About this project

This repository is a long-form, evolving how-to guide for hardening a Linux server. It is written for at-home or small self-managed servers, though the author notes the concepts also apply to larger environments. The guide is distribution-agnostic in intent but written and tested on Debian, with apt-based commands provided. Structure and scope: - Introduction explains the objective, why server security matters, why another guide exists, links to other guides (including CIS Benchmarks), and a to-do list of future topics. - Before You Start covers threat modeling, choosing a stable and well-supported distribution, installation notes, pre/post-installation requirements, and using Ansible playbooks. - The SSH Server section covers public/private keys, creating an SSH group for AllowGroups, securing /etc/ssh/sshd_config, removing short Diffie-Hellman keys, and 2FA/MFA for SSH. - The Basics section covers limiting sudo and su access, sandboxing with FireJail, NTP client setup, securing /proc, enforcing secure passwords, automatic security updates and alerts, entropy pool notes, and a panic/secondary/fake password login system. - The Network section covers UFW firewall, Docker and UFW interaction, PSAD for iptables intrusion detection, Fail2Ban, and CrowdSec. - The Auditing section covers AIDE file/folder integrity monitoring, ClamAV anti-virus scanning, Rkhunter and chrootkit rootkit detection, logwatch, ss for listening ports, Lynis security auditing, and OSSEC host intrusion detection. - The Danger Zone, Miscellaneous, and Left Over sections cover MSMTP with Google, Gmail and Exim4 as MTA with implicit TLS, a separate iptables log file, contacting the author, helpful links, acknowledgments, and license. The guide emphasizes copy-paste code snippets using basic commands like echo, cat, sed, awk, and grep, while warning that snippets do not validate changes and that backups are included in steps. It advises reading the whole guide first, not blindly pasting commands, and keeping a second terminal open before applying SSH changes. Ansible playbooks are available in a separate linked repository, with instructions to edit variables, enable temporary root SSH access, and run requirements and main playbooks. License is CC-BY-SA. Contributions are accepted via fork and pull request or new issues.