Skip to main content

Hardening

Network​

  • Allow port 8443 only from the networks your administrators and agents are in.
  • Agents need no inbound ports. Their only connection is outbound, to the server.

Certificates​

  • The self-signed certificate is safe for agents, which pin its key. For browsers, check the fingerprint once, or use your own certificate with --tls-cert and --tls-key.
  • Back up /var/lib/deaconguard/tls/. If the key is lost, agents must be enrolled again.

Accounts​

  • Use a long, unique password for every dashboard account. Every account is an administrator.
  • Remove accounts that are no longer needed: sudo -u deaconguard deaconguard user remove NAME. This signs them out everywhere.
  • Review the Audit log for unexpected sign-ins, tokens or enrollments.

Enrollment tokens​

  • Create a token just before you enroll a machine, and revoke tokens you didn't use.
  • Treat an unused token like a password: anyone with it can enroll a machine with your server until it expires.

Keep it current​

  • Upgrade regularly; security fixes go into the latest minor version. Watch the repository's releases on GitHub to be notified.
  • Verify releases you install by hand.