Secure Installation of Apache Guacamole on CentOS VPS
Budget: $10 – $30 USD
Objective:
Install and securely configure Apache Guacamole on a cPanel-based VPS. Ensure HTTPS-only access, hardened security, and TOTP-based 2FA. Provide verifiable evidence that all steps have been completed correctly.
Requirements:
1. Installation
Install the latest stable release of Apache Guacamole from official sources only (no third-party repos).
Provide command history or logs showing source and method of installation.
2. HTTPS & Reverse Proxy
Set up Apache or Nginx as a reverse proxy.
Install Let’s Encrypt SSL and enforce HTTPS-only access.
Submit screenshot of browser padlock + cert details as proof.
3. Firewall & Port Restrictions
Restrict Guacamole’s backend port (e.g., 8080) to localhost only.
Use UFW or CSF to block all unnecessary ports.
Provide output of ufw status or iptables -L.
4. Authentication & 2FA
Set up strong passwords and implement TOTP-based 2FA using the official Guacamole TOTP extension:
Install and configure guacamole-auth-totp.
Ensure QR code appears at first login.
Test and confirm 2FA on PC, iPhone, and iPad.
Submit:
Screenshot of QR code prompt during first login
Screenshot of working 2FA login screen
5. Database Security
Secure MySQL/PostgreSQL:
Use strong DB user credentials.
Restrict DB access to localhost only.
Provide config file or screenshot proving settings.
6. Tomcat Hardening
Disable unused Tomcat features.
Secure with strong credentials.
Restrict public access to Tomcat if not needed.
Submit relevant server.xml or tomcat-users.xml excerpts.
7. Fail2Ban Configuration
Install and configure Fail2Ban to monitor Guacamole/Tomcat logs.
Submit output of fail2ban-client status showing jail is active.
8. System Security
Apply all available system and Guacamole updates.
Submit output of apt list --upgradable or yum check-update.
9. Logging & Monitoring
Enable Guacamole and system logging of login attempts and changes.
Provide log excerpts showing login activity.
Deliverables:
Secure, working Guacamole installation with:
HTTPS-only access
Functional TOTP 2FA
Tested access from PC, phone, and tablet.
PDF or DOCX documentation containing:
Admin credentials (shared securely)
User management + 2FA setup instructions
Update and monitoring instructions
Proof of each requirement as outlined above.
Install and securely configure Apache Guacamole on a cPanel-based VPS. Ensure HTTPS-only access, hardened security, and TOTP-based 2FA. Provide verifiable evidence that all steps have been completed correctly.
Requirements:
1. Installation
Install the latest stable release of Apache Guacamole from official sources only (no third-party repos).
Provide command history or logs showing source and method of installation.
2. HTTPS & Reverse Proxy
Set up Apache or Nginx as a reverse proxy.
Install Let’s Encrypt SSL and enforce HTTPS-only access.
Submit screenshot of browser padlock + cert details as proof.
3. Firewall & Port Restrictions
Restrict Guacamole’s backend port (e.g., 8080) to localhost only.
Use UFW or CSF to block all unnecessary ports.
Provide output of ufw status or iptables -L.
4. Authentication & 2FA
Set up strong passwords and implement TOTP-based 2FA using the official Guacamole TOTP extension:
Install and configure guacamole-auth-totp.
Ensure QR code appears at first login.
Test and confirm 2FA on PC, iPhone, and iPad.
Submit:
Screenshot of QR code prompt during first login
Screenshot of working 2FA login screen
5. Database Security
Secure MySQL/PostgreSQL:
Use strong DB user credentials.
Restrict DB access to localhost only.
Provide config file or screenshot proving settings.
6. Tomcat Hardening
Disable unused Tomcat features.
Secure with strong credentials.
Restrict public access to Tomcat if not needed.
Submit relevant server.xml or tomcat-users.xml excerpts.
7. Fail2Ban Configuration
Install and configure Fail2Ban to monitor Guacamole/Tomcat logs.
Submit output of fail2ban-client status showing jail is active.
8. System Security
Apply all available system and Guacamole updates.
Submit output of apt list --upgradable or yum check-update.
9. Logging & Monitoring
Enable Guacamole and system logging of login attempts and changes.
Provide log excerpts showing login activity.
Deliverables:
Secure, working Guacamole installation with:
HTTPS-only access
Functional TOTP 2FA
Tested access from PC, phone, and tablet.
PDF or DOCX documentation containing:
Admin credentials (shared securely)
User management + 2FA setup instructions
Update and monitoring instructions
Proof of each requirement as outlined above.