Skip to content

Linux Hardening

Reducing the attack surface of Linux hosts through configuration.

Why It Matters

Linux servers run a large share of internet-facing infrastructure, so hardening them directly reduces exposure. As with Windows, most of the work is removing defaults that favor convenience over security.

Reference

Baselines

Baseline Source
CIS Benchmarks CIS Linux Benchmarks
DISA STIGs DoD STIGs
Vendor guides Ubuntu, RHEL, and SUSE security guides

Key Areas

Area Controls
Accounts Strong password policy, no shared accounts, lock unused accounts
SSH Key-based auth, disable root login (PermitRootLogin no), disable password auth where possible, change defaults
Privilege Least-privilege sudo rules, audit /etc/sudoers
Services Disable and remove unneeded services and packages
Firewall ufw or firewalld with a default-deny inbound policy
Updates Timely patching, unattended security updates
Logging Centralize logs, enable auditd for key events
File integrity AIDE or similar for critical files
MAC SELinux or AppArmor in enforcing mode

Quick Checks

sudo ss -tulnp              # listening services
sudo grep PermitRootLogin /etc/ssh/sshd_config
sudo ufw status verbose     # firewall state
systemctl list-unit-files --state=enabled   # enabled services

How I Use It

I apply a CIS benchmark with a tool like OpenSCAP or an Ansible role rather than by hand, then tune exceptions. SSH and the firewall are the first priorities on any internet-facing host, followed by trimming services and turning on auditd.

Resources