Skip to content

Improve Security of Remote Support Sessions #7900

@gsanchietti

Description

@gsanchietti

Enhance the security of remote support sessions by implementing the following changes:

  • Limit session longevity by stopping support sessions after 24 hours. 24 hours is a soft limit that can be manually increased by operators up to 7 days. The limit of 7 days is enforced also on the VPN server side.
  • Show the session expiration time inside the UI.
  • Ensure SSH is only accessible via the support VPN to prevent unauthorized direct access.
  • Evaluate and possibly enforce restrictions to allow access to the web interface with the support user only from a specified list of IP addresses.

Discussion:

Metadata

Metadata

Labels

No labels
No labels

Projects

Status

In Progress

Relationships

None yet

Development

No branches or pull requests

Issue actions