4 ms·
Does anyone have a link to a good server hardening guide that they can share here? Specifically and especially when running servers locally, or on things like A
by khalidx 5y ago
Does anyone have a link to a good server hardening guide that they can share here? Specifically and especially when running servers locally, or on things like AWS or DigitalOcean.
So many guides online, and the uninitiated can rarely differentiate between a good one and an outdated one. I’ve used a good one in the past but can’t think of it right now.
- more_corn 5y ago1) minimize your attack surface, only service ports allowed, use a load balancer if available, your security groups can be restricted to your IP address. Better yet you can deploy in a private subnet and use tailscale or a bastion host. 2) automatic security updates (unattended-upgrades on Debian based, yum-cron on rhel based) 3) use ssh keys and named accounts. Disable root and default logins (on aws the default account is ec2-user on Amazon linux and Ubuntu for Ubuntu images) 4) on aws trusted advisor recommends some good account hardening steps.