The first five minutes on a new server
Summary
Bryan Kennedy describes a short basic hardening of Linux with user accounts, SSH keys, a firewall and automatic security updates. The procedure is aimed at Ubuntu servers. UFW configures the host firewall.
Ideas
- A personal administrator account replaces logging in directly as root every day.
- SSH keys remove guessable passwords from network access.
- The firewall only allows services that are actually needed.
- Automatic security updates shorten known windows of vulnerability.
Insights
- Secure defaults work best before the first public service.
- A short, reproducible procedure prevents forgotten basic steps.
- Hardening must preserve both access security and maintainability.
Facts
- Fail2ban is named as an additional layer of protection.
Recommendations
- Automate the basic configuration with infrastructure as code.
- Test a second way in before closing the session.
References
Links to the original source and the Web Archive open in a new tab.