Changes between Version 2 and Version 3 of GENIOperationsTrial/GENISecurityCheckClearinghouse


Ignore:
Timestamp:
07/02/15 07:44:45 (9 years ago)
Author:
lnevers@bbn.com
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • GENIOperationsTrial/GENISecurityCheckClearinghouse

    v2 v3  
    1010== 1.1 Goals of GENI Clearinghouse Security Check ==
    1111
    12 This sections will clearly state what is being verifies.
     12The GENI Clearinghouse server is located at the GPO, where it undergoes various GMOC security checks. This page captures an outline of security checks activities executed by the GPO team:
     13 - GPO monitors vulnerabilities feeds for system level packages and:
     14    o Evaluates potential vulnerabilities that would apply to Clearinghouse environment.
     15    o Priorities vulnerabilities to be installed.
     16    o Verifies that vulnerability fix is being applied in the GENI Community.
     17 - GPO monitors system for unusual system and services behavior and investigates as needed.
     18 - GPO periodically checks logs:
     19    o /var/log/apache2/error.log
     20    o /var/log/geni-chapi/chapi.log
     21    o /var/log/apache2/ch_error.log
     22    o /var/log/apache2/portal_error.log
     23
     24The first 3 of the above logs are checked with a script (geni-ch/bin/geni-check-errors). If something looks odd in those 3 logs than the following are reviewed:
     25    o /var/log/apache2/portal_ssl_access.log
     26    o /var/log/apache2/ch_ssl_access.log
    1327
    1428== 1.2 Steps for GENI Clearinghouse Security Check ==