<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Data Security on Dataprd.Com</title>
		<link>https://dataprd.com/categories/data-security/</link>
		<description>Recent content in Data Security on Dataprd.Com</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Wed, 03 Jun 2026 14:00:00 +0000</lastBuildDate>
		
			<atom:link href="https://dataprd.com/categories/data-security/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Migrating from WordPress to Hugo: Speed, Security, and GitHub Pages</title>
				<link>https://dataprd.com/posts/wordpress-to-hugo-migration/</link>
				<pubDate>Wed, 03 Jun 2026 14:00:00 +0000</pubDate>
				<guid>https://dataprd.com/posts/wordpress-to-hugo-migration/</guid>
				<description>&lt;p&gt;The WordPress setup behind this blog kept causing trouble: security issues, breaches, and a constant stream of updates for core, theme and plugins. For a site of articles that almost never change, that was too much upkeep and too much risk.&lt;/p&gt;&#xA;&lt;p&gt;So I moved it to &lt;a href=&#34;https://gohugo.io/&#34;&gt;Hugo&lt;/a&gt; and now serve it as flat files from GitHub Pages, for free. This post covers why, how the SQL dump became Markdown, and the deployment setup.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Building a Self-Hosted Personal Dashboard with Glance</title>
				<link>https://dataprd.com/posts/personal-dashboard-glance/</link>
				<pubDate>Wed, 03 Jun 2026 13:00:00 +0000</pubDate>
				<guid>https://dataprd.com/posts/personal-dashboard-glance/</guid>
				<description>&lt;p&gt;I used to start the day by going through the same handful of browser tabs: weather, calendar, news, markets, YouTube. I wanted all of it on one screen instead.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/glanceapp/glance&#34;&gt;Glance&lt;/a&gt; is an open source, self-hosted dashboard. It ships as a single binary with no database, and the whole page (widgets, data sources, refresh intervals, layout) is declared in one YAML file, &lt;code&gt;glance.yml&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;My config has grown to about 730 lines, plus roughly 2,000 lines of PHP in the proxy layer that feeds the parts Glance cannot fetch on its own. This post covers what is on the screen, where the data comes from, and why the PHP layer exists at all.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Data Governance in the Big Data and Hadoop world - Whitepaper</title>
				<link>https://dataprd.com/posts/data-governance-in-the-big-data-and-hadoop-world-whitepaper/</link>
				<pubDate>Fri, 25 Aug 2017 16:11:15 +0000</pubDate>
				<guid>https://dataprd.com/posts/data-governance-in-the-big-data-and-hadoop-world-whitepaper/</guid>
				<description>&lt;p&gt;&lt;strong&gt;&lt;em&gt;My full whitepaper — &lt;a href=&#34;https://dataprd.com/files/Data_Governance_2015.pdf&#34; title=&#34;Data Governance in the Big Data and Hadoop World&#34;&gt;Download PDF&lt;/a&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Amidst vast data lakes and a high velocity of incoming data, enterprises are finding that despite the procedures, policies, and systems that are already in place, their data governance frameworks still aren&amp;rsquo;t delivering the insights needed to drive smart business decisions. Pain points such as privacy and security, appropriate permissions, and labor-intensive data mining processes are challenging general data governance frameworks that do not allow for flexibility or agility. Hadoop can be an excellent framework to support a large data storage repository with immense processing power. The key to success is understanding how to unleash Hadoop&amp;rsquo;s powerful storage capabilities. This white paper reveals:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Top 7 challenges of building a data lake</title>
				<link>https://dataprd.com/posts/top-7-challenges-of-building-a-data-lake/</link>
				<pubDate>Sat, 07 Jan 2017 18:26:42 +0000</pubDate>
				<guid>https://dataprd.com/posts/top-7-challenges-of-building-a-data-lake/</guid>
				<description>&lt;p&gt;While from the technical perspective, deployment, management and provisioning tools are available to quickly set up a Hadoop cluster, introducing it to the organization is a tough task. Here are the biggest challenges of building a data lake   &lt;strong&gt;1. Understand the purpose and limitations of the technology&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Hadoop environment provides a vendor independent tool-chain for data storage, management and analytics in a scalable fashion - it can manage infinite amount of data and with add-ons makes real-time and data science use-cases available for the enterprise&lt;/li&gt;&#xA;&lt;li&gt;Many organizations do not have Big Data. They just load their RDBMS content and get surprised that a 20 node enterprise Hadoop setup&amp;rsquo;s performance is subpar compared with a single PostgreSQL instance. Sure, because the purpose and capabilities are different - we should compare apples with apples after all&lt;/li&gt;&#xA;&lt;li&gt;In 95% of the cases stakeholders think that this new technology will substitute their painful proprietary data environment of RDBMSs. It is a highly distributed environment so the case is that it is never capable to substitute proprietary data systems. But it can live well beneath those providing extreme value. The purpose of the data lake is different. Ingest data, all of your data, and deal with portions of it without costly ETLs to move it from here to there. Refine your data system, be it processing, reporting or prediction models by slowly adding more datasets.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;2. Security&lt;/strong&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>Setting up a firewall to secure a Hadoop cluster&#39;s network with Shorewall</title>
				<link>https://dataprd.com/posts/setting-up-a-firewall-to-secure-hadoop-clusters-network-with-shorewall/</link>
				<pubDate>Fri, 14 Mar 2014 13:40:59 +0000</pubDate>
				<guid>https://dataprd.com/posts/setting-up-a-firewall-to-secure-hadoop-clusters-network-with-shorewall/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;http://shorewall.net/&#34;&gt;Shorewall&lt;/a&gt; is a tool to configure Linux inbuilt IPTables in an easy and understandable way. Assume we have a basic setup: &lt;em&gt;Lan | Firewall with Proxy server | Internet&lt;/em&gt; &lt;img src=&#34;https://dataprd.com/images/uploads/2014/08/Shorewall_Proxy.png&#34; alt=&#34;Network_Config&#34;&gt; A secure setup is to:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;ACCEPT HTTP(80) and HTTPS(443) from LAN to NET&lt;/li&gt;&#xA;&lt;li&gt;ACCEPT special services ports from specific LAN to NET (like e-banking)&lt;/li&gt;&#xA;&lt;li&gt;ACCEPT only the needed FW services from LAN to FW - SSH(22) and MAIL(25,443,993,&amp;hellip;) to FW (if mail server is on FW)&lt;/li&gt;&#xA;&lt;li&gt;ACCEPT only the needed FW services from NET to FW - SSH(22) with IP restriction (and SSH key) and MAIL(25,443,993,&amp;hellip;) to FW (if mail server is on FW)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;SSH port can be changed&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;LOC to LOC connections are not possible to be governed by FW, therefore all allowed&lt;/li&gt;&#xA;&lt;li&gt;REJECT any incoming connection (other than above) to LAN or FW&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Shorewall configuration - with some additional examples on the syntax and rules:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Security of a Hadoop cluster</title>
				<link>https://dataprd.com/posts/security-of-a-hadoop-cluster/</link>
				<pubDate>Fri, 14 Mar 2014 13:30:30 +0000</pubDate>
				<guid>https://dataprd.com/posts/security-of-a-hadoop-cluster/</guid>
				<description>&lt;p&gt;Hadoop is not only a data processing but a data warehouse solution. When we are talking about high amount of data we are talking about business value (the basis of the services) for a company. As Hadoop uses many nodes, network devices all the equipment must be included in a security plan - no weakest links are allowed. &lt;strong&gt;To secure our assets the following tools and approaches can be used.&lt;/strong&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>Data security on Android</title>
				<link>https://dataprd.com/posts/data-security-on-android/</link>
				<pubDate>Thu, 13 Mar 2014 13:13:23 +0000</pubDate>
				<guid>https://dataprd.com/posts/data-security-on-android/</guid>
				<description>&lt;p&gt;The biggest data generator is in our pockets - so securing it to protect privacy is the very first step to do before starting to use a device. Steps to secure Android:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Remove all non-needed apps&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Acquire root permissions on your phone (phone specific, use &lt;a href=&#34;http://forum.xda-developers.com/&#34;&gt;XDA forum&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Use &lt;a href=&#34;https://play.google.com/store/apps/details?id=com.keramidas.TitaniumBackup&amp;amp;hl=hu&#34;&gt;Titanium Backup&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Backup all your data&lt;/li&gt;&#xA;&lt;li&gt;Freeze or uninstall all unnecessary programs&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Remove all which is vendor specific (Samsung, Sony, MIUI fork, &amp;hellip;)&lt;/li&gt;&#xA;&lt;li&gt;Remove all Google packages&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Disable all unused or privacy wise dangerous services with &lt;a href=&#34;http://forum.xda-developers.com/showthread.php?t=2392490&#34;&gt;Disable Services&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;If some vital functions are not working you can re-enable it&lt;/li&gt;&#xA;&lt;li&gt;Regularly, apps with disabled services still work (e.g. disabling LocationAccess for Facebook app)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://dataprd.com/images/uploads/2014/08/DisableServices.jpg&#34; alt=&#34;DisableServices&#34;&gt; &lt;img src=&#34;https://dataprd.com/images/uploads/2014/08/DisableServices.png&#34; alt=&#34;DisableServices&#34;&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>Secure Linux based environment - communication for SMEs</title>
				<link>https://dataprd.com/posts/secure-environment-for-communication/</link>
				<pubDate>Thu, 13 Mar 2014 13:11:16 +0000</pubDate>
				<guid>https://dataprd.com/posts/secure-environment-for-communication/</guid>
				<description>&lt;p&gt;Data governance procedures include the management of communication assets (e-mail, instant messaging, phone calls), which are considered as business secrets. While small enterprises should make calculations on using the cloud as the price benefit might be worth the negative impact on data management and ownership, a medium/large sized company is suggested to use own solutions with own security and data backup policies. Hereby - &lt;em&gt;in brief&lt;/em&gt; - I present an &lt;em&gt;exemplary cost-effective,&lt;/em&gt; secure setup for small to medium enterprises own infrastructure based on encrypted communication and messaging storage with data security and backup in mind. &lt;em&gt;This is a high-level overview: data governance practices, backup policies, disaster recovery, update procedures, security testing, physical security, etc. are to be defined&lt;/em&gt;. &lt;img src=&#34;https://dataprd.com/images/uploads/2014/08/MidSecure.png&#34; alt=&#34;Middle sized company secure network&#34;&gt; Linux based servers: CentOS or Ubuntu Office 1: ~100-200 users&lt;/p&gt;</description>
			</item>
			<item>
				<title>Set up Owncloud for personal data management and Android sync</title>
				<link>https://dataprd.com/posts/set-up-owncloud-for-personal-data-management-and-android-sync/</link>
				<pubDate>Thu, 13 Mar 2014 13:09:25 +0000</pubDate>
				<guid>https://dataprd.com/posts/set-up-owncloud-for-personal-data-management-and-android-sync/</guid>
				<description>&lt;p&gt;If privacy is a concern and you&amp;rsquo;d be feeling better to host your own CalDAV and CardDAV (calendar and contact) data but still would like to access it from your smartphone and web, Owncloud is a straightforward open-source tool to use. Remark: hosting your email would only be a possibility if high availability server hardware and internet connection is available for use.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Register a cheap domain with Namecheap and configure &lt;a href=&#34;https://www.namecheap.com/support/knowledgebase/category.aspx/11/dynamic-dns&#34;&gt;DynamicDNS&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Add this script to CRON to regularly update Namecheap on your IP address&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Do this on the Internet interface of your host or OpenWRT router&lt;/li&gt;&#xA;&lt;li&gt;Use this script&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;background-color:#f7f7f7;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;urllib2&lt;span style=&#34;color:#0550ae&#34;&gt;.&lt;/span&gt;urlopen&lt;span style=&#34;color:#1f2328&#34;&gt;(&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;http://dynamicdns.park-your-domain.com/update?host=&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;%s&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;&amp;amp;domain=&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;%s&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;&amp;amp;password=&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;%s&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#0550ae&#34;&gt;%&lt;/span&gt; &lt;span style=&#34;color:#1f2328&#34;&gt;(&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;subdomain&amp;#34;&lt;/span&gt;&lt;span style=&#34;color:#1f2328&#34;&gt;,&lt;/span&gt; &lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;yourdomain.com&amp;#34;&lt;/span&gt;&lt;span style=&#34;color:#1f2328&#34;&gt;,&lt;/span&gt; &lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;hash.by.namecheap..82d9365e23be655&amp;#34;&lt;/span&gt;&lt;span style=&#34;color:#1f2328&#34;&gt;))&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;&#xA;&lt;li&gt;Set it in crontab&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;background-color:#f7f7f7;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;crontab -e&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Add this to run IP update script every 0:05&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#0550ae&#34;&gt;5&lt;/span&gt; &lt;span style=&#34;color:#0550ae&#34;&gt;0&lt;/span&gt; * * * /path/to/script&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;&#xA;&lt;li&gt;Use an Ubuntu Server (14.04 64)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;background-color:#f7f7f7;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Install Owncloud from Repository&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#6639ba&#34;&gt;cd&lt;/span&gt; ~&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;wget http://download.opensuse.org/repositories/isv:ownCloud:community/xUbuntu_14.04/Release.key&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo sh -c &lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;echo &amp;#39;deb http://download.opensuse.org/repositories/isv:/ownCloud:/community/xUbuntu_14.04/ /&amp;#39; &amp;gt;&amp;gt; /etc/apt/sources.list.d/owncloud.list&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo apt-get update&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo apt-get install owncloud&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo apt-get install mysql-server&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Define MySQL password&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Create MySQL table&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo mysql -u root -p &lt;span style=&#34;color:#57606a&#34;&gt;#DefinedPwHere&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#x9;CREATE DATABASE owncloud&lt;span style=&#34;color:#1f2328&#34;&gt;;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#x9;GRANT ALL ON owncloud.* to &lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#39;owncloud&amp;#39;&lt;/span&gt;@&lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#39;localhost&amp;#39;&lt;/span&gt; IDENTIFIED BY &lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#39;database_password&amp;#39;&lt;/span&gt;&lt;span style=&#34;color:#1f2328&#34;&gt;;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#x9;&lt;span style=&#34;color:#6639ba&#34;&gt;exit&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Set file permissions&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo chown -R www-data:www-data /var/www/owncloud&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;find /var/www/owncloud -type d -exec chmod &lt;span style=&#34;color:#0550ae&#34;&gt;750&lt;/span&gt; &lt;span style=&#34;color:#0550ae&#34;&gt;{}&lt;/span&gt; &lt;span style=&#34;color:#1f2328&#34;&gt;;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;find /var/www/owncloud -type f -exec chmod &lt;span style=&#34;color:#0550ae&#34;&gt;640&lt;/span&gt; &lt;span style=&#34;color:#0550ae&#34;&gt;{}&lt;/span&gt; &lt;span style=&#34;color:#1f2328&#34;&gt;;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Enable Apache SSL&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo a2enmod ssl&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo a2ensite default-ssl&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo service apache2 reload&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo a2enmod rewrite&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Generate SSL certs&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo openssl req -x509 -nodes -days &lt;span style=&#34;color:#0550ae&#34;&gt;365&lt;/span&gt; -newkey rsa:2048 -keyout /etc/apache2/ssl/apache.key -out /etc/apache2/ssl/apache.crt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Modify Apache configuration&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo nano /etc/apache2/sites-available/default-ssl&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#57606a&#34;&gt;#Add this to the file being edited with Nano&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&amp;lt;IfModule mod_ssl.c&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &amp;lt;VirtualHost _default_:443&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        ServerName YourServerName&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        ServerAdmin webmaster@localhost&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        DocumentRoot /var/www&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;Directory /&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            Options FollowSymLinks&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            AllowOverride None&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;/Directory&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;Directory /var/www/&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            Options Indexes FollowSymLinks MultiViews&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            AllowOverride None&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            Order allow,deny&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            allow from all&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;/Directory&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        ErrorLog &lt;span style=&#34;color:#0a3069&#34;&gt;${&lt;/span&gt;&lt;span style=&#34;color:#953800&#34;&gt;APACHE_LOG_DIR&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;}&lt;/span&gt;/error.log&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        LogLevel warn&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        CustomLog &lt;span style=&#34;color:#0a3069&#34;&gt;${&lt;/span&gt;&lt;span style=&#34;color:#953800&#34;&gt;APACHE_LOG_DIR&lt;/span&gt;&lt;span style=&#34;color:#0a3069&#34;&gt;}&lt;/span&gt;/ssl_access.log combined&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        SSLEngine on&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        SSLCertificateFile /etc/apache2/ssl/apache.crt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        SSLCertificateKeyFile /etc/apache2/ssl/apache.key&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;FilesMatch &lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;.(cgi|shtml|phtml|php)&lt;/span&gt;$&lt;span style=&#34;color:#0a3069&#34;&gt;&amp;#34;&lt;/span&gt;&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            SSLOptions +StdEnvVars&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;/FilesMatch&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;Directory /usr/lib/cgi-bin&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            SSLOptions +StdEnvVars&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;/Directory&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;Directory /var/www/owncloud&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            Options Indexes FollowSymLinks MultiViews&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            AllowOverride All&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            Order allow,deny&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            Allow from all&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#57606a&#34;&gt;# add any possibly required additional directives here&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#57606a&#34;&gt;# e.g. the Satisfy directive (see below for details):&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            Satisfy Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &amp;lt;/Directory&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &amp;lt;/VirtualHost&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&amp;lt;/IfModule&amp;gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo service apache2 restart&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;&#xA;&lt;li&gt;Access your Owncloud at http://host/owncloud&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Follow install steps, use MySQL, owncloud as database and use your database password as root or owncloud user&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://owncloud.org/seven/&#34;&gt;Use your Owncloud&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Configure your router to forward requests of yourdomain:443 to yourowncloudhost:443 to access Owncloud from the Internet&lt;/li&gt;&#xA;&lt;li&gt;Configure mobile device sync&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://davdroid.bitfire.at/configuration&#34;&gt;Use DAVdroid for your Android phone&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;CalDAV: https://yourowncloudhost/remote.php/caldav/&lt;/li&gt;&#xA;&lt;li&gt;CardDAV: https://yourowncloudhost/remote.php/carddav/&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;As most likely a self-signed certificate is used, set it up with &lt;a href=&#34;http://cadroid.bitfire.at/&#34;&gt;CADroid&lt;/a&gt; accessible from FDroid market&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
	</channel>
</rss>
