Skip to main content

Recently Updated Pages

Architecture

WAF for Small Ecosystems

Where the edge sits and what it hands off to. The WAF is one boundary in a layered defense, and u...

Updated 2 months ago by Chris Landis

Why This Design

WAF for Small Ecosystems

A single edge host that terminates public TLS, inspects every request, and forwards only what pas...

Updated 2 months ago by Chris Landis

Concepts

WAF for Small Ecosystems

The single front door to a self-hosted environment: what it inspects, what it terminates, and wha...

Updated 2 months ago by Chris Landis

Keeping Renewal Boring

Mutual TLS with a Private CA

Short-lived certificates are only a good idea if renewal is reliably automated. The price of shor...

Updated 2 months ago by Chris Landis

Concepts

Mutual TLS with a Private CA

Why nothing inside the network is trusted without proof, and how to run the CA that makes it poss...

Updated 2 months ago by Chris Landis

Architecture

Mutual TLS with a Private CA

Before the configuration, the model. Three ideas make the rest of this book make sense: where the...

Updated 2 months ago by Chris Landis

Enforcing mTLS

Mutual TLS with a Private CA

This is where the policy becomes real. The two configurations below, one on the calling side, one...

Updated 2 months ago by Chris Landis

Issuing and Installing Certificates

Mutual TLS with a Private CA

Every host follows the same bootstrap: make the internal names resolve, trust the CA root, then r...

Updated 2 months ago by Chris Landis

Standing up the CA

Mutual TLS with a Private CA

This is the identity root for every machine in the environment. Everything else in the book depen...

Updated 2 months ago by Chris Landis

Appendix A - SSO Test App

SSO For Small Ecosystems

Clone the repo into a location capable of serving a python flask application. git clone https://g...

Updated 2 months ago by Chris Landis

Configuring BookStack (group-aware pattern)

SSO For Small Ecosystems

Pattern: group-aware. BookStack authenticates users through Keycloak and reads their group member...

Updated 2 months ago by Chris Landis

Configuring Keycloak

SSO For Small Ecosystems

A running Keycloak does nothing useful until you decide how realms are split, how users prove who...

Updated 2 months ago by Chris Landis

1. Introduction

TheDen Home Network Runbook

This runbook defines the network topology, architecture, security configuration, and operational ...

Updated 2 months ago by Chris Landis

7.2 Glossery

Privacy and Security Runbook 7. Reference

Term Definition 3-2-1 Rule A backup strategy: keep 3 copies of your data, on 2...

Updated 2 months ago by Chris Landis

7.1 Maintenance Checklists

Privacy and Security Runbook 7. Reference

Monthly Checklist Time Required: ~30 minutes Backups Verify your computer backup completed...

Updated 2 months ago by Chris Landis

6.4 Device Incidents

Privacy and Security Runbook 6. Incident Playbooks

Ransomware Infection Signs of ransomware Files suddenly encrypted with unfamiliar extension...

Updated 2 months ago by Chris Landis

6.3 Personal Data Incidents

Privacy and Security Runbook 6. Incident Playbooks

Identity Theft Signs of identity theft: Accounts or loans you didn't open appearing on cred...

Updated 2 months ago by Chris Landis

6.1 Account Compromise

Privacy and Security Runbook 6. Incident Playbooks

Compromised Email Account Signs your email might be compromised: Can't log in / password does...

Updated 2 months ago by Chris Landis

6.1 How to Use These Playbooks

Privacy and Security Runbook 6. Incident Playbooks

When you discover a security incident: Don't panic - Take a breath; most incidents are recov...

Updated 2 months ago by Chris Landis

5.1 Backups

Privacy and Security Runbook 5. Backups and Recovery

Core Concepts: Protect Your Data, Have a Recovery Plan You need backups BEFORE disaster strikes....

Updated 2 months ago by Chris Landis