温馨提示×

centos minimal如何加固

小樊
51
2026-09-08 19:48:39
栏目: 智能运维

下面给你一套CentOS Minimal(7/8/Stream 通用)系统加固清单,从“装完系统第一步”到“生产级安全基线”,按优先级排列,偏实战、可操作。


一、系统初始化阶段(装完系统立刻做)

1. 更新系统

yum update -y

或(CentOS 8/Stream):

dnf update -y

2. 创建普通用户 + sudo

useradd admin
passwd admin
usermod -aG wheel admin

禁止 root 直接登录(见后文)

3. 配置时间同步

yum install -y chrony
systemctl enable --now chronyd

验证:

timedatectl

二、SSH 安全(最重要)

4. 修改 SSH 配置

vi /etc/ssh/sshd_config

推荐配置:

Port 2222
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2

5. 使用密钥登录

ssh-keygen -t ed25519
ssh-copy-id -p 2222 admin@server

重启 SSH:

systemctl restart sshd

三、防火墙与网络

6. 启用 firewalld

systemctl enable --now firewalld
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload

7. 禁用不必要服务

systemctl disable --now postfix
systemctl disable --now bluetooth

8. 禁止 IPv6(如不使用)

grubby --update-kernel=ALL --args="ipv6.disable=1"
reboot

四、账户与权限加固

9. 密码策略

vi /etc/login.defs
PASS_MAX_DAYS 90
PASS_MIN_DAYS 1
PASS_MIN_LEN 12
PASS_WARN_AGE 7

10. 锁定无效账户

passwd -l daemon
passwd -l bin

11. 限制 su

vi /etc/pam.d/su

取消注释:

auth required pam_wheel.so use_uid

五、系统与内核安全

12. 禁用 Ctrl+Alt+Del

systemctl mask ctrl-alt-del.target

13. 开启 SELinux

vi /etc/selinux/config
SELINUX=enforcing
setenforce 1

14. 内核参数加固

vi /etc/sysctl.d/99-hardening.conf
net.ipv4.ip_forward=0
net.ipv4.conf.all.send_redirects=0
net.ipv4.conf.all.accept_redirects=0
net.ipv4.icmp_echo_ignore_broadcasts=1
kernel.dmesg_restrict=1
sysctl --system

六、日志与审计

15. 安装基础安全工具

yum install -y audit rsyslog
systemctl enable --now auditd rsyslog

16. 配置日志轮转

vi /etc/logrotate.d/syslog

七、入侵检测与自动防护(推荐)

17. 安装 fail2ban

yum install -y epel-release
yum install -y fail2ban
systemctl enable --now fail2ban

配置示例:

[sshd]
enabled = true
port = 2222
maxretry = 3

八、可选但强烈推荐

  • ✅ 使用 防火墙白名单 IP
  • ✅ 定期备份 /etc 和用户数据
  • ✅ 启用 自动安全更新(yum-cron)
  • ✅ 使用 Lynis 做安全扫描
yum install -y lynis
lynis audit system

九、一句话总结

CentOS Minimal 加固核心 = 非 root + 密钥 + 改端口 + 防火墙 + SELinux + 日志审计

如果你告诉我:

  • CentOS 版本(7 / 8 / Stream)
  • 是否公网服务器
  • 是否跑 Web / 数据库

我可以给你更精准的定制加固方案。

0 踩