3 ms·
what would be included in a "basic hardening"?
by frederikvs 10y ago
what would be included in a "basic hardening"?
- jlgaddis 10y agoThe "Center for Internet Security" Benchmarks [0] -- such as the one for Ubuntu 16.04 (PDF) [1] -- address your question. The DISA IASE [2] publishes hundreds of "Security Technical Implementation Guides" (STIGs) for various operating systems (including several Linux distributions [3]), software applications, networking devices, and so on. The OpenSCAP [4] Security Guides [5] are also a good reference. They are primarily aimed at compliance w/ security requirements (C2S, PCI-DSS, USGCB) -- for example, the "U.S. Government Commercial Cloud Services (C2S)" [6]. I don't 100% fully implement any of these, but I have a lot of RHEL and CentOS boxes publicly accessible on the Internet and they don't become accessible until they've had the majority of these recommendations implemented. P.S. Look around. There are tons of shell scripts, Ansible roles, Puppet modules, etc., that will take care of 90% of this for you. There's no excuse for having public-facing machines that aren't locked down. [0]: https://benchmarks.cisecurity.org/downloads/benchmarks/ https://benchmarks.cisecurity.org/downloads/benchmarks/ [1]: https://benchmarks.cisecurity.org/tools2/linux/cis_ubuntu_linux_16.04_lts_benchmark_v1.0.0.pdf https://benchmarks.cisecurity.org/tools2/linux/cis_ubuntu_li... [2]: http://iase.disa.mil/Pages/index.aspx http://iase.disa.mil/Pages/index.aspx [3]: http://iase.disa.mil/stigs/os/unix-linux/Pages/index.aspx http://iase.disa.mil/stigs/os/unix-linux/Pages/index.aspx [4]: https://github.com/OpenSCAP/scap-security-guide/ https://github.com/OpenSCAP/scap-security-guide/ [5]: https://www.open-scap.org/security-policies/choosing-policy/ https://www.open-scap.org/security-policies/choosing-policy/ [6]: http://static.open-scap.org/ssg-guides/ssg-rhel7-guide-C2S.html http://static.open-scap.org/ssg-guides/ssg-rhel7-guide-C2S.h...
- frederikvs 10y agoThanks, very interesting reads. Makes one wonder why these things aren't default on a linux distro... As an embedded software developer it's a bit inconvenient that it's all focused towards the big distributions (ubuntu, RHEL, ...), but still interesting input for securing an embedded linux device :-)
- jlgaddis 10y agoWhile these guides are aimed at specific distributions, many (most?) of the concepts "translate" quite easily to other flavors of Linux. sysctl's, for example, might be configured in a different file but they will still exist and work the same (disclaimer: usually!).