<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SPEKTRA Edge</title>
    <link>https://docs.edgelq.com/learn/os/security/</link>
    <description>Recent content on SPEKTRA Edge</description>
    <generator>Hugo</generator>
    <language>en</language>
    <atom:link href="https://docs.edgelq.com/learn/os/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title></title>
      <link>https://docs.edgelq.com/learn/os/security/disk-encryption/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.edgelq.com/learn/os/security/disk-encryption/</guid>
      <description>Disk encryption Disk encryption protects the data at rest on a device, so that a lost or stolen device does not expose your configuration or workload data. This page explains what is encrypted, how a device unlocks itself, and how to recover access.&#xA;What is encrypted When encryption is enabled, the two areas that hold your information are encrypted:&#xA;the configuration area (device settings, identity, administrator password, hooks) the data area (container images, workload data, logs) The boot and system-image areas are not encrypted; they contain only the operating system, which is public and identical across devices.</description>
    </item>
    <item>
      <title></title>
      <link>https://docs.edgelq.com/learn/os/security/tpm-attestation/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.edgelq.com/learn/os/security/tpm-attestation/</guid>
      <description>TPM &amp;amp; device attestation Devices use a hardware security module — a TPM (Trusted Platform Module) — to establish a strong, hardware-rooted identity and to protect sensitive material. This page explains what the TPM is used for and how attestation works during provisioning.&#xA;What the TPM is used for Device identity. The TPM holds keys that uniquely and verifiably identify the device. These keys cannot be copied off the device. Attestation.</description>
    </item>
    <item>
      <title></title>
      <link>https://docs.edgelq.com/learn/os/security/secure-boot/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.edgelq.com/learn/os/security/secure-boot/</guid>
      <description>Secure Boot Secure Boot is a firmware feature that ensures a device only runs boot software that is cryptographically signed and trusted. SPEKTRA Edge OS supports Secure Boot so that the boot chain — from firmware through to the operating system — is verified before it runs.&#xA;Why use Secure Boot Secure Boot protects against tampering with the boot path. Combined with disk encryption and device attestation, it raises the bar for an attacker with physical access: the device will refuse to boot modified or untrusted boot software.</description>
    </item>
    <item>
      <title></title>
      <link>https://docs.edgelq.com/learn/os/security/ssh-access/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.edgelq.com/learn/os/security/ssh-access/</guid>
      <description>SSH access A device runs an SSH server so you can reach its console for administration. You control whether SSH is enabled, how users authenticate, and where connections may originate. SSH settings are managed from the dashboard (or the API) and applied to the device automatically.&#xA;Enabling or disabling the SSH server You can turn the SSH server off entirely for devices that should never accept direct shell access. With the server disabled, you can still administer the device through remote access over the platform connection.</description>
    </item>
    <item>
      <title></title>
      <link>https://docs.edgelq.com/learn/os/security/user-accounts/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.edgelq.com/learn/os/security/user-accounts/</guid>
      <description>User accounts Each device has a local administrator account used for console and SSH access. This page explains how its password is set and stored, and how to recover access if the password is lost.&#xA;The administrator account The administrator account (admin) has the privileges needed to operate the device locally. For security, devices ship without a usable default password — the administrator password is something you set yourself, so there is no well-known credential to exploit.</description>
    </item>
    <item>
      <title></title>
      <link>https://docs.edgelq.com/learn/os/security/usb-control/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.edgelq.com/learn/os/security/usb-control/</guid>
      <description>USB device control USB device control lets you restrict which USB peripherals a device will accept, protecting against unauthorized devices being plugged into hardware in the field. It is configured from the dashboard (or the API).&#xA;How it works When USB device control is enabled, the device accepts only USB peripherals that match your allow rules; everything else is rejected. When it is disabled, USB devices are accepted normally.&#xA;Allow rules Each allow rule describes the USB devices it permits.</description>
    </item>
    <item>
      <title></title>
      <link>https://docs.edgelq.com/learn/os/security/remote-access/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.edgelq.com/learn/os/security/remote-access/</guid>
      <description>Remote access You can administer devices remotely through the SPEKTRA Edge platform without exposing any inbound ports on the device. Operator actions are carried over the device&amp;rsquo;s existing outbound connection to the platform.&#xA;What you can do remotely Through the platform you can:&#xA;open a remote shell on a device transfer files to and from a device stream system logs and container logs start, stop, and restart workloads reboot or shut down a device These work from the dashboard and from the cuttle command-line tool.</description>
    </item>
  </channel>
</rss>
