mirror of
https://github.com/trimstray/the-practical-linux-hardening-guide.git
synced 2025-12-06 09:12:46 +01:00
6e9e9f53120c88b97fd6d2a25d18e6dfbd2549bd
- signed-off-by: trimstray <trimstray@gmail.com>
The Practical Linux Hardening Guide
"Did you know all your doors were locked?" - Riddick (The Chronicles of Riddick)
Created by
trimstray and
contributors
I'm back, work in progress...
Table Of Contents
- Contributing
- Other hardening guides
- Pre install tasks
- Post install tasks
- Bootloader configuration (grub)
- Disk partitions
- Keep system updated
- Package management
- Netfilter ruleset
- TCP wrapper
- Users and groups
- System path permissions
- PAM module
- Limits
- Shadow passwords
- Linux kernel hardening
- Remove unused modules
- Secure shared memory
- IRQ balance
- Disable compilers
- Email notifications
- Backups
- External devices
- Tools
- Services
- Deployment
- Testing configuration
- External resources
Contributing
If you find something which doesn't make sense, or one of these doesn't seem right, or something seems really stupid; please make a pull request or please add valid and well-reasoned opinions about your changes or comments.
Before add pull request please see this.
Other hardening guides
| Distribution | Comment |
|---|---|
| Arch Linux | |
| CentOS Linux | |
| Debian GNU/Linux | old guide |
| Fedora Linux | old guide |
| Red Hat Enterprise | |
| Slackware Linux | limited |
| Ubuntu Linux | limited |
Description
This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
auditcentoschecklistcisguidehardeninglinuxlinux-hardeninglinux-securitymanualopenscappci-dssredhat-enterprise-linuxsecurity
Readme
658 KiB
