{"id":178,"date":"2019-01-31T06:00:09","date_gmt":"2019-01-31T06:00:09","guid":{"rendered":"https:\/\/www.alansiu.net\/munkiguide\/?p=178"},"modified":"2025-08-07T04:43:45","modified_gmt":"2025-08-07T04:43:45","slug":"basicsecurity","status":"publish","type":"post","link":"https:\/\/www.alansiu.net\/munkiguide\/basicsecurity\/","title":{"rendered":"Adding some basic security to your Munki repo"},"content":{"rendered":"\r\n<h3>SSL<\/h3>\r\n<p>So far, we&#8217;ve just been working with <em>http<\/em> instead of <em>https<\/em>. Yeah, that&#8217;s not good going forward. So you&#8217;ll want to fix that, especially if you add <a href=\"https:\/\/github.com\/munki\/munki\/wiki\/Using-Basic-Authentication\" target=\"_blank\">basic authentication<\/a>.<\/p><p>So, yeah, even though your Munki &#8220;website&#8221; is &#8220;static,&#8221; you should at least make it <em>https<\/em>.<\/p>\r\n<h4>Let&#8217;s Encrypt<\/h4><p>If your Munki repo is public-facing (try to be conservative with what kind of traffic you translate WAN-to-LAN on your firewall), you can get a free SSL certificate by using <a href=\"https:\/\/certbot.eff.org\/instructions?ws=apache&#038;os=osx\" target=\"_blank\">Let&#8217;s Encrypt&#8217;s certbot<\/a>.<\/p>\r\n<h4>Self-signed certificate<\/h4>\r\n<p>You can create a self-signed certificate. More details at <a href=\"https:\/\/www.alansiu.net\/2016\/02\/02\/using-https-self-signed-certificates-and-basic-authentication-with-munki\/\" target=\"_blank\">Using https \/ self-signed certificates and basic authentication with Munki<\/a>.<\/p>\r\n<h3><em>https<\/em> going forward<\/h3>\r\n<p>The links above should help, but securing a web server isn&#8217;t a Munki-specific thing, so have a look at the links above. If they get you going with securing your repo, yay! If not, you can continue with <em>http<\/em> for now, but you may want to revisit in the future. Going forward, all the rest of the tutorials will assume you have <em>https<\/em> enabled.<\/p>\r\n<h3>Securing access to the repo<\/h3>\r\n<p><em>https<\/em> and basic authentication add some security to the access of the repo by clients, but you should also protect write access to the repo. In fact, that protection is more important. Munki runs as root, so any changes to the repo must be made carefully and only by approved people in your school. One wrong script could wipe out user data or cause other problems.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>SSL So far, we&#8217;ve just been working with http instead of https. Yeah, that&#8217;s not good going forward. So you&#8217;ll want to fix that, especially if you add basic authentication. So, yeah, even though your Munki &#8220;website&#8221; is &#8220;static,&#8221; you should at least make it https. Let&#8217;s Encrypt If your Munki repo is public-facing (try [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-178","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"jetpack_shortlink":"https:\/\/wp.me\/paDrAJ-2S","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts\/178","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/comments?post=178"}],"version-history":[{"count":4,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts\/178\/revisions"}],"predecessor-version":[{"id":525,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/posts\/178\/revisions\/525"}],"wp:attachment":[{"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/media?parent=178"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/categories?post=178"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.alansiu.net\/munkiguide\/wp-json\/wp\/v2\/tags?post=178"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}