Post OS Configuration

After sucessfully installing the OS (AlmaLinux 10.1), we’ll need to do some necessary configurations.

Apply System Updates and Enable Automatic Patching

Security hardening begins with maintaining an up-to-date system. AlmaLinux follows Red Hat Enterprise Linux security advisories, making timely updates critical.

sudo dnf clean all
sudo dnf update -y
sudo reboot

To ensure ongoing protection, enable automatic security updates:

sudo dnf install -y dnf-automatic
sudo systemctl enable --now dnf-automatic.timer

Secure SSH Configuration

Prior to hardening the SSH configuration, you should create a SSH keypair for your server and add it into authorized_keys file.

Edit the SSH configuration file:

sudo nano /etc/ssh/sshd_config

Apply the following settings:

Protocol 2
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
PermitEmptyPasswords no
X11Forwarding no
AllowUsers <your_admin_user>
MaxAuthTries 3
LoginGraceTime 30

Validate and restart SSH:

sudo sshd -t
sudo systemctl restart sshd

Configure Firewall Rules With Minimal Exposure

Firewalld provides dynamic firewall management and should be enabled by default.

sudo systemctl enable --now firewalld

Allow only essential services like this:

sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload

Enable SELinux in Enforcing Mode

SELinux provides mandatory access control and significantly reduces the impact of potential compromises.

Verify the current status:

getenforce

If required, enable enforcing mode:

sudo nano /etc/selinux/config

Set:

SELINUX=enforcing
SELINUXTYPE=targeted

Protect Against Brute Force Attempts

Install EPEL

sudo dnf install epel-release

Install Fail2Ban

sudo dnf install fail2ban fail2ban-firewalld

Once the Fail2Ban installation is complete, use the following commands to start and enable the Fail2Ban service:

sudo systemctl start fail2ban
sudo systemctl enable fail2ban

You can use the following command to check the Fail2Ban service’s status:

sudo systemctl status fail2ban

Configuring Fail2Ban

The main configuration file for Fail2Ban is found at /etc/fail2ban/jail.conf. It has a section where settings for Fail2Ban can be defined; we are not changing this file because a package upgrade may replace it.

So, first, create a custom Fail2Ban configuration file, /etc/fail2ban/jail.local. This is the file where customizations to Fail2Ban’s settings should occur. Copying from jail.conf to jail.local isn’t a backup. Rather, it’s an essential step to further customize and configure Fail2Ban according to specific needs.

By default, this /etc/fail2ban/jail.local file does not exist, but Fail2Ban will look for it and read its contents if it exists:

sudo nano /etc/fail2ban/jail.local

Add the following contents, and save the file:

[DEFAULT]
ignoreip = 127.0.0.1/8 ::1
bantime = 1h
findtime = 1h
maxretry = 5

Activating Firewalld support

Fail2Ban uses the iptables firewall by default. To activate Firewalld support, use the following command:

sudo mv /etc/fail2ban/jail.d/00-firewalld.conf /etc/fail2ban/jail.d/00-firewalld.local

Restarting the Fail2Ban service

Then, restart the Fail2Ban service to apply the changes:

sudo systemctl restart fail2ban

Securing the SSH service with Fail2Ban

Fail2Ban does not block any remote hosts by default unless you enable jail configuration for a service that you want to secure. The jail’s configuration is located in the /etc/fail2ban/jail.d file and takes control of the jail.local file.

To secure the SSH service, use the following command to generate a jail configuration file for SSH:

sudo nano /etc/fail2ban/jail.d/sshd.local

Then, paste the following lines:

# This configuration will block the remote host for 3 hours after 3 failed SSH login attempts. 
[sshd]
enabled = true
bantime = 3h
maxretry = 3

When you’re finished, save and close the file, then restart the SSH service to reflect the changes:

sudo systemctl restart fail2ban

Next, use the fail2ban-client command-line tool to verify the jail configuration status:

sudo fail2ban-client status

Use the following command to check the SSH jail for any banned IP addresses:

sudo fail2ban-client status sshd

Installing SELinux Troubleshoot

Installing setroubleshoot and setroubleshoot-server will help understanding issues relating to SELinux configuration.

sudo dnf install setroubleshoot setroubleshoot-server

Restart auditd after installation.

sudo service auditd restart

References