{"id":12585,"date":"2021-12-14T13:00:52","date_gmt":"2021-12-14T21:00:52","guid":{"rendered":"https:\/\/www.couchbase.com\/blog\/?p=12585"},"modified":"2025-06-13T23:06:12","modified_gmt":"2025-06-14T06:06:12","slug":"couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family","status":"publish","type":"post","link":"https:\/\/www.couchbase.com\/blog\/pt\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/","title":{"rendered":"Couchbase Server 7.0.2 Aplicar TLS, HSTS e aplicar a fam\u00edlia de endere\u00e7os IP"},"content":{"rendered":"<p><em><span style=\"font-weight: 400;\">Nesta postagem do blog, apresentarei tr\u00eas novos recursos do Couchbase Server 7.0.2 (\"Servidor\") para ajudar os administradores a implantar o Couchbase Server de forma segura: Enforce TLS, HSTS e Enforce IP Address Family.\u00a0<\/span><\/em><\/p>\n<p><span style=\"font-weight: 400;\">Ao implantar um cluster do Couchbase Server, uma pr\u00e1tica recomendada \u00e9 evitar que um n\u00f3 do servidor seja conectado diretamente \u00e0 Internet.  Aconselhamos que os clientes implantem um firewall no per\u00edmetro de rede do cluster, bem como um firewall em cada n\u00f3 do servidor. Esses firewalls devem ser configurados para bloquear todas as portas inseguras, portas de servi\u00e7os que n\u00e3o estejam em uso e fam\u00edlias inteiras de endere\u00e7os IP que n\u00e3o estejam em uso.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00c9 nesse ponto que esses tr\u00eas novos recursos entram em a\u00e7\u00e3o. Os administradores devem implementar firewalls e permitir apenas portas espec\u00edficas, conforme necess\u00e1rio. As novas configura\u00e7\u00f5es fornecem prote\u00e7\u00f5es adicionais que atingem o mesmo objetivo, no que alguns podem chamar de controle compensat\u00f3rio.<\/span><\/p>\n<h4><span style=\"font-weight: 400;\">Aplicar TLS<\/span><\/h4>\n<p><span style=\"font-weight: 400;\">O primeiro novo recurso \u00e9 o refor\u00e7o da criptografia de rede TLS. No Couchbase Server 6.5.0, introduzimos <\/span><a href=\"https:\/\/www.couchbase.com\/blog\/pt\/node-to-node-encryption-with-couchbase-server-6-5\/\"><span style=\"font-weight: 400;\">Criptografia de n\u00f3 para n\u00f3<\/span><\/a><span style=\"font-weight: 400;\">.  Com a criptografia de n\u00f3 para n\u00f3 ativada, permitimos a configura\u00e7\u00e3o de como os dados s\u00e3o tratados entre os n\u00f3s do Couchbase Server.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Opcionalmente, os dados de controle s\u00e3o configurados para serem criptografados ou todos os dados entre os n\u00f3s s\u00e3o criptografados.  Isso garante que o tr\u00e1fego de rede do cluster entre n\u00f3s seja seguro e, se os administradores implantarem aplicativos para se conectarem apenas ao cluster usando conex\u00f5es de rede criptografadas, todos os dados do banco de dados na rede ser\u00e3o criptografados.  Nesse ponto, o administrador implantaria um firewall para bloquear as portas de rede que lidam com o tr\u00e1fego de rede n\u00e3o criptografado ou de texto simples.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Com o novo recurso Enforce TLS, adicionamos uma terceira op\u00e7\u00e3o \u00e0 configura\u00e7\u00e3o de criptografia do cluster, para ser rigoroso.  Quando essa op\u00e7\u00e3o est\u00e1 ativada, o \u00fanico tr\u00e1fego de rede permitido no cluster \u00e9 seguro e criptografado.  Isso se aplica a tudo, desde a interface do usu\u00e1rio da Web, as ferramentas de linha de comando, o acesso a aplicativos e o tr\u00e1fego de rede entre os n\u00f3s do cluster, mas n\u00e3o se aplica \u00e0s interfaces de loopback locais.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">O Enforce TLS pode ser facilmente implementado usando o comando CLI:<\/span><\/p>\n<p><em><span style=\"font-weight: 400;\">couchbase-cli setting-security -cluster-encryption-level strict<\/span><\/em><\/p>\n<h4><span style=\"font-weight: 400;\">Cabe\u00e7alho de transporte seguro HTTP (HSTS)<\/span><\/h4>\n<p><span style=\"font-weight: 400;\">Juntamente com a configura\u00e7\u00e3o Enforce TLS, h\u00e1 tamb\u00e9m uma nova configura\u00e7\u00e3o para ativar opcionalmente um cabe\u00e7alho HTTP Secure Transport Header (HSTS).  O cabe\u00e7alho HTTP Strict Transport Security informa ao navegador da Web de um usu\u00e1rio que ele nunca deve carregar um site usando HTTP e deve converter automaticamente todas as tentativas de acesso ao site usando HTTP para solicita\u00e7\u00f5es HTTPS.  Isso \u00e9 \u00fatil se voc\u00ea quiser que todo o acesso \u00e0 interface do usu\u00e1rio ocorra somente por HTTPS.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Quando um navegador sabe que um dom\u00ednio ativou o HSTS, ele faz duas coisas:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ele sempre usa um <\/span><span style=\"font-weight: 400;\">https:\/\/<\/span><span style=\"font-weight: 400;\"> mesmo ao clicar em uma conex\u00e3o <\/span><span style=\"font-weight: 400;\">https:\/\/<\/span><span style=\"font-weight: 400;\"> ou ap\u00f3s digitar um dom\u00ednio na barra de localiza\u00e7\u00e3o sem especificar um protocolo.\u00a0\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ele remove a capacidade de os usu\u00e1rios clicarem nos avisos sobre certificados inv\u00e1lidos.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Um aspecto a ser lembrado sobre o Couchbase Server: por padr\u00e3o, a porta n\u00e3o TLS da interface do usu\u00e1rio \u00e9 <\/span><em><span style=\"font-weight: 400;\">8091<\/span><\/em><span style=\"font-weight: 400;\"> enquanto a porta TLS \u00e9 <\/span><em><span style=\"font-weight: 400;\">18091<\/span><\/em><span style=\"font-weight: 400;\">.  Com o HSTS ativado, todas as solicita\u00e7\u00f5es de <\/span><em><span style=\"font-weight: 400;\">https:\/\/cluster:8091<\/span><\/em><span style=\"font-weight: 400;\"> tentar\u00e1 acessar automaticamente o <\/span><em><span style=\"font-weight: 400;\">https:\/\/cluster:8091<\/span><\/em><span style=\"font-weight: 400;\">e n\u00e3o o correto <\/span><em><span style=\"font-weight: 400;\">18091<\/span><\/em><span style=\"font-weight: 400;\"> porto.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">O HSTS pode ser ativado com o comando CLI:<\/span><\/p>\n<p><em><span style=\"font-weight: 400;\">\u00a0<\/span><span style=\"font-weight: 400;\">couchbase-cli setting-security -hsts-max-age\u00a0\u00a0\u00a0\u00a0<\/span><\/em><\/p>\n<p><span style=\"font-weight: 400;\">Configurar o <\/span><span style=\"font-weight: 400;\">Idade m\u00e1xima<\/span><span style=\"font-weight: 400;\"> para a quantidade de tempo, em segundos, que o navegador deve lembrar para acessar a interface do usu\u00e1rio do Couchbase somente usando HTTPS.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Voc\u00ea tamb\u00e9m pode optar por ativar\/desativar o HSTS <\/span><em><span style=\"font-weight: 400;\">pr\u00e9-carga<\/span><\/em><span style=\"font-weight: 400;\"> e <\/span><em><span style=\"font-weight: 400;\">includeSubDomains<\/span><\/em><span style=\"font-weight: 400;\"> diretivas.<\/span><\/p>\n<h4><span style=\"font-weight: 400;\">Aplicar a fam\u00edlia de endere\u00e7os IP<\/span><\/h4>\n<p><span style=\"font-weight: 400;\">Tamb\u00e9m aconselhamos os clientes a usar um firewall e bloquear todo o tr\u00e1fego de rede para portas e protocolos que n\u00e3o sejam necess\u00e1rios, incluindo fam\u00edlias inteiras de endere\u00e7os IP.  Por exemplo, se a sua organiza\u00e7\u00e3o usa somente endere\u00e7os IPv4, voc\u00ea deve bloquear no n\u00edvel do firewall todo o acesso a endere\u00e7os IPv6 nos n\u00f3s do Couchbase Server.  Para adicionar alguns controles de compensa\u00e7\u00e3o, adicionamos op\u00e7\u00f5es \u00e0s configura\u00e7\u00f5es de Fam\u00edlia de endere\u00e7os IP.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">No exemplo anterior, se uma organiza\u00e7\u00e3o s\u00f3 usa endere\u00e7os IPv4 e usou o comando CLI:<\/span><\/p>\n<p><em><span style=\"font-weight: 400;\">couchbase-cli ip-family -set -ipv4<\/span><\/em><\/p>\n<p><span style=\"font-weight: 400;\">...o cluster usaria o IPv4 para a comunica\u00e7\u00e3o entre os n\u00f3s, mas ainda seria poss\u00edvel que o tr\u00e1fego passasse pelo IPv6 dos clientes, a menos que houvesse um firewall para impedir isso.  Se o endere\u00e7o IPv4 n\u00e3o pudesse ser vinculado, o n\u00f3 sofreria uma falha autom\u00e1tica.  O novo <\/span><em><span style=\"font-weight: 400;\">-ipv4only<\/span><\/em><span style=\"font-weight: 400;\"> instruir\u00e1 o cluster a sempre tentar vincular-se a interfaces IPv4 e nunca permitir comunica\u00e7\u00f5es de rede IPv6.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Como alternativa, h\u00e1 tamb\u00e9m <\/span><em><span style=\"font-weight: 400;\">-ipv6 <\/span><\/em><span style=\"font-weight: 400;\">e <\/span><em><span style=\"font-weight: 400;\">-ipv6only<\/span><\/em><span style=\"font-weight: 400;\"> que alcan\u00e7am o mesmo resultado, mas para a fam\u00edlia de endere\u00e7os IPv6 em vez da fam\u00edlia de endere\u00e7os IPv4.  Se <\/span><em><span style=\"font-weight: 400;\">-ipv4<\/span><\/em><span style=\"font-weight: 400;\"> e <\/span><em><span style=\"font-weight: 400;\">-ipv6<\/span><\/em><span style=\"font-weight: 400;\"> estiverem definidas, ambas as interfaces dever\u00e3o ser vinculadas e, se uma delas estiver dispon\u00edvel, o sistema dever\u00e1 us\u00e1-la e iniciar.\u00a0\u00a0\u00a0<\/span><\/p>\n<h4><span style=\"font-weight: 400;\">Conclus\u00e3o<\/span><\/h4>\n<p><span style=\"font-weight: 400;\">Neste artigo, mostrei a voc\u00ea o Enforce TLS, o HSTS e o Enforce IP Address Family.  Todos esses recursos de seguran\u00e7a t\u00eam como objetivo criar uma barreira robusta para os invasores que tentam comprometer seus sistemas. Se a seguran\u00e7a for importante para voc\u00ea, recomendo a leitura de algumas publica\u00e7\u00f5es adicionais no blog sobre nossos recursos de seguran\u00e7a que ajudam a manter seus dados do Couchbase protegidos.\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><a href=\"https:\/\/www.couchbase.com\/blog\/pt\/tls-1-3-encryption\/\"><span style=\"font-weight: 400;\">A criptografia TLS 1.3 chega ao Couchbase Server 7.0<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\"><a href=\"https:\/\/www.couchbase.com\/blog\/pt\/node-to-node-encryption-with-couchbase-server-6-5\/\"><span style=\"font-weight: 400;\">Criptografia n\u00f3 a n\u00f3 com o Couchbase Server 6.5<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\"><a href=\"https:\/\/www.couchbase.com\/blog\/pt\/ipv6-galore-couchbase\/\"><span style=\"font-weight: 400;\">IPv6 em abund\u00e2ncia com o Couchbase<\/span><\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>In this blog post, I will introduce three new features in Couchbase Server 7.0.2 (&#8220;Server&#8221;) to help administrators deploy Couchbase Server in a secure manner: Enforce TLS, HSTS, and Enforce IP Address Family.\u00a0 When deploying a Couchbase Server cluster, a [&hellip;]<\/p>","protected":false},"author":1864,"featured_media":12589,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[1816,1813],"tags":[8907,1666,2186,9262],"ppma_author":[8928],"class_list":["post-12585","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-couchbase-server","category-security","tag-couchbase-server-7-0","tag-encryption","tag-ipv6","tag-tls-encryption"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.1 (Yoast SEO v26.1.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Couchbase Server 7.0.2 Enforce TLS, HSTS &amp; Enforce IP Address Family - The Couchbase Blog<\/title>\n<meta name=\"description\" content=\"Learn how Couchbase Server 7.0.2 security features include making a robust barrier for attackers who try to compromise your systems\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.couchbase.com\/blog\/pt\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Couchbase Server 7.0.2 Enforce TLS, HSTS &amp; Enforce IP Address Family\" \/>\n<meta property=\"og:description\" content=\"Learn how Couchbase Server 7.0.2 security features include making a robust barrier for attackers who try to compromise your systems\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.couchbase.com\/blog\/pt\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/\" \/>\n<meta property=\"og:site_name\" content=\"The Couchbase Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-14T21:00:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-14T06:06:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1707\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ian McCloy, Director Product Management\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ian McCloy, Director Product Management\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/\"},\"author\":{\"name\":\"Ian McCloy, Director Product Management, Couchbase\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/#\/schema\/person\/7e8c834bce5128ad6cd764cd1c4cea19\"},\"headline\":\"Couchbase Server 7.0.2 Enforce TLS, HSTS &#038; Enforce IP Address Family\",\"datePublished\":\"2021-12-14T21:00:52+00:00\",\"dateModified\":\"2025-06-14T06:06:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/\"},\"wordCount\":860,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg\",\"keywords\":[\"Couchbase Server 7.0\",\"Encryption\",\"IPv6\",\"TLS encryption\"],\"articleSection\":[\"Couchbase Server\",\"Security\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/\",\"url\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/\",\"name\":\"Couchbase Server 7.0.2 Enforce TLS, HSTS & Enforce IP Address Family - The Couchbase Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg\",\"datePublished\":\"2021-12-14T21:00:52+00:00\",\"dateModified\":\"2025-06-14T06:06:12+00:00\",\"description\":\"Learn how Couchbase Server 7.0.2 security features include making a robust barrier for attackers who try to compromise your systems\",\"breadcrumb\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage\",\"url\":\"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg\",\"contentUrl\":\"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg\",\"width\":2560,\"height\":1707,\"caption\":\"Connect 2022 - Nomination for customer awards\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.couchbase.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Couchbase Server 7.0.2 Enforce TLS, HSTS &#038; Enforce IP Address Family\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/#website\",\"url\":\"https:\/\/www.couchbase.com\/blog\/\",\"name\":\"The Couchbase Blog\",\"description\":\"Couchbase, the NoSQL Database\",\"publisher\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.couchbase.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/#organization\",\"name\":\"The Couchbase Blog\",\"url\":\"https:\/\/www.couchbase.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/2023\/04\/admin-logo.png\",\"contentUrl\":\"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/2023\/04\/admin-logo.png\",\"width\":218,\"height\":34,\"caption\":\"The Couchbase Blog\"},\"image\":{\"@id\":\"https:\/\/www.couchbase.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/#\/schema\/person\/7e8c834bce5128ad6cd764cd1c4cea19\",\"name\":\"Ian McCloy, Director Product Management, Couchbase\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/www.couchbase.com\/blog\/#\/schema\/person\/image\/97dd714a3242521ce9dcea0d96550c5f\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/41f65bee70b5e03e46ae996303a13060d366d405ecb235ff5493d4f1ac3a6f3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/41f65bee70b5e03e46ae996303a13060d366d405ecb235ff5493d4f1ac3a6f3d?s=96&d=mm&r=g\",\"caption\":\"Ian McCloy, Director Product Management, Couchbase\"},\"description\":\"Ian McCloy is the Director of the Platform and Security Product Management Group for Couchbase and lives in the United Kingdom. His dedicated team is responsible for the Reliability, Availability, Serviceability and Security architecture of Couchbase Server and the SaaS Database, Capella. This team also own cloud-native platforms like the Couchbase Kubernetes Autonomous Operator. Ian has a vast range of experience as a Software Engineer, Technical Support Engineer, Quality Assurance Engineer and Systems Administrator. Ian has led global technical teams for the majority of his 20 year professional career and holds several patents in the areas of information security, virtualisation and hardware design. https:\/\/www.linkedin.com\/in\/ianmccloy\/\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/ianmccloy\/\"],\"url\":\"https:\/\/www.couchbase.com\/blog\/pt\/author\/ian-mccloycouchbase-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Couchbase Server 7.0.2 Enforce TLS, HSTS & Enforce IP Address Family - The Couchbase Blog","description":"Saiba como os recursos de seguran\u00e7a do Couchbase Server 7.0.2 incluem a cria\u00e7\u00e3o de uma barreira robusta para os invasores que tentam comprometer seus sistemas","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.couchbase.com\/blog\/pt\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/","og_locale":"pt_BR","og_type":"article","og_title":"Couchbase Server 7.0.2 Enforce TLS, HSTS & Enforce IP Address Family","og_description":"Learn how Couchbase Server 7.0.2 security features include making a robust barrier for attackers who try to compromise your systems","og_url":"https:\/\/www.couchbase.com\/blog\/pt\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/","og_site_name":"The Couchbase Blog","article_published_time":"2021-12-14T21:00:52+00:00","article_modified_time":"2025-06-14T06:06:12+00:00","og_image":[{"width":2560,"height":1707,"url":"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg","type":"image\/jpeg"}],"author":"Ian McCloy, Director Product Management","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ian McCloy, Director Product Management","Est. reading time":"4 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#article","isPartOf":{"@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/"},"author":{"name":"Ian McCloy, Director Product Management, Couchbase","@id":"https:\/\/www.couchbase.com\/blog\/#\/schema\/person\/7e8c834bce5128ad6cd764cd1c4cea19"},"headline":"Couchbase Server 7.0.2 Enforce TLS, HSTS &#038; Enforce IP Address Family","datePublished":"2021-12-14T21:00:52+00:00","dateModified":"2025-06-14T06:06:12+00:00","mainEntityOfPage":{"@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/"},"wordCount":860,"commentCount":0,"publisher":{"@id":"https:\/\/www.couchbase.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage"},"thumbnailUrl":"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg","keywords":["Couchbase Server 7.0","Encryption","IPv6","TLS encryption"],"articleSection":["Couchbase Server","Security"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/","url":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/","name":"Couchbase Server 7.0.2 Enforce TLS, HSTS & Enforce IP Address Family - The Couchbase Blog","isPartOf":{"@id":"https:\/\/www.couchbase.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage"},"image":{"@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage"},"thumbnailUrl":"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg","datePublished":"2021-12-14T21:00:52+00:00","dateModified":"2025-06-14T06:06:12+00:00","description":"Saiba como os recursos de seguran\u00e7a do Couchbase Server 7.0.2 incluem a cria\u00e7\u00e3o de uma barreira robusta para os invasores que tentam comprometer seus sistemas","breadcrumb":{"@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#primaryimage","url":"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg","contentUrl":"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/sites\/1\/2021\/12\/dylan-gillis-KdeqA3aTnBY-unsplash-scaled.jpg","width":2560,"height":1707,"caption":"Connect 2022 - Nomination for customer awards"},{"@type":"BreadcrumbList","@id":"https:\/\/www.couchbase.com\/blog\/couchbase-server-7-0-2-enforce-tls-hsts-enforce-ip-address-family\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.couchbase.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Couchbase Server 7.0.2 Enforce TLS, HSTS &#038; Enforce IP Address Family"}]},{"@type":"WebSite","@id":"https:\/\/www.couchbase.com\/blog\/#website","url":"https:\/\/www.couchbase.com\/blog\/","name":"Blog do Couchbase","description":"Couchbase, o banco de dados NoSQL","publisher":{"@id":"https:\/\/www.couchbase.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.couchbase.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/www.couchbase.com\/blog\/#organization","name":"Blog do Couchbase","url":"https:\/\/www.couchbase.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/www.couchbase.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/2023\/04\/admin-logo.png","contentUrl":"https:\/\/www.couchbase.com\/blog\/wp-content\/uploads\/2023\/04\/admin-logo.png","width":218,"height":34,"caption":"The Couchbase Blog"},"image":{"@id":"https:\/\/www.couchbase.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.couchbase.com\/blog\/#\/schema\/person\/7e8c834bce5128ad6cd764cd1c4cea19","name":"Ian McCloy, diretor de gerenciamento de produtos, Couchbase","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/www.couchbase.com\/blog\/#\/schema\/person\/image\/97dd714a3242521ce9dcea0d96550c5f","url":"https:\/\/secure.gravatar.com\/avatar\/41f65bee70b5e03e46ae996303a13060d366d405ecb235ff5493d4f1ac3a6f3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/41f65bee70b5e03e46ae996303a13060d366d405ecb235ff5493d4f1ac3a6f3d?s=96&d=mm&r=g","caption":"Ian McCloy, Director Product Management, Couchbase"},"description":"Ian McCloy \u00e9 diretor do grupo de gerenciamento de produtos de plataforma e seguran\u00e7a da Couchbase e mora no Reino Unido. Sua equipe dedicada \u00e9 respons\u00e1vel pela arquitetura de confiabilidade, disponibilidade, capacidade de servi\u00e7o e seguran\u00e7a do Couchbase Server e do banco de dados SaaS, Capella. Essa equipe tamb\u00e9m \u00e9 propriet\u00e1ria de plataformas nativas da nuvem, como o Operador Aut\u00f4nomo Kubernetes do Couchbase. Ian tem uma vasta experi\u00eancia como engenheiro de software, engenheiro de suporte t\u00e9cnico, engenheiro de garantia de qualidade e administrador de sistemas. Ian liderou equipes t\u00e9cnicas globais durante a maior parte de sua carreira profissional de 20 anos e possui v\u00e1rias patentes nas \u00e1reas de seguran\u00e7a da informa\u00e7\u00e3o, virtualiza\u00e7\u00e3o e design de hardware. https:\/\/www.linkedin.com\/in\/ianmccloy\/","sameAs":["https:\/\/www.linkedin.com\/in\/ianmccloy\/"],"url":"https:\/\/www.couchbase.com\/blog\/pt\/author\/ian-mccloycouchbase-com\/"}]}},"authors":[{"term_id":8928,"user_id":1864,"is_guest":0,"slug":"ian-mccloycouchbase-com","display_name":"Ian McCloy, Director Product Management","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/41f65bee70b5e03e46ae996303a13060d366d405ecb235ff5493d4f1ac3a6f3d?s=96&d=mm&r=g","author_category":"","last_name":"McCloy, Director Product Management","first_name":"Ian","job_title":"","user_url":"","description":"Ian McCloy \u00e9 diretor do grupo de gerenciamento de produtos de plataforma e seguran\u00e7a da Couchbase e mora no Reino Unido.  Sua equipe dedicada \u00e9 respons\u00e1vel pela arquitetura de confiabilidade, disponibilidade, capacidade de servi\u00e7o e seguran\u00e7a do Couchbase Server e do banco de dados SaaS, Capella.  Essa equipe tamb\u00e9m \u00e9 propriet\u00e1ria de plataformas nativas da nuvem, como o Operador Aut\u00f4nomo Kubernetes do Couchbase.  Ian tem uma vasta experi\u00eancia como engenheiro de software, engenheiro de suporte t\u00e9cnico, engenheiro de garantia de qualidade e administrador de sistemas. Ian liderou equipes t\u00e9cnicas globais durante a maior parte de sua carreira profissional de 20 anos e det\u00e9m v\u00e1rias patentes nas \u00e1reas de seguran\u00e7a da informa\u00e7\u00e3o, virtualiza\u00e7\u00e3o e design de hardware. https:\/\/www.linkedin.com\/in\/ianmccloy\/"}],"_links":{"self":[{"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/posts\/12585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/users\/1864"}],"replies":[{"embeddable":true,"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/comments?post=12585"}],"version-history":[{"count":0,"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/posts\/12585\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/media\/12589"}],"wp:attachment":[{"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/media?parent=12585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/categories?post=12585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/tags?post=12585"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.couchbase.com\/blog\/pt\/wp-json\/wp\/v2\/ppma_author?post=12585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}