Skip to main content

OTRS and HTTPS

Following the recent upgrade of OTRS on our servers to the latest version, I went one step further and decided to deploy https to wrap it all up. There is no significantly important data shared or entered in our OTRS configuration, but I think it a worthwhile exercise to put encryption in place. I've only really touched on SSL once or twice before with server configurations, and I started out by looking for a cheap certificate. The thing is, this is a commercial application of the system and I didn't want to use a non-profit or education SSL cert for something that is part of our money making enterprise.

Enter "Let's Encrypt". I read about this somewhere - probably one of the many *almost* spam newsletter type emails I get during the week from a vendor. A Google search brought up a DigitalOcean write up on how to apply this to the particular version of Linux I'm running.

I'm just going to say that I love the DigitalOcean walk through's. They're clear and easy to follow. I tend to have bits of extra complexity in my installs, but I'm usually able to extrapolate from the D/O information to get want I want. Here is the link to the walk through that I used:

https://www.digitalocean.com/community/tutorials/how-to-secure-apache-with-let-s-encrypt-on-ubuntu-14-04

Get around it - it's great. So now we have an encrypted OTRS site and it works well.

Apart from just having an encrypted site, we have also noticed a pleasing uptick in the responsiveness of the site and a removal of an ongoing issue we were having access it from external. When my techs would try to connect to the page from outside the office and then enter data into it, they would have to continuously re-authenticate. This was completely unusable and also one of those problems I just never seemed to have time to get around to fixing. Now, with https:// in front of the address, this problem has disappeared! The site responsiveness isn't to be ignored - no matter where it's being accessed from, the page is significantly faster, a fact which pleases all of us.

To summarise - spend the time and get the encryption happening for OTRS - it's worth it!

Comments

Popular posts from this blog

Plone - the open source Content Management System - a review

One of my clients, a non-profit, has a lot of files on it's clients. They need a way to digitally store these files, securely and with availability for certain people. They also need these files to expire and be deleted after a given length of time - usually about 7 years. These were the parameters I was given to search for a Document Management System (DMS) or more commonly a Content Management System (CMS). There are quite a lot of them, but most are designed for front facing information delivery - that is, to write something, put it up for review, have it reviewed and then published. We do not want this data published ever - and some CMS's make that a bit tricky to manage. So at the end of the day, I looked into several CMS systems that looked like they could be useful. The first one to be reviewed was OpenKM ( www.openkm.com ). It looked OK, was open source which is preferable and seemed to have solid security and publishing options. Backing up the database and upgradin

Musings on System Administration

I was reading an article discussing forensic preparation for computer systems. Some of the stuff in there I knew the general theory of, but not the specifics of how to perform. As I thought about it, it occurred to me that Systems Administration is such a vast field. There is no way I can know all of this stuff. I made a list of the software and operating systems I currently manage. They include: - Windows Server 2003, Standard and Enterprise - Exchange 2003 - Windows XP - Windows Vista - Windows 2000 - Ubuntu Linux - OpenSuSE Linux - Mac OSX (10.3 and 10.4) - Solaris 8 - SQL 2005 - Various specialised software for the transport industry I have specific knowledge on some of this, broad knowledge on all of it, and always think "There's so much I *don't* know". It gets a bit down heartening sometimes. For one thing - I have no clue about SQL 2005 and I need to make it work with another bit of software. All complicated and nothing straightforward. Irritating doesn&

Traffic Monitoring using Ubuntu Linux, ntop, iftop and bridging

This is an update of an older post, as the utilities change, so has this concept of a cheap network spike - I use it to troubleshoot network issues, usually between a router and the network to understand what traffic is going where. The concept involves a transparent bridge between two network interface cards, and then looking at that traffic with a variety of tools to determine network traffic specifics. Most recently I used one to determine if a 4MB SDSL connection was saturated or not. It turned out the router was incorrectly configured and the connection had a maximum usage under 100Kb/s (!) At $1600 / month it's probably important to get this right - especially when the client was considering upgrading to a faster (and more expensive) link based on their DSL provider's advice. Hardware requirements: I'm using an old Dell Vostro desktop PC with a dual gigabit NIC in it - low profile and fits into the box nicely. Added a bit of extra RAM and a decent disk and that&