温馨提示×

如何加固centos minimal

小樊
35
2026-09-24 01:54:09
栏目: 智能运维

“加固 CentOS Minimal”通常指最小化安装后的安全加固,目标是减少攻击面、提高系统抗风险能力。下面按优先级 + 可执行命令给出一套通用加固清单(适用于 CentOS 7 / 8 / Stream,部分命令视版本略有差异)。


一、系统更新与基础设置

1. 更新系统

yum update -y     # CentOS 7
dnf update -y     # CentOS 8 / Stream

2. 设置时区与时间同步

timedatectl set-timezone Asia/Shanghai
yum install -y chrony
systemctl enable --now chronyd

二、账号与口令安全

3. 禁用 root 直接登录(推荐)

useradd admin
passwd admin
usermod -aG wheel admin

编辑 SSH 配置:

vi /etc/ssh/sshd_config

修改:

PermitRootLogin no
PasswordAuthentication no   # 建议用密钥
systemctl restart sshd

4. 口令策略(CentOS 7)

authconfig --passminlen=12 --passminclass=3 --update

CentOS 8:

vi /etc/security/pwquality.conf
minlen = 12
minclass = 3

5. 锁定无用账号

passwd -l lp
passwd -l sync
passwd -l shutdown

三、SSH 安全

6. 修改默认端口(可选)

Port 22222

7. 仅允许指定用户

AllowUsers admin

8. 使用密钥登录

ssh-keygen -t ed25519

四、防火墙与网络

9. 启用 firewalld

systemctl enable --now firewalld
firewall-cmd --set-default-zone=public
firewall-cmd --add-service=ssh --permanent
firewall-cmd --reload

10. 禁用 IPv6(如不需要)

grubby --update-kernel=ALL --args="ipv6.disable=1"
reboot

五、服务最小化

11. 关闭不必要服务

systemctl disable --now postfix
systemctl disable --now bluetooth

12. 查看监听端口

ss -tunlp

六、系统安全加固

13. 启用 SELinux

getenforce
setenforce 1

永久启用:

vi /etc/selinux/config
SELINUX=enforcing

14. 配置自动安全更新

CentOS 8:

dnf install -y dnf-automatic
systemctl enable --now dnf-automatic.timer

七、日志与审计

15. 启用 auditd

systemctl enable --now auditd

16. 日志集中管理(可选)

yum install -y rsyslog

八、进阶(生产推荐)

  • 使用 fail2ban 防暴力破解
  • 配置文件完整性检查(AIDE)
  • 定期漏洞扫描(OpenSCAP)
  • 使用 防火墙 + 跳板机 + 私钥

如果你能说明:

  • CentOS 版本(7 / 8 / Stream)
  • 是否云服务器 / 内网
  • 是否生产环境

我可以给你一份更精确的加固脚本或 checklist。

0 踩