securedrop-docs icon indicating copy to clipboard operation
securedrop-docs copied to clipboard

Improve "Configure the Network" instructions to disable extra ethernet ports

Open ChumOfChance opened this issue 8 months ago • 0 comments

Describe the change

Non-standard/non-recommended server hardware with extra ethernet ports caused issues during the migration from Ubuntu Focal -> Noble. The extra port was configured but not connected. Instructions to overcome this block in the upgrade process were added in https://github.com/freedomofpress/securedrop-docs/pull/661

It is suggested that the Configure the Network instructions be improved to recommend explicitly disabling unused ethernet ports. If applicable, include instructions so that in the case of a new installation on hardware with extra ethernet ports, the user can follow to disable unused ports rather than have them be auto-configured by the Noble installer.

How will this impact SecureDrop users?

This may improve the outcome of future upgrades, putting non-standard hardware in a state more inline with the recommendations. Disabling unused ethernet ports also improves the security of the servers e.g. if a user inadvertently connects an unused port to the wrong network.

Additional context

  1. Need to investigate how Noble installer handles multiple ethernet ports, if it is different from Focal installer.

ChumOfChance avatar May 14 '25 20:05 ChumOfChance