{"id":442,"date":"2022-11-15T16:53:07","date_gmt":"2022-11-15T14:53:07","guid":{"rendered":"https:\/\/upcloud.com\/global\/us\/2022\/11\/15\/modern-operating-systems-improved-security\/"},"modified":"2022-11-15T16:53:07","modified_gmt":"2022-11-15T14:53:07","slug":"modern-operating-systems-improved-security","status":"publish","type":"post","link":"https:\/\/upcloud.com\/global\/blog\/modern-operating-systems-improved-security\/","title":{"rendered":"New modern operating systems with improved security out of the box"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Password strength has always been a concern for all internet-connected systems. Doubly so for any cloud servers with open service ports. If you&#8217;ve ever had a look at your Syslogs after deployment, many servers are immediately subjected to brute-force attacks straight from creation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the longest time, the best advice has been to disable password login and <a href=\"https:\/\/upcloud.com\/global\/docs\/guides\/use-ssh-keys-authentication\/\">use SSH keys for authentication<\/a> instead. Last year, we introduced one-time passwords for better security while highly recommending everyone move to the SSH-keys-only approach. Now with further changes coming with new operating system templates, it&#8217;s time to say goodbye to passwords!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SSH keys only going forward<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Starting with the releases of the latest templates from Ubuntu, Alma and Rocky Linux, all new Cloud Server deployments are done with SSH keys only. Enabling password login at server creation is not available using these operating system templates. The following operating systems and any future versions can only be created with SSH keys:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ubuntu 22.04 LTS<\/li>\n\n\n\n<li>Alma Linux 9<\/li>\n\n\n\n<li>Rocky Linux 9<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When deploying one of these templates via your UpCloud Control Panel, you will notice only the SSH keys option is available. Consequently, the Metadata service needs to be enabled during deployment for adding the SSH keys to the server. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/upcloud.com\/media\/ssh-keys-only-ubuntu-2204-2-1024x705.png\" alt=\"SSH key management in the UpCloud control panel, for secure remote server access.\" class=\"wp-image-31772\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Similarly, if you are deploying a new Cloud Server using one of these templates <a href=\"https:\/\/upcloud.com\/global\/docs\/guides\/deploying-server-upcloud-api\/\">via the UpCloud API<\/a>, you will need to enable Metadata. The <a href=\"https:\/\/upcloud.com\/global\/docs\/guides\/upcloud-metadata-service\/\">Metadata service<\/a> can be disabled after server creation if not needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One-time passwords remain an option for older templates while available. If your service relies on password authentication, choose one of the other operating systems instead.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Password strength has always been a concern for all internet-connected systems. Doubly so for any cloud servers with open service ports. If you&#8217;ve ever had [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":58070,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"166,3552,205,634,703,187","_relevanssi_noindex_reason":"Blocked by a filter function","footnotes":""},"categories":[4,7],"tags":[],"class_list":["post-442","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcements","category-product-updates"],"acf":[],"_links":{"self":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/442","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/comments?post=442"}],"version-history":[{"count":0,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/442\/revisions"}],"wp:attachment":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/media?parent=442"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/categories?post=442"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/tags?post=442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}