Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Donald A. Tevault

Rating No ratings yet

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on, practical guide for Linux administrators and security enthusiasts to systematically harden their systems—covering user account security, firewalls, encryption, SSH, access control, and more—with step-by-step labs and real-world commands. 【Book Arc】 - **Opening (~0%–10%)**: Introduces the book's scope and sets up the lab environment, covering running Linux in virtual machines (VirtualBox, Ubuntu, CentOS/AlmaLinux) and the basics of connecting via SSH from Windows. This stage establishes the practical, lab-driven approach used throughout. - **Early (~10%–23%)**: Focuses on securing user accounts, including managing sudo privileges with aliases (Host_Alias, User_Alias, Cmnd_Alias), handling account and password expiration with `chage`, and locking/unlocking accounts with `usermod` and `passwd`. Includes hands-on labs for assigning limited sudo privileges and setting expiry data. - **Early (~23%–32%)**: Continues user security with encryption of home directories using eCryptfs, enforcing strong password criteria, and forcing password changes on first login. Labs demonstrate creating encrypted home directories and setting account/password expiry data. - **Middle (~32%–48%)**: Shifts to network security, starting with firewall configuration. Covers iptables for IPv4 and IPv6, including rule creation, persistence with `iptables-persistent`, and the nuances of ICMP for IPv6. Introduces nftables as a modern alternative, with examples of building and managing rulesets. - **Late (~48%–100%)**: The excerpts suggest the book continues with SSH hardening (disabling protocol 1, key management, disabling root/password logins), discretionary access control, ACLs, SELinux/AppArmor, kernel hardening, auditing, logging, vulnerability scanning, and application blocking with fapolicyd. The final chapter offers security tips for busy administrators. 【Key Takeaways】 - **Virtual lab setup is the foundation** (Opening): Running Linux in VMs (VirtualBox) with Ubuntu and CentOS/AlmaLinux provides a safe, isolated environment for testing security configurations. This approach allows you to experiment without risking production systems. - **Sudo privileges can be finely granular** (Early): Using aliases in the sudoers file (e.g., `WEBADMINS WEBSERVERS=(ALL) WEBCOMMANDS`) lets you delegate specific commands to specific users on specific hosts. This is crucial for the principle of least privilege in small to large enterprises. - **Account expiration and password aging are distinct controls** (Early): Password expiry allows users to self-reset, while account expiry requires admin intervention. Tools like `chage` and `passwd` let you set both, ensuring temporary accounts (e.g., for contractors) don't linger and become security risks. - **Locking accounts is reversible and legally safer than deletion** (Early): Using `usermod -L` or `passwd -l` adds an exclamation point to the password hash in `/etc/shadow`, locking the user out without deleting data. This is vital for compliance with laws like Sarbanes-Oxley that restrict file deletion. - **Encryption protects data at rest** (Early): eCryptfs can encrypt home directories during user creation (`adduser --encrypt-home`), and tools like `ecryptfs-unwrap-passphrase` are essential for recovery. This ensures sensitive user data is unreadable if the disk is stolen. - **Firewall rules must be persistent and stateful** (Middle): iptables rules vanish on reboot unless saved (e.g., with `iptables-persistent`). Using `ctstate RELATED,ESTABLISHED` allows established connections while blocking new unwanted ones, and verbose output (`-v`) helps debug rule effectiveness. - **IPv6 firewalling requires more ICMP allowances** (Middle): Unlike IPv4, IPv6 relies on ICMP for neighbor discovery (replacing ARP) and dynamic addressing, so you must permit additional ICMP types. This is a common oversight that breaks IPv6 connectivity. - **nftables is the modern firewall framework** (Middle): nftables offers a more streamlined syntax than iptables, with rule handles for precise insertion (e.g., `position 3`). It's the future of Linux firewalling, and learning it prepares you for newer distributions. 【Reading Tips】 - **Skim the early VM setup if you're experienced**: Chapters 1–2 (virtual environment, basic user creation) are essential for beginners but can be skimmed if you already have a Linux lab. Focus on the sudo and account management labs. - **Deep-read the firewall chapters (3–4)**: These are dense but critical. Practice iptables and nftables commands in your VM, and pay special attention to IPv6 ICMP rules—this is where many admins stumble. - **Follow the hands-on labs sequentially**: The book is lab-driven; each lab builds on previous concepts. Don't skip them, as they reinforce the commands and their real-world applications. - **Watch for distribution-specific quirks**: The book highlights differences (e.g., SUSE's sudo behavior, Ubuntu's lack of predefined aliases). Note these to avoid confusion when working across distros. - **Take away the command cheat-sheet**: For each chapter, jot down the key commands (`chage`, `usermod`, `iptables`, `nft`, `ecryptfs-*`) and their options. This will serve as a quick reference for daily admin tasks. 【Coverage Limits】 The excerpts primarily cover the opening through the firewall chapters (~48% of the book). Later topics (SSH hardening, SELinux/AppArmor, kernel hardening, auditing, logging, vulnerability scanning, fapolicyd) are listed in the table of contents but not detailed in the provided material.
Page 17
ilable. The chapters may be a little rough around the edges right now, but our authors will update them over time. You can dip in and out of this book or fol...
View in text
Excerpt 2
user account to the wheel group as the RHEL-type distros do. Instead, it automatically assigns the same password that you created for yourself to the root us...
View in text
Excerpt 3
've undoubtedly heard for your entire computer career says: Make passwords of a certain minimum length. Make passwords that consist of a combination of upper...
View in text
Excerpt 4
need the same types of ICMP messages that we need for IPv4. So, let's start with them: donnie@ubuntu3:~$ sudo ip6tables -A INPUT -p icmpv6 --icmpv6-type 1 -j...
View in text
Excerpt 5
at the next portion: Chain IN_public_allow (1 references) target prot opt source destination ACCEPT tcp -- anywhere anywhere tcp dpt:ssh ctstate NEW ACCEPT t...
View in text
Excerpt 6
ount with the -t ecryptfs option to encrypt the directory. Note that you’ll list the directory name twice, because the it will be used as its own mount point...
View in text
Excerpt 7
tu machine, just do the following: sudo apt install apache2 This also installs the mod_ssl package, which contains the libraries and configuration files for...
View in text
Excerpt 8
n. One is for Ubuntu 22.04, while the other is for CentOS 7. AlmaLinux 8 and 9 have their own unique way of doing business, so I'm saving that for the next s...
View in text
Tags
AI categories
LinuxCybersecurityDevOps
Publisher: Packt Publishing
Publish Year: 2023
Language: English
File Format: PDF
File Size: 11.2 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…