Home > Ask the Enterprise Linux Experts > Security Questions & Answers > Hardening Linux servers for remote access
Ask The Enterprise Linux Expert: Questions & Answers
EMAIL THIS

Hardening Linux servers for remote access

James Turnbull EXPERT RESPONSE FROM: James Turnbull

Pose a Question
Other Enterprise Linux Categories
Meet all Enterprise Linux Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 03 January 2008
I host several Linux servers which allow users remote access and file transfer capabilities via SSHv2/SFTP. These systems are already hardened with external firewalls, SSH hardening ala DenyHosts and internal privilege hardening via Bastille, limits.conf and some of my own hand-rolled scripts. Is there anything you might recommend to further tighten such a setup, since many users will have shell access?

>
EXPERT RESPONSE

It sounds like you've got most of the bases covered. I have a few suggestions that may assist you:

  • Look at PAM and potentially how to use it to harden your user controls. Strong passwords and authentication controls are critical on hosts with large numbers of shell users.
  • Consider a deployment of SELinux (or depending on your platform AppArmor). While both can be complicated to configure they can be very powerful in adding more granular controls to your hosts.
  • Consider very carefully what packages are installed, for example, if a lot of users have shell access then the addition of tools like compilers and scripting languages can greatly assist an attacker in compromising your host. Ensure you have the minimal and most appropriate set of packages installed.
  • Often the first warnings of something going wrong is a log message. Try setting up some centralized logging and alerting on some of the more critical messages for security and operations and consider the use of tools like SEC or Swatch, which are helpful with this.
  • Lastly, ensure you keep up to date with patches and updates for both your operating system and your applications.
  • Hope that helps and good luck with securing your hosts.


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Linux Migration Advice: Unix-to-Linux, Windows-to-Linux
    HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts