Manual/VirtOn/2. Installation and initial setup/2.4 Login and initial connection
Home
VirtOn DocumentationVersion 1.0User Guide

2.4 Login and initial connection

On this page

2.4 Login and initial connection

The login page is VirtOn It's the root page of the

  • I'm not a logan. : VirtOn To use the VirtOn We need a dedicated ID and a password.
  • Basic administrator account The initial idea was: adminAnd, the initial password uses a temporary password that was not notified at the time of the test or delivery.
The submission document recommends that the default administrator password and the test temporary password are not fixed. The passwords required for the test are not notified and must be changed after the test is completed.

Entry entries and permissible range

ItemsExplanationThe input criteria
I'm not going to lie.VirtOn It's a user account ID.Enter the registered unique account ID.
Password.It's the password used to authenticate your account.It's masked on the screen and not stored as a plain board on the server.
The IP address of the connectionIt's the IP of the administrator PC that made the login request.If you have a whitelist set up, you can log in only to the registered IP.

2.4.1 Login failure policy

It's a security policy for a log-in failure.

  • Account information discrepancy Users name:(I'm not going to lie.) And when you misread the password, The ID or password is not correct. The phrase is printed.
  • Try to log in. Login in a short time. Try five times. You can log in to the same IP or ID. Block for 10 minutes.So we're going to do that.
  • IP-based blocking is blocked even if you try to use five or more different IDs from one IP.
  • A blocking based on an ID will be blocked if you try to block it five times or more with each user using a different password.
  • The transcript log. Security policy: Copy logging is not allowed, the session runs according to the logging session afterwards, and the previous logging is blocked.

2.4.2 Change the administrator password

This is the password change page that you go to after you log in to your first administrator account.

  • Policy of required change The default admin account is provided when you first log in, Change the password.We have to. (If you don't change it, VirtOn You can't use the service.)
  • The complexity of the password. : To change the password, you need the following conditions:English with a capital/symbol, numbers, special characters or more than 9 digitsSame letter three times in a row.Keyboard/number sequence not enteredEnter the same as the user IDYou can't reuse your old password.
  • The verification process For accuracy, you enter the password once more, and it can be changed if it's written correctly to fit the conditions.
  • So this is the (When you enter 1234) The satisfied condition is the check mark that makes the UI different and provides convenience.
  • The password change button will not be activated until the conditions are met and the new password is verified.
  • However, even if you're satisfied with the terms and the new password is over, when you click the Change Password button, you can't change it with the error message if you reuse the previous password.

2.4.3 Log out

2.4.3.1 Log out and session expiration

VirtOn It's a policy when you stop using or when your session expires.

  • How to log out Upper right: Icon of the accountYou press log out.
  • Proxmox The drive. Log out city, connected Proxmox API Log out with the connection. So we're going to do that.
  • Duration of the session The duration of the session: Three hours.And then three hours later, the session ends. VirtOn We need to re-rout logins.
  • The time of the session expiration : Short, automatic log-out due to session expiration Proxmox API The information.You don't have to rewrite it.

How to check session expiration and failure

The situation.Screen view/createController verification items
Log outGo to the login screen.Check that the security feature is blocked in your browser.
Session is over.They're going to need a jahogine.After the session expires, the existing API Check that the call is blocked.
The transcript log.It's either blocked or running on a logged-in basis.Check the log and session changes in the log check.

2.4.4 Blacklist and Whitelist

VirtOn The system operates a powerful IP access control system to protect the system from outside intrusion attempts and hacking threats.(The whites.) You can register and you can strengthen the security.

  • Login failed to make the blacklist. Three logins in the last hour. (- Stop for 10 minutes.) And when you're there, you're judging it's an unusual access, and the IP address for that access is blacklisted and blocked.
  • When you access IP that's not on the whitelist, When the whitelist IP is undefined, there are no access restrictions, but when the whitelist is set, only the registered IP is allowed.
  • Login failure on the White List. If you fail to meet the IP log-in blocking criteria, the blocking will not happen, but you should try to log in after a while.

How to verify IP access control

The situation.How to check
The white-listed myth.I'm just checking that the general login policy applies.
Set up the whitelistCheck that the login screen or authentication request is blocked from an unregistered IP.
Block the blacklist.Check the security alerts and check logs to see if the IP is blocked, the view is blocked, and the disability is.

2.4.5 Proxmox API Set it up

VirtOn The service. Proxmox VE To control the server, API When the password change to the administrator account is completed, the system is automatically set to boot.(Setup) It goes to the page.

2.4.5.1 Initial reactivation setting

This setting is the top administrator.(Super Admin) Or the manager.(Admin) Only authorized users do the first time, and the set information is encrypted and stored in the database.

  • Set the object When we first built the system, the administrator(Admin Or SUPER ADMIN) Just enter it once.(User) And you can access the service directly without going through this process.
  • API The token method : VirtOn It's not an ID/password for security. API We use the token method. Proxmox You need to enter the token information that's been issued from the console.Host (Host) I'm going to move. Proxmox It's the IP address or domain of the server.The port. (Port) : Proxmox API The port. (The default value is 8006.) I'm going to enter it.Token ID : username@Realm! is the token name format. (Yeah, root@pam!virton)Secret The token was created when it was issued. UUID It's the secret key to the form. (It's encrypted when it's stored.)
  • Setup save and automatically apply When you save the settings, the reactive success is displayed, and all users logging in afterwards automatically without any separate IP or token input. Proxmox It's connected to the dashboard.
  • Fixed settings To change the connection information after the initial setup, log in to the administrator permissions. [Set it up [You can edit it from the System Settings menu.

Check the initial activation failure time

The symptoms.Check the itemHow to take action
Proxmox Connection failureHost, port, token ID, secret valueProxmox I'll check the token permissions and input format again on the console.
Certificate errorProxmox Whether or not to register a certificateI run the certificate registration script for the distribution process and try again.
Setup not savedAdministrator permissions, missing the required valueSUPER ADMIN Or ADMIN Log into the account and enter all the necessary values.