Version: 2.1.0
Securing HiTechCloud
This section describes the best practices and settings that can increase the security of your HiTechCloud server and, thus, protect it from various types of attacks and loss of sensitive data:
For Server Administrators (HiTechAdmin):
- Enable Basic Access Authentication for HiTechAdmin
- Configure CorazaWAF rules
- Change HiTechCloud or HiTechAdmin ports
- Restrict access to HiTechAdmin
- Check passwords against weakpass.com lists
- Changing the HiTechCloud Administrator Username
- Securing HiTechCloud and the Mail Server With SSL/TLS Certificates
- Restricting access to Features based on Hosting Plans
- Setup Fail2ban for email
- Setup DKIM for emails
- Setup ImunifyAV
- Enable CSF Blocklists
- Limiting Connections with CSF
- Rate-limiting failed HiTechCloud Panel logins
- Change SSH root user password
- Change SSH port
- Configure SSH Keys
- Disable Terminal in HiTechAdmin
- Disable Server Reboot in HiTechAdmin
- Disable HiTechAdmin access
For Website Administrators (HiTechCloud):
- Enabling WAF protection per domain
- Configure Automatic Backups
- Fix Files Permissions
- Scan website files for Malware
- Suspend a Compromised Website
- Setting up Multi-Factor Authentication in HiTechCloud
- Configure Automatic SSL
- Reviewing Account activity log
- Reviewing Active Sessions
- Viewing Login History