Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hedgehog Arkime viewer node should use TLS #122

Closed
mmguero opened this issue Oct 20, 2022 · 1 comment
Closed

Hedgehog Arkime viewer node should use TLS #122

mmguero opened this issue Oct 20, 2022 · 1 comment
Assignees
Labels
arkime Relating to Malcolm's use of Arkime security Related to issues with bearing on the security of Malcolm itself sensor For issues dealing with the Hedgehog OS capture sensor

Comments

@mmguero
Copy link
Collaborator

mmguero commented Oct 20, 2022

See the Arkime config documentation. Although we have been using passwordSecret and an IP-based ACL to make sure communication with the hedgehog's arkime instance viewer isn't allowed by unauthorized parties, we should really be using TLS there as well. This can be done by setting certFile and keyFile in the configuration when starting up that viewer. I need to add code to generate a certificate upon startup and use it for this purpose.

@mmguero mmguero self-assigned this Oct 20, 2022
@mmguero mmguero added arkime Relating to Malcolm's use of Arkime sensor For issues dealing with the Hedgehog OS capture sensor security Related to issues with bearing on the security of Malcolm itself labels Oct 20, 2022
mmguero added a commit to mmguero-dev/Malcolm that referenced this issue Oct 20, 2022
mmguero added a commit to mmguero-dev/Malcolm that referenced this issue Oct 20, 2022
@mmguero
Copy link
Collaborator Author

mmguero commented Nov 2, 2022

done for v6.4.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
arkime Relating to Malcolm's use of Arkime security Related to issues with bearing on the security of Malcolm itself sensor For issues dealing with the Hedgehog OS capture sensor
Projects
Status: Released
Development

No branches or pull requests

1 participant