Differences between revisions 7 and 8
Revision 7 as of 2011-07-19 01:14:34
Size: 0
Editor: ?UJ-x51
Comment:
Revision 8 as of 2011-11-03 08:16:06
Size: 1152
Editor: ?dbp
Comment: System Hardening
Deletions are marked like this. Additions are marked like this.
Line 1: Line 1:
#language en
~-[[DebianWiki/EditorGuide#translation|Translation(s)]]: none-~
----
The following are some system hardening recommendation from security auditor for default configuration of Debian GNU/Linux. You may apply if appropriate.

## If your page gets really long, uncomment this Table of Contents
## <<TableOfContents(2)>>

== Login Credential ==

/etc/login.defs: Enforce changing password after limited days

PASS_MAX_DAYS 93

/etc/ssh/sshd_config: Disable root login as many brute force attack target to 'root' user

PermitRootLogin no

/etc/pam.d/common-password: Enforce using strong password (Requires libpam-cracklib)

password required pam_unix.so nullok obscure md5 remember=11 min=6

== Miscellaneous ==

/etc/issue, /etc/issue.net: Set warning message and remove server identity such as OS version

WARNING: This system is restricted access to authorized person only.

## You can add other _helpful_ links here.
##== See also ==
##----

## If this page belongs to an existing Category, add it below.
## CategorySomething | CategoryAnother
----
CategorySystemSecurity CategorySystemSecurity

Translation(s): none


The following are some system hardening recommendation from security auditor for default configuration of Debian GNU/Linux. You may apply if appropriate.

Login Credential

/etc/login.defs: Enforce changing password after limited days

PASS_MAX_DAYS 93

/etc/ssh/sshd_config: Disable root login as many brute force attack target to 'root' user

?PermitRootLogin no

/etc/pam.d/common-password: Enforce using strong password (Requires libpam-cracklib)

password required pam_unix.so nullok obscure md5 remember=11 min=6

Miscellaneous

/etc/issue, /etc/issue.net: Set warning message and remove server identity such as OS version

WARNING: This system is restricted access to authorized person only.


CategorySystemSecurity CategorySystemSecurity