封面
版权信息
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Chapter 1. First Things First – Creating a Safe Environment
Access control
The CIA model
The principles of security
Data center security
Server security
The importance of logs
The people aspect of security
Summary
Chapter 2. OpenStack Security Challenges
Private cloud versus public cloud security
The different kinds of security threats
The possible attacks
The OpenStack structure
Future components
Summary
Chapter 3. Securing OpenStack Networking
The Open Systems Interconnection model
TCP/IP
Architecting secure networks
Generic Routing Encapsulation (GRE)
Flat network versus VLAN versus GRE in OpenStack Quantum
Design a secure network for your OpenStack deployment
Virtual Private Network as a Service (VPNaaS)
Summary
Chapter 4. Securing OpenStack Communications and Its API
Encryption security
Symmetric encryption
Asymmetric encryption
Symmetric/asymmetric comparison and synergies
Hashing
Public key infrastructure
Cipher security
Designing a redundant environment for your APIs
Secure your OpenStack API with TLS
Enforcing HTTPS for future connections
Summary
Chapter 5. Securing the OpenStack Identification and Authentication System and Its Dashboard
Identification versus authentication versus authorization
Identification
Authentication
Authorization
Session management
Federated identity
Configuring OpenStack Keystone to use Apache HTTPd
Setting up Keystone as a Identity Provider
Configuring Shibboleth
Summary
Chapter 6. Securing OpenStack Storage
Different storage types
Backends
Security
Securing OpenStack Swift
Summary
Chapter 7. Securing the Hypervisor
Various types of virtualization
Hypervisors
Baremetal
Containers
Docker
Linux Containers
Criteria for choosing a hypervisor
Hardening the hardware management
sVirt – SELinux and virtualization
Hardening the host operative system
Summary
Index
更新时间:2021-07-16 13:28:29