Post OS Configuration
After sucessfully installing the OS (AlmaLinux 10.1), we’ll need to do some necessary configurations.
Apply System Updates and Enable Automatic Patching
Security hardening begins with maintaining an up-to-date system. AlmaLinux follows Red Hat Enterprise Linux security advisories, making timely updates critical.
sudo dnf clean all
sudo dnf update -y
sudo reboot
To ensure ongoing protection, enable automatic security updates:
sudo dnf install -y dnf-automatic
sudo systemctl enable --now dnf-automatic.timer
Secure SSH Configuration
Prior to hardening the SSH configuration, you should create a SSH keypair for your server and add it into authorized_keys file.
Edit the SSH configuration file:
sudo nano /etc/ssh/sshd_config
Apply the following settings:
Protocol 2
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
PermitEmptyPasswords no
X11Forwarding no
AllowUsers <your_admin_user>
MaxAuthTries 3
LoginGraceTime 30
Validate and restart SSH:
sudo sshd -t
sudo systemctl restart sshd
Configure Firewall Rules With Minimal Exposure
Firewalld provides dynamic firewall management and should be enabled by default.
sudo systemctl enable --now firewalld
Allow only essential services like this:
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
Enable SELinux in Enforcing Mode
SELinux provides mandatory access control and significantly reduces the impact of potential compromises.
Verify the current status:
getenforce
If required, enable enforcing mode:
sudo nano /etc/selinux/config
Set:
SELINUX=enforcing
SELINUXTYPE=targeted
Protect Against Brute Force Attempts
Install EPEL
sudo dnf install epel-release
Install Fail2Ban
sudo dnf install fail2ban fail2ban-firewalld
Once the Fail2Ban installation is complete, use the following commands to start and enable the Fail2Ban service:
sudo systemctl start fail2ban
sudo systemctl enable fail2ban
You can use the following command to check the Fail2Ban service’s status:
sudo systemctl status fail2ban
Configuring Fail2Ban
The main configuration file for Fail2Ban is found at /etc/fail2ban/jail.conf. It has a section where settings for Fail2Ban can be defined; we are not changing this file because a package upgrade may replace it.
So, first, create a custom Fail2Ban configuration file, /etc/fail2ban/jail.local. This is the file where customizations to Fail2Ban’s settings should occur. Copying from jail.conf to jail.local isn’t a backup. Rather, it’s an essential step to further customize and configure Fail2Ban according to specific needs.
By default, this /etc/fail2ban/jail.local file does not exist, but Fail2Ban will look for it and read its contents if it exists:
sudo nano /etc/fail2ban/jail.local
Add the following contents, and save the file:
[DEFAULT]
ignoreip = 127.0.0.1/8 ::1
bantime = 1h
findtime = 1h
maxretry = 5
Activating Firewalld support
Fail2Ban uses the iptables firewall by default. To activate Firewalld support, use the following command:
sudo mv /etc/fail2ban/jail.d/00-firewalld.conf /etc/fail2ban/jail.d/00-firewalld.local
Restarting the Fail2Ban service
Then, restart the Fail2Ban service to apply the changes:
sudo systemctl restart fail2ban
Securing the SSH service with Fail2Ban
Fail2Ban does not block any remote hosts by default unless you enable jail configuration for a service that you want to secure. The jail’s configuration is located in the /etc/fail2ban/jail.d file and takes control of the jail.local file.
To secure the SSH service, use the following command to generate a jail configuration file for SSH:
sudo nano /etc/fail2ban/jail.d/sshd.local
Then, paste the following lines:
# This configuration will block the remote host for 3 hours after 3 failed SSH login attempts.
[sshd]
enabled = true
bantime = 3h
maxretry = 3
When you’re finished, save and close the file, then restart the SSH service to reflect the changes:
sudo systemctl restart fail2ban
Next, use the fail2ban-client command-line tool to verify the jail configuration status:
sudo fail2ban-client status
Use the following command to check the SSH jail for any banned IP addresses:
sudo fail2ban-client status sshd
Installing SELinux Troubleshoot
Installing setroubleshoot and setroubleshoot-server will help understanding issues relating to SELinux configuration.
sudo dnf install setroubleshoot setroubleshoot-server
Restart auditd after installation.
sudo service auditd restart