07-11-2019 07:20 AM
Hi again, one more thing.
For the NI auth login options, is the traffic encrypted? As i understand it admin username and password is needed for allmost all operations, and atleast for installing disk images. If the login information is unencrypted it can really be secure?
07-11-2019 01:42 PM
Hi Mrmas,
I actually did some testing this time, so I'm going to walk back what I said previously. I'm going to call the Web Interface the WIF for shorthand purposes.
I'm a bit hesitant to make any general recommendations since I am no expert on security. I think you already have some good recommendations and blocking port 80 is probably not a bad idea since the WIF can still be accessed via HTTPS in that case. That being said, it seems certain things require port 80 with no simple way around it.
As for NI Auth, it looks like the username might be unencrypted for one of the transfers but that a password is always encrypted. Both appear to be encrypted if you use the HTTPS version of the WIF to log in. For more information on NI Auth, I suggest looking at Manage User Accounts on Linux Real-Time OS Devices or the Linux User Management with Pluggable Authentication Modules (PAM) and NIAuth section of the NI Linux Real-Time Security User Guide.