/www\/header.php\r\nsudo sed -i -e &#039;s\/http:\\\/\\\/vklink\\.com\\.au\/..\/g&#039; \/var\/www\/css\/allmon.css\r\n\r\n#change http to https for remote files\r\nsudo sed -i -e &#039;s\/http\/https\/g&#039; \/var\/www\/header.php<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>By default the AllMon\u00a0installation with VKNode is not encrypted. \u00a0What does this mean? \u00a0If you have your AllMon page publicly accessible, you are sending your admin username and password over the internet in plan text, in the open. \u00a0That&#8217;s bad. \u00a0Really bad. This post will detail the steps required to secure your install so that &hellip; <a href=\"https:\/\/lance.conryclan.com\/home\/securing-allmon-on-vklink-nodes\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Securing AllMon on VKLink nodes<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-137","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/posts\/137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/comments?post=137"}],"version-history":[{"count":1,"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/posts\/137\/revisions"}],"predecessor-version":[{"id":139,"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/posts\/137\/revisions\/139"}],"wp:attachment":[{"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/media?parent=137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/categories?post=137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lance.conryclan.com\/home\/wp-json\/wp\/v2\/tags?post=137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}