<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://www.wvds.it/wiki/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://www.wvds.it/wiki/feed.php">
        <title>WvdS Doku - hr:int:dbgway:operator:sicherheit</title>
        <description></description>
        <link>https://www.wvds.it/wiki/</link>
        <image rdf:resource="https://www.wvds.it/wiki/lib/exe/fetch.php?media=wiki:dokuwiki.svg" />
       <dc:date>2026-05-22T16:13:24+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:firewall-regeln&amp;rev=1769730068&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:start&amp;rev=1769762978&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:tls-einrichten&amp;rev=1769762972&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:zertifikat-erneuern&amp;rev=1769762964&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://www.wvds.it/wiki/lib/exe/fetch.php?media=wiki:dokuwiki.svg">
        <title>WvdS Doku</title>
        <link>https://www.wvds.it/wiki/</link>
        <url>https://www.wvds.it/wiki/lib/exe/fetch.php?media=wiki:dokuwiki.svg</url>
    </image>
    <item rdf:about="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:firewall-regeln&amp;rev=1769730068&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-01-29T23:41:08+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Runbook: Firewall pravila</title>
        <link>https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:firewall-regeln&amp;rev=1769730068&amp;do=diff</link>
        <description>Runbook: Firewall pravila

Trajanje: ~10 minuta 

Uloga: Network-Admin, Security-Admin 

Preduvjet: Root/Admin prava

Kontrola pristupa za Data Gateway na mreznoj razini.

----------

Tijek rada



----------

Potrebni portovi
 Port  Protokol  Smjer</description>
    </item>
    <item rdf:about="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:start&amp;rev=1769762978&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-01-30T08:49:38+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Sigurnost</title>
        <link>https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:start&amp;rev=1769762978&amp;do=diff</link>
        <description>Sigurnost

Ciljna skupina: Security-Admini, DevOps 

Sadrzaj: TLS, Certifikati, Kontrola pristupa 

Prioritet: Kriticno za produkciju

Sigurnosna konfiguracija za produktivni rad Data Gatewaya.

----------

Tijek rada



----------

Runbookovi
  Runbook</description>
    </item>
    <item rdf:about="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:tls-einrichten&amp;rev=1769762972&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-01-30T08:49:32+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Runbook: TLS postavljanje</title>
        <link>https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:tls-einrichten&amp;rev=1769762972&amp;do=diff</link>
        <description>Runbook: TLS postavljanje

Trajanje: ~15 minuta 

Uloga: Security-Admin 

Preduvjet: Certifikat (PFX ili PEM+KEY)

HTTPS za Data Gateway aktivirati.

----------

Tijek rada



----------

1. Certifikat pribaviti

Opcija A: Let&#039;s Encrypt (besplatno)


# Certbot instalirati
sudo apt install certbot

# Certifikat zatraziti
sudo certbot certonly --standalone -d gateway.example.com

# Rezultat:
# /etc/letsencrypt/live/gateway.example.com/fullchain.pem
# /etc/letsencrypt/live/gateway.example.com/privk…</description>
    </item>
    <item rdf:about="https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:zertifikat-erneuern&amp;rev=1769762964&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-01-30T08:49:24+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Runbook: Certifikat obnoviti</title>
        <link>https://www.wvds.it/wiki/doku.php?id=hr:int:dbgway:operator:sicherheit:zertifikat-erneuern&amp;rev=1769762964&amp;do=diff</link>
        <description>Runbook: Certifikat obnoviti

Trajanje: ~10 minuta 

Uloga: Security-Admin 

Ucestalost: Svakih 90 dana (Let&#039;s Encrypt) ili godisnje

Obnova TLS certifikata za Data Gateway.

----------

Tijek rada



----------

1. Istek provjeriti


# Aktualni certifikat provjeriti
openssl s_client -connect gateway.example.com:443 -servername gateway.example.com 2&gt;/dev/null | \
    openssl x509 -noout -dates

# Dana do isteka
echo | openssl s_client -connect gateway.example.com:443 2&gt;/dev/null | \
    openssl …</description>
    </item>
</rdf:RDF>
