IT CHRONICLE
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
[ DOTT. FRANCESCO_RUSSO ]

ICT JOB DIARIESICT JOB DIARIES

List topics List topics
[ DOTT. FRANCESCO_RUSSO ]

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo acquittal è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

Send Large Files via PEC using Google Cloud Storage

Data encryption

In daily ICT consulting, especially when interfacing corporate infrastructures with law firms or Public Administrations, a known and frustrating technical limitation often arises: the attachment size limit of Certified Electronic Mail (PEC). Most Italian PEC providers impose a hard cap of 50 to 100 MB. But how do you proceed when you need to legally transmit log archives, digital forensic images, or entire CAD projects that exceed several gigabytes?

The optimal solution is to decouple the physical transport of the file from its legal certification. In this article, we will explore how to use Python to automate the upload of a large file to Google Cloud Storage, calculate its SHA-256 hash to guarantee integrity, and automatically send a PEC containing the download link and the cryptographic fingerprint.

Solution Architecture

Including the file's cryptographic hash within the body of a PEC message legally binds that specific file (hosted externally) to the certified communication. If even a single bit of the file on Google Cloud Storage were to change, the hash would no longer match the one "notarized" by the PEC delivery receipt.

  • Hash Calculation: We use SHA-256 to generate a unique fingerprint of the local file.
  • Cloud Storage: We upload the file to a GCS bucket and generate a Signed URL or public link for downloading.
  • SMTP Automation: We send the PEC using Python's standard libraries, authenticating on the PEC provider's SMTP server.

The Python Script: Step-by-Step Implementation

To run this script, ensure you have the official Google Cloud library installed:
pip install google-cloud-storage. You will also need a Service Account JSON with write permissions to your bucket.

import hashlib
import smtplib
from email.message import EmailMessage
from google.cloud import storage
import os

# Variable Configuration
FILE_PATH = "C:\\Projects\\huge_file_to_send.zip"
BUCKET_NAME = "your-corporate-bucket"
PEC_SENDER = "your.email@pec.it"
PEC_PASSWORD = "YourSecurePassword"
PEC_RECIPIENT = "recipient@pec.it"
SMTP_SERVER = "smtps.pec.aruba.it" # Example for Aruba PEC
SMTP_PORT = 465

def calculate_sha256(file_path):
    """Calculates the SHA-256 hash of a local file."""
    sha256_hash = hashlib.sha256()
    with open(file_path, "rb") as f:
        # Read the file in chunks to handle large files efficiently
        for byte_block in iter(lambda: f.read(4096), b""):
            sha256_hash.update(byte_block)
    return sha256_hash.hexdigest()

def upload_to_gcs(file_path, bucket_name):
    """Uploads the file to Google Cloud Storage and returns the URL."""
    # Set the environment variable for GCP authentication
    os.environ["GOOGLE_APPLICATION_CREDENTIALS"] = "service_account.json"
    
    storage_client = storage.Client()
    bucket = storage_client.bucket(bucket_name)
    blob_name = os.path.basename(file_path)
    blob = bucket.blob(blob_name)
    
    print(f"[*] Uploading to GCS: {blob_name}...")
    blob.upload_from_filename(file_path)
    
    # Makes the file temporarily accessible
    # Note: For production use Signed URLs for enhanced security
    blob.make_public()
    return blob.public_url

def send_pec(file_url, file_hash):
    """Sends the link and hash via PEC (Certified Email)."""
    msg = EmailMessage()
    msg['Subject'] = "Project Transmission and Cryptographic Hash"
    msg['From'] = PEC_SENDER
    msg['To'] = PEC_RECIPIENT
    
    message_body = f"""
    Dear User,
    
    The requested project is transmitted via virtual attachment. 
    Due to PEC size limitations, the file is available for download at the following secure link:
    
    DOWNLOAD LINK: {file_url}
    
    To ensure the integrity and legal validity of this transmission, the file's cryptographic footprint is provided:
    ALGORITHM: SHA-256
    HASH: {file_hash}
    
    Best regards,
    The System Administrator
    """
    msg.set_content(message_body)
    
    print("[*] Connecting to PEC SMTP server...")
    with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT) as server:
        server.login(PEC_SENDER, PEC_PASSWORD)
        server.send_message(msg)
    print("[+] PEC sent successfully!")

if __name__ == "__main__":
    print("[*] Starting Hash calculation...")
    file_hash = calculate_sha256(FILE_PATH)
    print(f"[+] SHA-256 Hash: {file_hash}")
    
    file_url = upload_to_gcs(FILE_PATH, BUCKET_NAME)
    print(f"[+] File URL: {file_url}")
    
    send_pec(file_url, file_hash)

Conclusions for IT Risk Management

This hybrid infrastructure not only solves a burdensome operational roadblock, but it does so while complying with strict Information Security standards. By utilizing cloud buckets, we can enforce automated Data Retention policies (e.g., auto-deleting the blob after 30 days), while embedding the hash into the PEC transaction legally seals the perimeter of our corporate communication.

Inviare File Grandi via PEC con Google Cloud Storage

Data encryption


Nel quotidiano della consulenza ICT, specialmente quando si interfacciano infrastrutture aziendali con studi legali o Pubblica Amministrazione, emerge un limite tecnico tanto noto quanto frustrante: il limite di dimensione degli allegati della Posta Elettronica Certificata (PEC). La maggior parte dei provider impone un tetto massimo tra i 50 e i 100 MB. Ma come procedere quando è necessario trasmettere per via legale archivi di log, immagini forensi o interi progetti CAD che superano i svariati gigabyte?

La soluzione ottimale consiste nel disaccoppiare il trasporto del file dalla sua certificazione legale. In questo articolo vedremo come automatizzare tramite Python l'upload di un file su Google Cloud Storage, calcolarne l'hash SHA-256 per garantirne l'integrità e inviare automaticamente una PEC contenente il link di download e l'impronta crittografica.

L'Architettura della Soluzione

Includere l'hash crittografico del file all'interno del corpo di un messaggio PEC vincola legalmente quel file (ospitato esternamente) alla comunicazione certificata. Se anche un solo bit del file su Google Cloud Storage dovesse cambiare, l'hash non corrisponderebbe più a quello "notarizzato" dalla ricevuta di consegna della PEC.

  • Calcolo dell'Hash: Utilizziamo SHA-256 per generare l'impronta univoca del file locale.
  • Cloud Storage: Carichiamo il file su un bucket GCS e generiamo un URL firmato (Signed URL) o pubblico per il download.
  • Automazione SMTP: Inviamo la PEC utilizzando le librerie standard di Python, autenticandoci sul server del provider PEC.

Lo Script Python: Implementazione Passo-Passo

Per eseguire questo script, assicurati di avere installato la libreria ufficiale di Google Cloud:
pip install google-cloud-storage. Avrai inoltre bisogno di un Service Account JSON con i permessi di scrittura sul tuo bucket.

import hashlib
import smtplib
from email.message import EmailMessage
from google.cloud import storage
import os

# Configurazione Variabili
FILE_PATH = "C:\\Progetti\\file_enorme_da_inviare.zip"
BUCKET_NAME = "il-tuo-bucket-aziendale"
PEC_SENDER = "tua.email@pec.it"
PEC_PASSWORD = "LaTuaPasswordSicura"
PEC_RECIPIENT = "destinatario@pec.it"
SMTP_SERVER = "smtps.pec.aruba.it" # Esempio per Aruba PEC
SMTP_PORT = 465

def calculate_sha256(file_path):
    """Calcola l'hash SHA-256 di un file locale."""
    sha256_hash = hashlib.sha256()
    with open(file_path, "rb") as f:
        # Legge il file a blocchi per gestire file di grandi dimensioni
        for byte_block in iter(lambda: f.read(4096), b""):
            sha256_hash.update(byte_block)
    return sha256_hash.hexdigest()

def upload_to_gcs(file_path, bucket_name):
    """Carica il file su Google Cloud Storage e restituisce l'URL."""
    # Imposta la variabile d'ambiente per l'autenticazione GCP
    os.environ["GOOGLE_APPLICATION_CREDENTIALS"] = "service_account.json"
    
    storage_client = storage.Client()
    bucket = storage_client.bucket(bucket_name)
    blob_name = os.path.basename(file_path)
    blob = bucket.blob(blob_name)
    
    print(f"[*] Upload in corso su GCS: {blob_name}...")
    blob.upload_from_filename(file_path)
    
    # Rende il file temporaneamente scaricabile (o accessibile)
    # Nota: In produzione usare Signed URLs per maggiore sicurezza
    blob.make_public()
    return blob.public_url

def send_pec(file_url, file_hash):
    """Invia il link e l'hash tramite PEC."""
    msg = EmailMessage()
    msg['Subject'] = "Trasmissione Progetto e Hash Crittografico"
    msg['From'] = PEC_SENDER
    msg['To'] = PEC_RECIPIENT
    
    corpo_messaggio = f"""
    Gentile Utente,
    
    Si trasmette in allegato virtuale il progetto richiesto. 
    A causa delle limitazioni di dimensione della PEC, il file è disponibile per il download al seguente link sicuro:
    
    LINK DI DOWNLOAD: {file_url}
    
    Per garantire l'integrità e la validità legale della trasmissione, si fornisce l'impronta crittografica del file:
    ALGORITMO: SHA-256
    HASH: {file_hash}
    
    Cordiali saluti,
    L'Amministratore di Sistema
    """
    msg.set_content(corpo_messaggio)
    
    print("[*] Connessione al server SMTP PEC...")
    with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT) as server:
        server.login(PEC_SENDER, PEC_PASSWORD)
        server.send_message(msg)
    print("[+] PEC inviata con successo!")

if __name__ == "__main__":
    print("[*] Avvio calcolo Hash...")
    file_hash = calculate_sha256(FILE_PATH)
    print(f"[+] Hash SHA-256: {file_hash}")
    
    file_url = upload_to_gcs(FILE_PATH, BUCKET_NAME)
    print(f"[+] URL File: {file_url}")
    
    send_pec(file_url, file_hash)

Conclusioni per l'IT Risk Management

Questa infrastruttura ibrida non solo risolve un blocco operativo gravoso, ma lo fa rispettando rigorosi standard di Information Security. Utilizzando i bucket cloud possiamo applicare policy di Data Retention automatizzate (ad esempio, l'eliminazione del blob dopo 30 giorni), mentre l'inserimento dell'hash nella transazione PEC sigilla il perimetro legale della nostra comunicazione aziendale.

Guida Pratica: Hypervisor KVM con Web Cockpit su Debian 12

Cockpit Dashboard

Nel precedente articolo abbiamo analizzato la crisi di VMware post-acquisizione Broadcom. È tempo di passare all'azione fornendo una soluzione tecnica robusta ed economica.

In questa guida vi mostrerò come configurare un server Debian 12 (Bookworm) come hypervisor di livello 1 utilizzando KVM (Kernel-based Virtual Machine). Per la gestione, utilizzeremo Cockpit, un'interfaccia web nativa Linux che rende l'amministrazione delle Macchine Virtuali (VM) semplice e intuitiva.

1. Verifica e Aggiornamento del Sistema

Verifichiamo che la CPU supporti le estensioni di virtualizzazione (Intel VT-x o AMD-V):

egrep -c '(vmx|svm)' /proc/cpuinfo

Aggiorniamo il sistema:

sudo apt update && sudo apt full-upgrade -y

2. Installazione dello Stack KVM e Libvirt

Procediamo all'installazione dell'hypervisor e delle librerie di gestione.

sudo apt install qemu-kvm libvirt-clients libvirt-daemon-system bridge-utils virtinst libosinfo-bin -y

3. Configurazione del Networking (Bridge)

Per permettere alle VM di essere visibili nella rete LAN, configuriamo un Network Bridge (es. br0).

ATTENZIONE: Una configurazione errata di `/etc/network/interfaces` può causare la perdita di connettività remota del server. Procedi avendo un accesso fisico o IPMI/iLO.
# /etc/network/interfaces

auto lo
iface lo inet loopback

allow-hotplug enp3s0
iface enp3s0 inet manual

auto br0
iface br0 inet static
    address 192.168.1.100
    netmask 255.255.255.0
    gateway 192.168.1.1
    dns-nameservers 8.8.8.8
    bridge_ports enp3s0
    bridge_stp off
    bridge_fd 0
    bridge_maxwait 0

4. Setup di Cockpit per la Gestione Web

Installiamo l'interfaccia e il plugin per le VM:

sudo apt install cockpit cockpit-machines -y
Colleghiamoci al nostro server andando all'indirizzo https://localhost:9090/system
Buon divertimento a creare le vostre macchine virtuali
Cockpit Dashboard

5. Video Tutorial Completo dell'Installazione

A integrazione della guida, ecco la registrazione tramite Asciinema dell'intero processo. Puoi copiare il testo direttamente dal player.

Conclusioni

Navigando su https://indirizzo_ip_server:9090 avrai ora pieno accesso alla gestione delle tue macchine virtuali. Abbiamo trasformato un server Debian in un potente hypervisor KVM enterprise-grade, senza costi di licenza e senza vendor lock-in.

Practical Guide: KVM Hypervisor with Cockpit Web UI on Debian 12

Cockpit Dashboard

In our previous article, we analyzed the post-Broadcom VMware crisis. It is now time to take action by providing a robust and cost-effective technical solution.

In this guide, we will configure a clean Debian 12 (Bookworm) server as a Type 1 hypervisor using KVM (Kernel-based Virtual Machine). For management, we will use Cockpit, a native Linux web interface that makes administering Virtual Machines simple and intuitive.

1. System Verification and Update

First, verify that the CPU supports virtualization extensions (Intel VT-x or AMD-V):

egrep -c '(vmx|svm)' /proc/cpuinfo

Ensure the system is up to date:

sudo apt update && sudo apt full-upgrade -y

2. Installing the KVM and Libvirt Stack

Proceed with installing the hypervisor and management libraries.

sudo apt install qemu-kvm libvirt-clients libvirt-daemon-system bridge-utils virtinst libosinfo-bin -y

3. Network Configuration (Bridge)

To allow VMs to be visible on the LAN network, we must configure a Network Bridge (e.g., br0).

ATTENTION: An incorrect configuration of `/etc/network/interfaces` can cause loss of remote connectivity. Proceed with caution, preferably having physical or IPMI access.
# /etc/network/interfaces

auto lo
iface lo inet loopback

allow-hotplug enp3s0
iface enp3s0 inet manual

auto br0
iface br0 inet static
    address 192.168.1.100
    netmask 255.255.255.0
    gateway 192.168.1.1
    dns-nameservers 8.8.8.8
    bridge_ports enp3s0
    bridge_stp off
    bridge_fd 0
    bridge_maxwait 0

4. Cockpit Setup for Web Management

Install the base package and the specific module for VM management:

sudo apt install cockpit cockpit-machines -y

5. Complete Installation Video Tutorial

Integrating the textual guide, here is an Asciinema recording showing the entire process. You can copy text directly from the player.

Conclusions

By navigating to https://server_ip_address:9090, you now have full access to manage your virtual machines. We have transformed a standard Debian server into a powerful enterprise-grade KVM hypervisor, without licensing costs and vendor lock-in.




The VMware Earthquake: Broadcom’s Licensing Impact and the Open Source Exodus

VMWAREEscape


Broadcom’s acquisition of VMware was not merely a financial transaction; it was a seismic event that redefined the boundaries of the enterprise virtualization market. For years the de facto standard in data centers of all sizes, VMware is now experiencing a profound crisis of trust from its user base.

At IT Chronicle, we analyze infrastructural evolutions daily, and what we are observing in the field is unprecedented: a massive acceleration towards "de-VMware-ization" strategies. In this article, we will analyze the technical and economic causes of this exodus and why Open Source is no longer just a cheaper alternative, but a strategic necessity.

A Technical Analysis of the "Licensing Problem"

The shift in direction imposed by Broadcom is based on two pillars that have made remaining on the platform unsustainable for many organizations:

1. The Forced Transition to Subscriptions

Broadcom has eliminated the option to purchase perpetual licenses (SnS). Now, the software is only available via subscription. For companies that had planned long-term CAPEX investments, this translates into a drastic increase in OPEX, with renewal costs often tripling compared to the past.

2. Aggressive Portfolio Simplification

Dozens of standalone products have been consolidated into just two main suites: VMware Cloud Foundation (VCF) and VMware vSphere Foundation (VVF).

The technical-economic problem is evident: a customer requiring only the basic hypervisor (ESXi) and centralized management (vCenter) is now forced to purchase vSAN, NSX, and the Aria suite, even if they have no intention of using them. This "commercial over-provisioning" has made the TCO unjustifiable.

Consequences in the Field: The Tesco Case

The impact does not only concern SMBs. Giants of the caliber of Tesco, the British supermarket chain, have initiated plans to migrate thousands of hosts away from VMware. When players of this magnitude face the technical risks of an infrastructural migration, the signal to the market is unmistakable: the risk of vendor lock-in with Broadcom is considered higher than the migration risk.

Beyond VMware: Open Source Alternatives

The question our clients ask us is no longer "if" to migrate, but "where". The Linux-based ecosystem offers mature and standardized solutions.

  • Proxmox VE: Debian-based, gaining enormous popularity due to its "all-in-one" interface similar to vCenter.
  • XCP-ng: Solid and enterprise-grade for those coming from the Xen world.
  • KVM + Cockpit: The native Linux technology that powers the largest public clouds. Raw and incredibly high-performing.

For organizations seeking bare-metal stability without the complexity of hyper-converged clusters, the combination of Debian, KVM, and Cockpit represents the ideal solution. In our next article, we will provide a complete deployment guide for this stack.