Secure Installation of Apache Guacamole on CentOS VPS

Job ID: 39289713

Budget: $10 – $30 USD

Objective:

Install and securely configure Apache Guacamole on a cPanel-based VPS. Ensure HTTPS-only access, hardened security, and TOTP-based 2FA. Provide verifiable evidence that all steps have been completed correctly.
Requirements:
1. Installation

Install the latest stable release of Apache Guacamole from official sources only (no third-party repos).

Provide command history or logs showing source and method of installation.

2. HTTPS & Reverse Proxy

Set up Apache or Nginx as a reverse proxy.

Install Let’s Encrypt SSL and enforce HTTPS-only access.

Submit screenshot of browser padlock + cert details as proof.

3. Firewall & Port Restrictions

Restrict Guacamole’s backend port (e.g., 8080) to localhost only.

Use UFW or CSF to block all unnecessary ports.

Provide output of ufw status or iptables -L.

4. Authentication & 2FA

Set up strong passwords and implement TOTP-based 2FA using the official Guacamole TOTP extension:

Install and configure guacamole-auth-totp.

Ensure QR code appears at first login.

Test and confirm 2FA on PC, iPhone, and iPad.

Submit:

Screenshot of QR code prompt during first login

Screenshot of working 2FA login screen

5. Database Security

Secure MySQL/PostgreSQL:

Use strong DB user credentials.

Restrict DB access to localhost only.

Provide config file or screenshot proving settings.

6. Tomcat Hardening

Disable unused Tomcat features.

Secure with strong credentials.

Restrict public access to Tomcat if not needed.

Submit relevant server.xml or tomcat-users.xml excerpts.

7. Fail2Ban Configuration

Install and configure Fail2Ban to monitor Guacamole/Tomcat logs.

Submit output of fail2ban-client status showing jail is active.

8. System Security

Apply all available system and Guacamole updates.

Submit output of apt list --upgradable or yum check-update.

9. Logging & Monitoring

Enable Guacamole and system logging of login attempts and changes.

Provide log excerpts showing login activity.



Deliverables:

Secure, working Guacamole installation with:

HTTPS-only access

Functional TOTP 2FA

Tested access from PC, phone, and tablet.

PDF or DOCX documentation containing:

Admin credentials (shared securely)

User management + 2FA setup instructions

Update and monitoring instructions

Proof of each requirement as outlined above.
Related categories: System Admin Linux Apache Ubuntu Debian