Documentation Videos View Site

# Security Guide - CMDB-360 Base Station Overview

This document describes the default security configuration of the CMDB-360 Base Station. We recommend you do not modify or remove any of these controls as they are considered the minimum required when deploying the CMDB-360 Base Station in your environment.

Note

If your CMDB-360 Base Station is deployed in the managed CMDB-360 Cloud, please see the CMDB-360 Cloud documentation for specifics.

# Server Deployment

The CMDB-360 platform is comprised of a single server (Level 1, non-HA) or a three server cluster (Level 2, HA). Each server is running a Linux operating system (currently Ubuntu 20.04) and should be patched to the current available OS patches to limit potential security threats.

# System Users

System users should be limited to non-password only (using identity keys). The following are details and recommendations about the system users:

  • For cloud deployments, the cloud provider typically provides a login user named “ubuntu” which may be disabled after the initial login. This user should not have the ability to login using a password (only using identity keys).
  • The system is configured with a login user name “base” and this user should be used to access the Linux shell if necessary. The base user can sudo (become privileged) in order to perform system patching or other OS level actions.
  • The root user should not have the ability to login via SSH. This is the standard configuration for Ubuntu systems.

To ensure this setting is enabled, edit the /etc/ssh/sshd_config file as root user (using sudo) and make sure the following is set (remove the comment # if in front):

PermitRootLogin no

systemctl restart sshd

We suggest you do not create any additional system users and only configure the base user to accept the authorized keys of trusted system administrators.

# Access Ports

The Base Station server is configured for SSH access on TCP port 22 and for HTTPS access on TCP port 443. We recommend that you do not provide direct access to these ports from the Internet, rather use a load balancer (for the web traffic to 443/tcp) and a Bastion server (for the SSH access to 22/tcp).

Caution

Do not allow direct Internet access to your CMDB-360 Base Station. Instead use a load balancer for the web traffic and a Bastion server for SSH access.

# Encryption

CMDB-360 utilizes an industry standard encryption model for all connectivity and server operations. Data is encrypted during transit to and from the CMDB servers, during rest using disk encryption, and with specific database column-level encryption. We suggest you encrypt any backups that are stored externally using available methods.

# During Transit

In order to provide data confidentiality and integrity during transit, data is secured with TLS (TLS 1.2 as a minimum). This is accomplished with the configuration of the local nginx server using SSL/TLS certificates.

Caution

No data should ever be transmitted to or from the CMDB server that is not encrypted. Always configure nginx with SSL/TLS certificates.

# At Rest

While at rest, data is encrypted using both full-disk encryption and on particular data, using database column-level encryption (AES256). The default CMDB server build automation provides for this encryption and the configuration within the application and database configure the additional encryption by default.

Caution

Disks should always be encrypted. Do not deploy a CMDB server without full encryption. If deploying in a public cloud, please use the available disk encryption methods available.

# Backups

CMDB server database backups are performed locally by default. You should configure your backups to be sent to an external source. CMDB-360 currently supports the automated export of daily backups to either OCI Object Storage or AWS S3 cloud storage. These facilities provide standard encryption options for all your stored objects. You may configure your backup destination and credentials using the provided instructions.

Caution

Always use disk encryption or the available OCI Object Storage or AWS S3 storage encryption options when storing backups externally.

# Integration With External Traffic

The following sections describe additional optional connectivity to the CMDB-360 Base Station.

# REST API

The CMDB-360 Base Station provides a REST API to external clients you wish to access data found within the CMDB platform. The API operates over secure port 443/tcp using TLS of the Express web server described in the Software Architecture section of this document.

All clients must be provided an API bearer key that you can generate from the CMDB platform. Each client may have only one active key. These keys may be limited in the scope of data access.

# SSO

Single sign-on (SSO) is an authentication method that allows users to utilize a single set of credentials to securely login to multiple supporting applications. The CMDB-360 platform supports the Microsoft single sign-on capabilities via the Microsoft Entra ID. This service was formerly known as the Microsoft Azure AD.

# Software Architecture

The CMDB-360 Base Station is a unified platform containing a web server, database server along with application logic all running locally within each server. Optionally, there may be also be a message queue installed (for systems running LaunchPad).

# Web Server / Proxy Server

The web server is an Express server running under Node.js as the base user (non-privileged) on local port 8080/tcp. Traffic is processed and routed by the Express web server to application logic programs that access the local database. A few notes on the web server deployment:

  • No external access is allowed by the local firewall to port 8080/tcp (no insecure traffic allowed).
  • A local nginx proxy server running on local port 443/tcp routes external HTTPS requests from port 443/tcp to the local web server at port 8080/tcp.
  • The local nginx proxy handles certificate exchange ensuring that data is encrypted during transit using TLS (TLS 1.2 as a minimum).

Caution

No data should ever be transmitted to or from the CMDB server that is not encrypted. Always configure nginx with SSL/TLS certificates.

# Database Server

The database server is a MongoDB server running on default local port 27017/tcp. The database is encrypted on disk and also utilizes column-level encryption of certain database fields, including any local users defined for CMDB-360 access (if not using SSO).

Database ports should never be open to the firewall and are only utilized locally by applications running on the CMDB server.

Caution

Never open database ports in the firewall. All database connections to CMDB are internal and should not be exposed publicly.