ADX04 - Automic Hardening - System

In this post, you’ll harden an Automic Windows V24 lab environment from a systems perspective: You’ll start with the official hardening documentation and implement key settings for HTTPS, session timeouts, password policies, and login auditing. The focus is on practical testing rather than pure theory. You’ll learn how to make hardening measures measurable and how to evaluate security-related access later in reviews.

Automic hardening does not start with individual switches, but with a clear assessment of the reachable web and API interfaces. In this article you will learn how to examine an Automic Windows V24 lab environment from a systems perspective and implement concrete hardening measures in a traceable way. The focus is on AWI, REST/JCP, TLS, session timeouts, password rules, security auditing and optional AWI Security Headers.

You start with the official Automic documentation on security and hardening. Then you check AWI, JCP and REST component by component. This lets you determine whether encrypted access paths are already working and whether unencrypted accesses are still open. Afterwards you enable REST/JCP via the Automation-Engine configuration, harden AWI via configuration.properties, reduce open session risks and evaluate password and default access settings.

This article is especially helpful if you want to know:

  • how to enable HTTPS on AWI and REST

  • how USER_SESSION_TIMEOUT, password parameters and login auditing contribute to system hardening

  • what role OBJECT_AUDIT, security audit categories, revision reports and user activities play in a security review

By the end you will be able not only to configure Automic hardening but also to demonstrate it: with before-and-after checks, clear observations, visible audit events and analyzable reports. This makes the article suitable for administrators, operators and technical stakeholders who want to operate Automic Automation more securely and document hardening measures in a traceable way.

Learn Automic with PEM!

Would you like to learn more about Automic without having to travel across the country for workshops? At PEM, you decide when and how you want to continue your education! In interactive courses, tutorials and videos, you will learn everything you need to know about Automic – and more! And we are always there for you via comment function or email.

Does that sound interesting? Then get started today with PEM, Automic Training 2.0 and year-round Automic support!

More about PEM
Start now

FAQ about Automic Training on PEM

PEM is the most innovative and fastest growing Automic learning platform. It offers PEM members a comprehensive range of online training courses that can be accessed 24/7 and from anywhere. The platform includes dozens of videos and interactive courses and is aimed at beginners and professionals alike.