SHConnect: SH Way of Secure Server Access

SHConnect, SH Connection Enabler, SH Connection Remover
This article will discuss the issues with SSH key-based and password-based authentication methods. Also, the features and details of our new and advanced server access method called SHConnect.

First, let’s talk about why we decided to move away from the legacy ways of accessing the servers. When we say legacy server access methods, most organizations and companies still use password-based and key-based authentications, and it’s not that outdated. For our technicians to access the servers, we thought we needed something better and advanced because the number of servers that we manage and maintain keeps increasing day by day. In our new system, we are using the SSH key-based authentications to connect client servers, but from a fully secured gateway platform and our automation platforms are also using SSH key-based authentication securely. Our technicians won’t get access to the private key file on our secured gateway, and we even have a feature of automated rotation of SSH keys on the new system. In the past, we were using direct login to the client servers using shared private keys or passwords, but that has a lot of security threats and we developed a new setup based on an open-source software by customizing it and named it as SHConnect during our v2 launch. However, that open-source system also had drawbacks with failure in frequent updates and also a service agent must be installed on client servers. We were developing an in-house SSH gateway system due to these reasons, and finally this is ready and we replaced the SHConnect with our own home tool.

The first thing we did was listed out all the important features of our old SHConnect system to implement in our new in-house system and also connected it with our centralized SSO (Single Sign-On) system to secure our staff access with 2FA. Also, we wanted to provide few more layers of security for our customers, better logging, screen recordings of server activities that we perform, and also a uniform and more secured access using the new SHConnect.

 

SHConnect – Our new and advanced way to access servers securely.

SHConnect is an advanced and more secure server authentication method that our team uses to remotely access servers, web applications, Kubernetes clusters, and databases across all environments.

The features offered by this new authentication method are: 

    • This new approach is more secure than the commonly used shared SSH key-based and password-based authentication methods.
    • There is no need for clients to provide server root passwords.
    • The ServerHealers team will create a sudo user by running a script, and all the access to the server will be through this dedicated sudo user. No direct root access is allowed in the servers.
    • This new tool uses the default SSH service installed on your server to access, but in a secure way of fully protected private keys. There is no need of any extra agent to be installed as before.
    • All staff-level activities are logged on our system, along with access logs, per-staff history logs, restricted commands, and even video screen recordings of all the server activities that we perform.
    • The staff-level access to our new SHConnect gateway is set up through our SSO (Single Sign-On) system with two-factor authentication (2FA) for better security.
    • The SHConnect shell environment only allows limited commands.
    • The staff server access sessions and access logs are kept remotely.
    • The system will monitor client server access daily basis and report if there are any issues to our chat system.

 

“SH Connection Enabler” Script
You will need to log in to your Linux-based server as the root user and execute the “SH Connection Enabler” script given below to make your server ready to connect with the ServerHealers Ansible-based automation platform. ( After running the script given below, please proceed and complete the order and that’ll complete the connection process. )

curl -s scripts.serverhealers.com/shconnect/shce | bash

SH Connection Enabler

This script will modify a few files on your server. Those are given below and the reason for the modification.

FileModification
/home/shconnectCreate a home directory for the ServerHealers dedicated user.
/etc/passwdAdd the newly created dedicated user in this file.
/etc/groupsAdd the newly created dedicated user in this file.
/etc/sudoers.d/serverhealersAdd sudo privileges to the created dedicated user.
/home/shconnect/.ssh/authorized_keysAdd ServerHealers system backup keys to this file.
/etc/ssh/sshd_configModify this file only if the below entry/restriction exists:

AllowUsers variable adjustment

/etc/hosts.allowModify this file only if the below entry/restriction exists:

Host Access Control adjustment

/var/log/serverhealers_connect.logCreate this log file to store the ServerHealers Connection Enabler script.
Whitelist ServerHealers IP address (CSF/APF/Imunify360/UFW/Firewalld)Whitelist the ServerHealers office/system IP addresses on the firewall.
Once you do this, your server will be all set and ready to connect to our platform. We’ll then manually verify your order, and when we accept the order, our automation system will configure “SHConnect” and install our Monitor agent (on TCP port 6556) in your server, and that will complete the connection process.

 

“SH Connection Remover” Script

Log in to your Linux-based server as the root user and execute the “SH Connection Remover” script below to remove and disconnect your server from all ServerHealers platforms. This script will also revert all the changes made by the “SH Connection Enabler” script.

curl -s scripts.serverhealers.com/shconnect/shcr | bash

SH Connection Remover

We hope this article was helpful, and do reach out to us if you have any queries or suggestions.

Share this post

Stay up to date!

Stay up to date with the Web Hosting, Cloud and Server Management Industry News and Tutorials!

We will send you only the relevant emails, and we respect your privacy. Please review our privacy policy for more info.

We heal servers, clouds, and your business!

All you will ever need under one roof with superior quality of service
Are you a web hosting business owner? Running a data center? Cloud service provider? Server owner, or do you own a WordPress website? We provide services and solutions for all your requirements for an affordable rate with quality second to none.
Why Us?

Value-Added Services

We have services that can help you run a successful business. With us, you don't have to worry about these areas because our experts will take care of it for you.

Introducing - WPHealers!

Complete WordPress Management, 24x7 Support & White Label Agency Plans!

WordPress migration service, security, white-label reseller services and lot more! Grab the introductory deals now!

WPHealers

ServerHealers uses cookies.