下面给你一套CentOS Minimal(7/8/Stream 通用)系统加固清单,从“装完系统第一步”到“生产级安全基线”,按优先级排列,偏实战、可操作。
yum update -y
或(CentOS 8/Stream):
dnf update -y
useradd admin
passwd admin
usermod -aG wheel admin
禁止 root 直接登录(见后文)
yum install -y chrony
systemctl enable --now chronyd
验证:
timedatectl
vi /etc/ssh/sshd_config
推荐配置:
Port 2222
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
ssh-keygen -t ed25519
ssh-copy-id -p 2222 admin@server
重启 SSH:
systemctl restart sshd
systemctl enable --now firewalld
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload
systemctl disable --now postfix
systemctl disable --now bluetooth
grubby --update-kernel=ALL --args="ipv6.disable=1"
reboot
vi /etc/login.defs
PASS_MAX_DAYS 90
PASS_MIN_DAYS 1
PASS_MIN_LEN 12
PASS_WARN_AGE 7
passwd -l daemon
passwd -l bin
vi /etc/pam.d/su
取消注释:
auth required pam_wheel.so use_uid
systemctl mask ctrl-alt-del.target
vi /etc/selinux/config
SELINUX=enforcing
setenforce 1
vi /etc/sysctl.d/99-hardening.conf
net.ipv4.ip_forward=0
net.ipv4.conf.all.send_redirects=0
net.ipv4.conf.all.accept_redirects=0
net.ipv4.icmp_echo_ignore_broadcasts=1
kernel.dmesg_restrict=1
sysctl --system
yum install -y audit rsyslog
systemctl enable --now auditd rsyslog
vi /etc/logrotate.d/syslog
yum install -y epel-release
yum install -y fail2ban
systemctl enable --now fail2ban
配置示例:
[sshd]
enabled = true
port = 2222
maxretry = 3
/etc 和用户数据yum install -y lynis
lynis audit system
CentOS Minimal 加固核心 = 非 root + 密钥 + 改端口 + 防火墙 + SELinux + 日志审计
如果你告诉我:
我可以给你更精准的定制加固方案。