Note: All of the following config options can be set in
/etc/sicura/sicura-console.yaml
To disable the ‘Remediate’ button system wide, set the following option to false
.
main.disable_enforcement: true
main.schema_engine.signature_hash: "SHA384"
Some cryptographic settings used by Sicura Console have configuration options specified in the config file to meet some policy requirements.
To set the hashing algorithm for the web server’s HMAC algorithm use the following setting:
main.rack-session.hmac: "SHA384"
The address and port can be specified using the following parameters:
main.listen_ip: localhost
Note: In order for the Sicura Console to be discoverable externally (Both LAN and Internet) listen_ip should be
0.0.0.0
main.listen_port: 6468
First, either self-generate or purchase an SSL certificate and key.
Then place them in /etc/ssl/certs
and /etc/ssl/private
respectively.
In sicura-console.yaml
add the following configuration:
main.ssl.enabled: true
main.ssl.key: "/etc/ssl/private/mykey.key"
main.ssl.cert: "/etc/ssl/certs/mycert.pem"
# Enable SSL verify (Insecure if set to false)
main.ssl.verify: true