Currently, the lxc templates are downloaded from http://download.proxmox.com, which is also used as the domain for the Proxmox Debian repository.
It was already reported that the domain has an invalid SSL certificate, which the Proxmox Staff pointed to not be a big concern as the Debian packages...
I am trying to restrict a group of users to specific resources on a specific host in our cluster. I have used a resource pool to limit VM and storage access and other permissions to restrict network access. This seems to work well except that they can create VMs on other hosts in the cluster...
In out security scan of Backup Server 3.2-3 we got back that there is an issue on port 8007. It detect CVE-2002-20001.
The vulnerability is based on the following retrieved information from 8007/TCP:
Vulnerable cipher suites with DhKeyExchange algorithms supported by the server...
Installed proxmox 8.x on a mini pc with 8 physical nics for home use. Created a VM and installed OPNSense. Configured vmbrs so LAN, WIFI, Streaming devices, IOT devices are on a seperate network. Created a rule in proxmox firewall for 8006, 22 so only a specific pc can connect to the...
Hello, been using proxmox for about a year now and I am trying to improve the security of my cluster. Treating all traffic as a problem until proven otherwise. the Block IPv4 link-local (1000000102) rule on my PFsense firewall keeps blocking traffic from my proxmox VMs coming out of the cluster...
Hallo zusammen,
ich plane aktuell eine Malware Analysis Plattform aufzubauen.
Diese soll in insgesamt 2 VMs auf meinem Produktiven Proxmox Hypervisor laufen. (Ja ich weiß nicht ideal - auf einer kleinen Umgebung zuhause gehts leider nicht anders)
Die 2 Maschinen sollen untereinander...
As a general thought, I'm wondering if an official Proxmox Hardening wiki page would be useful?
Maybe placed here or similar?
https://pve.proxmox.com/wiki/Hardening
Asking because hardening a server (or cluster thereof) isn't rocket science, but seems to be under documented apart from various...
I'm currently working out the process of hardening a two node Proxmox cluster for internet facing deployment.
As part of that I'm moving all ports (other than ssh) to internal network interfaces that aren't publicly accessible. ssh will have it's own security configuration, not covered here...
Hi, today I looked through /root/.ssh/authorized_keys and there were 3 keys:
1) ssh-rsa from root@pve
2) ssh-rsa from my desktop (from where I usually manage proxmox)
3) ssh-ed25519 from u0_a129@localhost
Now, I recognize the 2nd key, but what about the 1st and 3rd keys?
I read somewhere that...
Hello everyone,
I'm trying to learn about proper security procedure with proxmox. On my current server :
root@server:~# hostnamectl
Operating System: Debian GNU/Linux 12 (bookworm)
Kernel: Linux 6.2.16-8-pve
Architecture: x86-64
It seem's 6.2.16 had gone EOL one year...
Scenario:
- One machine with proxmox
- Second machine with PBS
VMs on proxmox machine are DELETED, all the VM data is wiped.
After that, the proxmox machine is physically compromised.
What to expect: no data leak
Whan actually happens:
- PBS encryption key is available in /etc/pve on the...
in one of our (lazy infrequent) security scans we stumbled upon a running rpcbind. it seems that it was installed around 8.0.4.
trying to remove it tells us that pve depends on it:
The following packages will be REMOVED:
libpve-guest-common-perl* libpve-storage-perl* nfs-common* proxmox-ve*...
The pvecm qdevice setup requires an ssh connection to the QD, which is not there for "casting votes". As QDs are meant to be run externally, why is this not the other (natural) way around, i.e. generating script for one to execute on the QD, possibly provide the feature (as a perk) by calling...
Dear all,
I am trying to build a home server where i want to run few services, such as Nextcloud, as LXC contianers. I am relatively new to networking and before posting here i have read several pieces of documentation. Nevertheless, i still have doubts regarding the best setup for my use case...
Hi,
I noticed that if I set the OUTPUT policy to DROP, I need to add a few rules by default for SSH, migrations to work if I add another ringX address. Could it be that some rules that gets set by default for INPUT may have been forgotten in output ?
I see the usual ports...
Hello everyone,
I followed this guide : https://pve.proxmox.com/wiki/Fail2ban
Then implemented all the attempts @ https://forum.proxmox.com/threads/pve-8-0-%E2%80%93-fail2ban-log-locations-missing.129338/
When I manually trigger the maxretrys nothing happens. When I run the test code provided...
Hello,
i was wondering why only can choose Yubico and OATH/TOTP. I would like to enforce that all users are required to configure webauthn. Am i missing something, or is that option no available? Thank for your help.
Kind regards
schaurian
Hello !
My SOC reported an issue on my newly installed v8 (in place upgrade)
The SOC client (Covalence by Field Effet) was installed yesterday, just before 7to8 upgrade
shellcheck v. 0.9.0-1 is installed on this host. CVE-2021-28794 - 9.8/10
The unofficial ShellCheck extension before 0.13.4...
Hi,
I've purchased a HUNSN mini PC like this one (amazon link) and installed Proxmox VE 7 on it and it seems to run fine so far. After trying to find a way of passing-through a M.2 Wifi/BT card (like this one, amazon link) to a debian VM, and not finding one, I reached out to the seller which...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.