Tags:
create new tag
view all tags

SID-01821: Best practices for securing a remotely hosted twiki site

Status: Answered Answered TWiki version: 5.1.4 Perl version: not installed yet
Category: CategorySecurity Server OS: cent os 6.4 Last update: 12 years ago

Hi all,

We are planning to setup a twiki installation with a remote host (A VPS account). We have a domain registered and plan to secure the domain with an SSL cert. We've used twiki on our internal network but now that this is hosted elsewhere I want to secure it down as much as possible. We'll only need port 443 open and possibly smtp. This will be on cent os 6.4/apache.

As far as twiki settings and config go, I'm thinking apache authentication would be the best option. Any other tips or suggestions regarding a secure twiki install and config? I want to make sure the site is completely password protected unless the user is logged on (no sections accessible anonymously). Plan to use twiki 5.1.4.

Any tips or references appreciated.

-- Bryan Ino - 2013-11-12

Discussion and Answer

I recommend sticking with template login. The disadvantage of Apache login is that if you login from a public browser (not your own machine) you need to restart the browser to logout.

You can configure TWiki with template login to require authentication for all TWiki scripts. There are certain things that need to be done, such as password reset screen needs to be a static unauthenticated HTML page.

As you mentioned, best to run a secure TWiki on the internet with an SSL cert.

-- Peter Thoeny - 2013-11-12

Hi Peter,

I apologize I know its been almost a month since replying back. We had some emergency scenario to deal with at work so this got delayed. I am now back to setting twiki up with a host provider on a VPS account. At this time Im going to try the install myself. Thank you again for the feedback.

-- Bryan Ino - 2013-12-30

      Change status to:
ALERT! If you answer a question - or someone answered one of your questions - please remember to edit the page and set the status to answered. The status selector is below the edit box.
SupportForm
Status Answered
Title Best practices for securing a remotely hosted twiki site
SupportCategory CategorySecurity
TWiki version 5.1.4
Server OS cent os 6.4
Web server apache
Perl version not installed yet
Browser & version Chrome
Edit | Attach | Watch | Print version | History: r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions
Topic revision: r3 - 2013-12-30 - BryanIno
 
  • Learn about TWiki  
  • Download TWiki
This site is powered by the TWiki collaboration platform Powered by Perl Hosted by OICcam.com Ideas, requests, problems regarding TWiki? Send feedback. Ask community in the support forum.
Copyright © 1999-2026 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.