linux-server-hardening
Installation
SKILL.md
Linux Server Hardening
Distro support
Two-family skill. SSH and kernel/sysctl hardening are largely identical; the
big difference is mandatory access control — Debian/Ubuntu use AppArmor,
the RHEL family (Fedora, RHEL, CentOS Stream, Rocky, Alma, Oracle) enforces
SELinux by default. Full SELinux detail is in
references/selinux-reference.md.
| Concept | Debian/Ubuntu | RHEL family |
|---|---|---|
| Mandatory access control | AppArmor (aa-status, /etc/apparmor.d/) |
SELinux (getenforce, sestatus) — enforcing by default |
| Firewall | ufw |
firewalld |
| Auto security updates | unattended-upgrades |
dnf-automatic |
| Sudo admin group | sudo |
wheel |
| SSH hardening | /etc/ssh/sshd_config[.d] |
identical |
| sysctl hardening | /etc/sysctl.d/ |
identical |
| Audit daemon | auditd |
auditd (same) |