Security mechanisms, service levels and service requirements of network services should be identified, implemented and monitored.
All network traffic between users and internal systems is encrypted through Netbird VPN. Every connection requires 2FA authentication using YubiKeys.
Login across services is performed through Single Sign-On (SSO) using YubiKey-based 2FA (PIN + touch). Only authenticated and authorized users gain network access.Role-based access control (RBAC) enforces access policies across all network services.
SSH public keys are centrally managed in configuration files, private keys are securely stored on YubiKeys. LinuxAid automatically distributes SSH keys across all servers, eliminating manual setup, removing password-based logins, and ensuring secure, hardware-backed access control throughout the infra.