Security concerns

'User made' tutorials related to Porteus Kiosk edition.
Official kiosk documentation can be find here: http://porteus-kiosk.org/documentation.html
Forum rules
Porteus Kiosk section of the forum is unmaintained now. Its kept in a 'read only' mode for archival purposes.
Please use the kiosk contact page for directing your queries: https://porteus-kiosk.org/contact.html
LKG
Ronin
Ronin
Posts: 1
Joined: 07 Oct 2019, 20:32
Distribution: 4.9.0

Security concerns

Post#1 by LKG » 07 Oct 2019, 20:38

Hi there,

I'm new to Porteus and so far have tested the stand alone client side with great results. I want to move ahead and test the server side (which I have temporarily setup on a PC) but we have staff who have some basic security concerns. Due to current staffing at the moment we're lacking expertise, is there any chance anyone could help address the following concerns?

2. Security concerns with pre-installed package server software involving SSL Tunneling daemon on access to remote server for update.
3. SSH and VNC services enabled by default on test server.

My assumption would be that if the clients are all connecting to the server internally our firewall should be able to manage these concerns.

User avatar
fanthom
Moderator Team
Moderator Team
Posts: 5666
Joined: 28 Dec 2010, 02:42
Distribution: Porteus Kiosk
Location: Poland
Contact:

Security concerns

Post#2 by fanthom » 08 Oct 2019, 07:15

Hello LKG,

1) I must admit i dont understand the first point. Please evaluate on it.

2) Mind that i'm referring to PK Server "Premium" below.

VNC and SSH services are not enabled on PK Server by default (server has only a client utilities which are used when connecting to relevant ssh/vnc services on your kiosks). If you need an admin access to PK Server over SSh and VNC then you need to enable them in the server wizard, configure the port and set the password.

When configuring VNC service on PK Server you can tunnel it over SSH.
SSH access can be restricted by using the PK Server's firewall.

Thanks
Please add [Solved] to your thread title if the solution was found.

Locked