
Linux Hardening
- 300 installs
- 44 repo stars
- Updated May 22, 2026
- bagelhole/devops-security-agent-skills
linux-hardening is a Claude Code skill that guides CIS-aligned Linux server hardening—SSH, services, permissions, kernel params, and audit logging—for developers who must secure production hosts.
About
linux-hardening is a security-focused agent skill from bagelhole/devops-security-agent-skills that walks developers through hardening Linux production servers. The skill covers disabling unused services, applying CIS benchmark recommendations, tightening SSH configuration, fixing file permissions, tuning kernel parameters, and enabling audit logging so hosts meet baseline compliance. Developers reach for linux-hardening when provisioning or auditing VMs, containers, or bare-metal nodes before go-live or after a security review flags excessive attack surface. It pairs naturally with infrastructure-as-code workflows where agents need explicit checklists rather than ad-hoc shell one-liners.
- CIS benchmark alignment
- SSH and sudo hardening
- Service minimization
- Kernel sysctl tuning
Linux Hardening by the numbers
- 300 all-time installs (skills.sh)
- Ranked #632 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Jul 28, 2026 (Skillselion catalog sync)
npx skills add https://github.com/bagelhole/devops-security-agent-skills --skill linux-hardeningAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 300 |
|---|---|
| repo stars | ★ 44 |
| Last updated | May 22, 2026 |
| Repository | bagelhole/devops-security-agent-skills ↗ |
How do you harden Linux servers with CIS benchmarks?
Harden Linux servers by disabling unused services, applying CIS benchmarks, configuring SSH, permissions, kernel params, and audit logging for production hosts.
Who is it for?
Backend and DevOps engineers provisioning or auditing production Linux hosts who need CIS-aligned hardening checklists an agent can execute step by step.
Skip if: Developers who only need application-level security reviews or who run fully managed PaaS workloads where the cloud provider owns OS hardening.
When should I use this skill?
A developer asks to secure, harden, or CIS-benchmark a Linux server, SSH access, kernel params, or production host audit logging.
What you get
Hardened SSH config, disabled services list, kernel sysctl settings, permission fixes, and audit logging configuration ready to apply.
- hardened SSH configuration
- CIS-aligned sysctl and service changes
- audit logging setup
Files
Linux Hardening
Secure Linux servers following CIS benchmarks and security best practices.
When to Use This Skill
Use this skill when:
- Hardening production servers
- Meeting compliance requirements
- Implementing security baselines
- Configuring secure SSH access
SSH Hardening
# /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
AllowUsers deploy admin
Protocol 2User Security
# Password policy
sudo apt install libpam-pwquality
# /etc/security/pwquality.conf
minlen = 14
dcredit = -1
ucredit = -1
ocredit = -1
lcredit = -1
# Lock inactive accounts
useradd -D -f 30
# Audit sudo usage
echo "Defaults logfile=/var/log/sudo.log" >> /etc/sudoersFirewall Configuration
# UFW setup
ufw default deny incoming
ufw default allow outgoing
ufw allow ssh
ufw allow 443/tcp
ufw enable
# Or iptables
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPTKernel Hardening
# /etc/sysctl.d/99-security.conf
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.icmp_echo_ignore_broadcasts = 1
kernel.randomize_va_space = 2
fs.suid_dumpable = 0
# Apply
sysctl -pFile Permissions
# Critical files
chmod 600 /etc/shadow
chmod 644 /etc/passwd
chmod 700 /root
chmod 600 /etc/ssh/sshd_config
# Find world-writable files
find / -type f -perm -0002 -ls
# Find SUID files
find / -perm -4000 -type f -lsAudit Configuration
# Install auditd
apt install auditd
# /etc/audit/rules.d/audit.rules
-w /etc/passwd -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/sudoers -p wa -k actions
-a always,exit -F arch=b64 -S execve -k execBest Practices
- Disable unused services
- Keep system updated
- Use fail2ban for intrusion prevention
- Enable SELinux/AppArmor
- Regular security audits
- Monitor log files
- Implement least privilege
Related Skills
- cis-benchmarks - Compliance scanning
- firewall-config - Firewall rules
# SSH Server Hardening Configuration
# Place in /etc/ssh/sshd_config.d/hardening.conf
# Restart SSH: systemctl restart sshd
#------------------------------------------------------------------------------
# AUTHENTICATION
#------------------------------------------------------------------------------
# Disable root login
PermitRootLogin no
# Disable password authentication
PasswordAuthentication no
# Enable public key authentication
PubkeyAuthentication yes
# Disable empty passwords
PermitEmptyPasswords no
# Disable keyboard-interactive authentication
KbdInteractiveAuthentication no
# Disable challenge-response authentication
ChallengeResponseAuthentication no
# Maximum authentication attempts
MaxAuthTries 3
# Maximum sessions per connection
MaxSessions 2
# Maximum simultaneous unauthenticated connections
MaxStartups 10:30:60
# Login grace time
LoginGraceTime 60
#------------------------------------------------------------------------------
# SESSION
#------------------------------------------------------------------------------
# Client alive settings (timeout)
ClientAliveInterval 300
ClientAliveCountMax 2
# Disable TCP forwarding
AllowTcpForwarding no
# Disable agent forwarding
AllowAgentForwarding no
# Disable stream local forwarding
AllowStreamLocalForwarding no
# Disable X11 forwarding
X11Forwarding no
# Disable user environment processing
PermitUserEnvironment no
# Disable tunnel device forwarding
PermitTunnel no
# Disable gateway ports
GatewayPorts no
#------------------------------------------------------------------------------
# CRYPTOGRAPHY
#------------------------------------------------------------------------------
# Protocol version (SSH-2 only)
Protocol 2
# Strong ciphers only
Ciphers aes256-gcm@openssh.com,chacha20-poly1305@openssh.com,aes256-ctr
# Strong MACs only
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256
# Strong key exchange algorithms
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512
# Strong host key algorithms
HostKeyAlgorithms ssh-ed25519,rsa-sha2-512,rsa-sha2-256
#------------------------------------------------------------------------------
# LOGGING
#------------------------------------------------------------------------------
# Log level
LogLevel VERBOSE
# Enable sftp logging
Subsystem sftp /usr/lib/openssh/sftp-server -l INFO
#------------------------------------------------------------------------------
# ACCESS CONTROL
#------------------------------------------------------------------------------
# Use PAM
UsePAM yes
# Show banner
Banner /etc/issue.net
# Restrict to specific users (uncomment and customize)
# AllowUsers admin deploy
# Restrict to specific groups (uncomment and customize)
# AllowGroups sshusers admins
# Linux Kernel Security Hardening
# Place in /etc/sysctl.d/99-security.conf
# Apply with: sysctl -p /etc/sysctl.d/99-security.conf
#------------------------------------------------------------------------------
# NETWORK SECURITY
#------------------------------------------------------------------------------
# Disable IP forwarding (unless router)
net.ipv4.ip_forward = 0
net.ipv6.conf.all.forwarding = 0
# Disable packet redirect sending
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
# Disable ICMP redirect acceptance
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.default.secure_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
# Disable source routing
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv6.conf.all.accept_source_route = 0
net.ipv6.conf.default.accept_source_route = 0
# Log suspicious packets
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.default.log_martians = 1
# Ignore ICMP broadcast requests
net.ipv4.icmp_echo_ignore_broadcasts = 1
# Ignore bogus ICMP error responses
net.ipv4.icmp_ignore_bogus_error_responses = 1
# Enable reverse path filtering (spoofing protection)
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
# Enable TCP SYN cookies (SYN flood protection)
net.ipv4.tcp_syncookies = 1
# Disable IPv6 router advertisements
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
# Disable IPv6 if not needed
# net.ipv6.conf.all.disable_ipv6 = 1
# net.ipv6.conf.default.disable_ipv6 = 1
#------------------------------------------------------------------------------
# KERNEL SECURITY
#------------------------------------------------------------------------------
# Enable ASLR
kernel.randomize_va_space = 2
# Restrict access to kernel pointers
kernel.kptr_restrict = 2
# Restrict dmesg access
kernel.dmesg_restrict = 1
# Restrict ptrace scope
kernel.yama.ptrace_scope = 1
# Disable magic SysRq key
kernel.sysrq = 0
# Restrict unprivileged user namespaces
# kernel.unprivileged_userns_clone = 0
# Restrict loading TTY line disciplines
dev.tty.ldisc_autoload = 0
# Restrict userfaultfd to privileged users
vm.unprivileged_userfaultfd = 0
# Restrict BPF
kernel.unprivileged_bpf_disabled = 1
net.core.bpf_jit_harden = 2
# Restrict perf events
kernel.perf_event_paranoid = 3
#------------------------------------------------------------------------------
# FILE SYSTEM SECURITY
#------------------------------------------------------------------------------
# Restrict core dumps
fs.suid_dumpable = 0
# Restrict hardlinks and symlinks
fs.protected_hardlinks = 1
fs.protected_symlinks = 1
# Protect FIFOs and regular files
fs.protected_fifos = 2
fs.protected_regular = 2
CIS Linux Hardening Checklist
1. Initial Setup
1.1 Filesystem Configuration
- [ ] Disable unused filesystems (cramfs, freevxfs, jffs2, hfs, hfsplus, squashfs, udf)
- [ ] Ensure
/tmpis configured with nodev, nosuid, noexec - [ ] Ensure
/var,/var/tmp,/var/log,/var/log/auditare separate partitions - [ ] Ensure
/homeis separate partition with nodev
1.2 Configure Software Updates
- [ ] Ensure package manager repositories are configured
- [ ] Ensure GPG keys are configured
- [ ] Ensure automatic updates are enabled
1.3 Filesystem Integrity
- [ ] Ensure AIDE is installed
- [ ] Ensure filesystem integrity is regularly checked
2. Services
2.1 Special Purpose Services
- [ ] Ensure time synchronization is configured (chrony/ntp)
- [ ] Ensure X Window System is not installed
- [ ] Ensure rsync service is not installed or masked
- [ ] Ensure Avahi Server is not installed
- [ ] Ensure CUPS is not installed
- [ ] Ensure DHCP Server is not installed
- [ ] Ensure LDAP server is not installed
- [ ] Ensure NFS is not installed
- [ ] Ensure DNS Server is not installed
- [ ] Ensure FTP Server is not installed
- [ ] Ensure HTTP Server is not installed
- [ ] Ensure IMAP and POP3 server is not installed
- [ ] Ensure Samba is not installed
- [ ] Ensure SNMP Server is not installed
2.2 Service Clients
- [ ] Ensure NIS Client is not installed
- [ ] Ensure rsh client is not installed
- [ ] Ensure talk client is not installed
- [ ] Ensure telnet client is not installed
- [ ] Ensure LDAP client is not installed
- [ ] Ensure RPC is not installed
3. Network Configuration
3.1 Network Parameters (Host Only)
- [ ] Ensure IP forwarding is disabled
- [ ] Ensure packet redirect sending is disabled
3.2 Network Parameters (Host and Router)
- [ ] Ensure source routed packets are not accepted
- [ ] Ensure ICMP redirects are not accepted
- [ ] Ensure secure ICMP redirects are not accepted
- [ ] Ensure suspicious packets are logged
- [ ] Ensure broadcast ICMP requests are ignored
- [ ] Ensure bogus ICMP responses are ignored
- [ ] Ensure Reverse Path Filtering is enabled
- [ ] Ensure TCP SYN Cookies is enabled
3.3 Firewall Configuration
- [ ] Ensure firewall is installed (iptables, nftables, or firewalld)
- [ ] Ensure default deny firewall policy
- [ ] Ensure loopback traffic is configured
- [ ] Ensure outbound connections are configured
4. Access, Authentication and Authorization
4.1 Configure Shadow Suite
- [ ] Ensure password expiration is 365 days or less
- [ ] Ensure minimum days between password changes is 7 or more
- [ ] Ensure password expiration warning days is 7 or more
- [ ] Ensure inactive password lock is 30 days or less
- [ ] Ensure all users last password change date is in the past
4.2 Configure SSH Server
- [ ] Ensure SSH Protocol is set to 2
- [ ] Ensure SSH LogLevel is appropriate
- [ ] Ensure SSH X11 forwarding is disabled
- [ ] Ensure SSH MaxAuthTries is set to 4 or less
- [ ] Ensure SSH IgnoreRhosts is enabled
- [ ] Ensure SSH HostbasedAuthentication is disabled
- [ ] Ensure SSH root login is disabled
- [ ] Ensure SSH PermitEmptyPasswords is disabled
- [ ] Ensure SSH PermitUserEnvironment is disabled
- [ ] Ensure SSH Idle Timeout Interval is configured
- [ ] Ensure SSH LoginGraceTime is set to one minute or less
- [ ] Ensure SSH warning banner is configured
- [ ] Ensure SSH PAM is enabled
- [ ] Ensure SSH AllowTcpForwarding is disabled
4.3 Configure PAM
- [ ] Ensure password creation requirements are configured
- [ ] Ensure lockout for failed password attempts is configured
- [ ] Ensure password reuse is limited
- [ ] Ensure password hashing algorithm is SHA-512
5. Logging and Auditing
5.1 Configure Logging
- [ ] Ensure rsyslog is installed
- [ ] Ensure rsyslog Service is enabled
- [ ] Ensure logging is configured
- [ ] Ensure rsyslog default file permissions configured
- [ ] Ensure remote rsyslog messages only accepted on designated log hosts
5.2 Configure auditd
- [ ] Ensure auditing is enabled
- [ ] Ensure audit log storage size is configured
- [ ] Ensure audit logs are not automatically deleted
- [ ] Ensure changes to system administration scope are collected
- [ ] Ensure login and logout events are collected
- [ ] Ensure session initiation information is collected
- [ ] Ensure file deletion events by users are collected
- [ ] Ensure kernel module loading and unloading is collected
6. System Maintenance
6.1 File Permissions
- [ ] Ensure permissions on /etc/passwd are configured (644)
- [ ] Ensure permissions on /etc/shadow are configured (600)
- [ ] Ensure permissions on /etc/group are configured (644)
- [ ] Ensure permissions on /etc/gshadow are configured (600)
- [ ] Ensure no world writable files exist
- [ ] Ensure no unowned files or directories exist
- [ ] Ensure no ungrouped files or directories exist
6.2 User and Group Settings
- [ ] Ensure accounts in /etc/passwd use shadowed passwords
- [ ] Ensure no legacy "+" entries exist in /etc/passwd
- [ ] Ensure root is the only UID 0 account
- [ ] Ensure root PATH integrity
- [ ] Ensure all users' home directories exist
- [ ] Ensure users' home directories permissions are 750 or more restrictive
- [ ] Ensure users own their home directories
- [ ] Ensure no users have .forward files
- [ ] Ensure no users have .netrc files
- [ ] Ensure no users have .rhosts files
#!/bin/bash
# Linux Security Audit Script
# Usage: ./audit-system.sh [--verbose]
set -euo pipefail
VERBOSE="${1:-}"
PASS=0
WARN=0
FAIL=0
check() {
local status="$1"
local message="$2"
case "$status" in
PASS) echo -e "\e[32m[PASS]\e[0m $message"; ((PASS++)) ;;
WARN) echo -e "\e[33m[WARN]\e[0m $message"; ((WARN++)) ;;
FAIL) echo -e "\e[31m[FAIL]\e[0m $message"; ((FAIL++)) ;;
esac
}
echo "========================================="
echo "Linux Security Audit"
echo "========================================="
echo ""
# 1. System Updates
echo "1. System Updates"
echo "-----------------"
UPDATES=$(apt-get -s upgrade 2>/dev/null | grep -c "^Inst" || echo 0)
if [ "$UPDATES" -eq 0 ]; then
check "PASS" "System is up to date"
else
check "FAIL" "$UPDATES packages need updating"
fi
# 2. SSH Configuration
echo ""
echo "2. SSH Configuration"
echo "--------------------"
if grep -q "^PermitRootLogin no" /etc/ssh/sshd_config* 2>/dev/null; then
check "PASS" "Root login disabled"
else
check "FAIL" "Root login may be enabled"
fi
if grep -q "^PasswordAuthentication no" /etc/ssh/sshd_config* 2>/dev/null; then
check "PASS" "Password authentication disabled"
else
check "WARN" "Password authentication may be enabled"
fi
# 3. User Accounts
echo ""
echo "3. User Accounts"
echo "----------------"
EMPTY_PASS=$(awk -F: '($2 == "") {print $1}' /etc/shadow 2>/dev/null | wc -l)
if [ "$EMPTY_PASS" -eq 0 ]; then
check "PASS" "No accounts with empty passwords"
else
check "FAIL" "$EMPTY_PASS accounts with empty passwords"
fi
ROOT_ACCOUNTS=$(awk -F: '($3 == 0) {print $1}' /etc/passwd | wc -l)
if [ "$ROOT_ACCOUNTS" -eq 1 ]; then
check "PASS" "Only root has UID 0"
else
check "FAIL" "$ROOT_ACCOUNTS accounts have UID 0"
fi
# 4. File Permissions
echo ""
echo "4. File Permissions"
echo "-------------------"
SHADOW_PERMS=$(stat -c %a /etc/shadow 2>/dev/null)
if [ "$SHADOW_PERMS" = "600" ] || [ "$SHADOW_PERMS" = "640" ]; then
check "PASS" "/etc/shadow permissions: $SHADOW_PERMS"
else
check "FAIL" "/etc/shadow permissions: $SHADOW_PERMS (should be 600)"
fi
WORLD_WRITABLE=$(find /etc -type f -perm -002 2>/dev/null | wc -l)
if [ "$WORLD_WRITABLE" -eq 0 ]; then
check "PASS" "No world-writable files in /etc"
else
check "FAIL" "$WORLD_WRITABLE world-writable files in /etc"
fi
# 5. Network Security
echo ""
echo "5. Network Security"
echo "-------------------"
if sysctl -n net.ipv4.tcp_syncookies 2>/dev/null | grep -q "1"; then
check "PASS" "TCP SYN cookies enabled"
else
check "WARN" "TCP SYN cookies not enabled"
fi
if sysctl -n net.ipv4.conf.all.rp_filter 2>/dev/null | grep -q "1"; then
check "PASS" "Reverse path filtering enabled"
else
check "WARN" "Reverse path filtering not enabled"
fi
# 6. Firewall
echo ""
echo "6. Firewall Status"
echo "------------------"
if command -v ufw &>/dev/null && ufw status | grep -q "active"; then
check "PASS" "UFW firewall is active"
elif command -v firewalld &>/dev/null && systemctl is-active firewalld &>/dev/null; then
check "PASS" "firewalld is active"
elif iptables -L -n 2>/dev/null | grep -q "DROP\|REJECT"; then
check "PASS" "iptables has rules configured"
else
check "FAIL" "No firewall appears to be active"
fi
# 7. Services
echo ""
echo "7. Running Services"
echo "-------------------"
LISTENING=$(ss -tlnp 2>/dev/null | grep -c LISTEN || echo 0)
check "WARN" "$LISTENING services listening on ports"
# Summary
echo ""
echo "========================================="
echo "Audit Summary"
echo "========================================="
echo -e "Passed: \e[32m$PASS\e[0m"
echo -e "Warnings: \e[33m$WARN\e[0m"
echo -e "Failed: \e[31m$FAIL\e[0m"
echo ""
if [ "$FAIL" -gt 0 ]; then
exit 1
fi
#!/bin/bash
# Linux System Hardening Script
# Usage: ./harden-system.sh [--apply]
# Run without --apply to see what changes would be made
set -euo pipefail
APPLY="${1:-}"
if [ "$APPLY" != "--apply" ]; then
echo "DRY RUN MODE - No changes will be made"
echo "Run with --apply to make changes"
echo ""
fi
apply_change() {
if [ "$APPLY" == "--apply" ]; then
eval "$1"
echo " [APPLIED] $2"
else
echo " [WOULD APPLY] $2"
fi
}
echo "========================================="
echo "Linux System Hardening"
echo "========================================="
echo ""
# 1. Update system
echo "1. System Updates"
echo "-----------------"
apply_change "apt-get update && apt-get upgrade -y" "Update all packages"
# 2. Disable unused filesystems
echo ""
echo "2. Disable Unused Filesystems"
echo "------------------------------"
FILESYSTEMS="cramfs freevxfs jffs2 hfs hfsplus squashfs udf"
for fs in $FILESYSTEMS; do
apply_change "echo 'install $fs /bin/true' >> /etc/modprobe.d/disable-filesystems.conf" "Disable $fs"
done
# 3. Kernel parameters
echo ""
echo "3. Kernel Hardening (sysctl)"
echo "----------------------------"
SYSCTL_CONF="/etc/sysctl.d/99-hardening.conf"
cat << 'EOF' > /tmp/sysctl-hardening.conf
# Network security
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.default.secure_redirects = 0
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.default.log_martians = 1
net.ipv4.icmp_echo_ignore_broadcasts = 1
net.ipv4.icmp_ignore_bogus_error_responses = 1
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
net.ipv4.tcp_syncookies = 1
# IPv6 (disable if not needed)
net.ipv6.conf.all.disable_ipv6 = 1
net.ipv6.conf.default.disable_ipv6 = 1
# Kernel hardening
kernel.randomize_va_space = 2
kernel.kptr_restrict = 2
kernel.dmesg_restrict = 1
kernel.yama.ptrace_scope = 1
EOF
apply_change "cp /tmp/sysctl-hardening.conf $SYSCTL_CONF && sysctl -p $SYSCTL_CONF" "Apply kernel hardening parameters"
# 4. SSH hardening
echo ""
echo "4. SSH Hardening"
echo "----------------"
SSH_CONF="/etc/ssh/sshd_config.d/hardening.conf"
cat << 'EOF' > /tmp/ssh-hardening.conf
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
X11Forwarding no
AllowAgentForwarding no
PermitEmptyPasswords no
EOF
apply_change "cp /tmp/ssh-hardening.conf $SSH_CONF" "Apply SSH hardening"
# 5. File permissions
echo ""
echo "5. File Permissions"
echo "-------------------"
apply_change "chmod 600 /etc/shadow" "Secure /etc/shadow"
apply_change "chmod 644 /etc/passwd" "Secure /etc/passwd"
apply_change "chmod 600 /etc/gshadow" "Secure /etc/gshadow"
apply_change "chmod 644 /etc/group" "Secure /etc/group"
# 6. Remove unnecessary packages
echo ""
echo "6. Remove Unnecessary Services"
echo "------------------------------"
REMOVE_PKGS="telnet rsh-client rsh-redone-client"
for pkg in $REMOVE_PKGS; do
apply_change "apt-get remove -y $pkg 2>/dev/null || true" "Remove $pkg"
done
# 7. Configure firewall
echo ""
echo "7. Enable Firewall"
echo "------------------"
apply_change "ufw default deny incoming && ufw default allow outgoing && ufw allow ssh && ufw --force enable" "Configure UFW firewall"
# 8. Enable automatic updates
echo ""
echo "8. Automatic Security Updates"
echo "-----------------------------"
apply_change "apt-get install -y unattended-upgrades && dpkg-reconfigure -plow unattended-upgrades" "Enable unattended upgrades"
echo ""
echo "========================================="
echo "Hardening script complete"
if [ "$APPLY" != "--apply" ]; then
echo "Run with --apply to make changes"
fi
echo "========================================="
Related skills
How it compares
Choose linux-hardening when the task is OS-level baseline compliance on Linux hosts rather than application code review or cloud IAM policy design.
FAQ
What does linux-hardening configure on a server?
linux-hardening guides disabling unused services, applying CIS benchmark checks, tightening SSH, fixing permissions, tuning kernel parameters, and enabling audit logging so a Linux production host meets a documented security baseline.
When should developers use linux-hardening?
linux-hardening fits new VM or bare-metal provisioning, pre-launch security reviews, and post-incident hardening when an agent must translate CIS-style controls into concrete sshd, sysctl, and auditd changes.