Show Menu
Cheatography

Linux Server Hardening Checklist Cheat Sheet by

A practical baseline for Linux servers. Adapt to your distribution, workload, and security policy.

Identity and Access

Create named admini­strator accounts; avoid routine direct root login. Use sudo with least privilege. Use SSH keys where practical. Disable password authen­tic­ation only after confirming key-based access works.
Set Permit­Roo­tLogin to prohib­it-­pas­sword or no. Review author­ize­d_keys, sudoers entries, inactive accounts, and privileged groups regularly. Use MFA or an access gateway for admini­str­ative access where available.

Logging, Backups, and Verifi­cation

Ensure time synchr­oni­zation is working and logs are retained centrally where possible. Configure backups for required data and system config­ura­tion. Period­ically test restor­ation. Protect secrets and private keys with restri­ctive permis­sions. Never commit creden­tials to reposi­tories.
Record baseline config­ura­tion. Period­ically review authen­tic­ation logs, updates, firewall rules, and exposed services. ss -tulpn Review listening sockets. systemctl --failed Identify failed systemd units. journalctl -p warnin­g..a­lert -b Review curren­t-boot warnings and higher­-se­verity messages.
 

Network and Host Protection

Defaul­t-deny inbound traffic where feasible. Allow only required ports from approp­riate source ranges. Restrict SSH exposure with firewall rules, VPN, or an access gateway when possible.
Use SELinux or AppArmor in enforcing mode where supported. Invest­igate securi­ty-­control denials rather than disabling controls by default. Protect cloud metadata services and management interfaces according to the platform's guidance.
 

Patch and Service Management

Apply security updates through your normal change process. Confirm reboot requir­ements for kernel and core-l­ibrary updates. Remove or disable packages, daemons, and listening services that are not required.
Check enabled services with: systemctl --type­=se­rvice --stat­e=r­unning Check listening sockets with: ss -tulpn Keep a supported OS release and a documented rollba­ck/­rec­overy plan.
 

Comments

No comments yet. Add yours below!

Add a Comment

Your Comment

Please enter your name.

    Please enter your email address

      Please enter your Comment.

          Related Cheat Sheets

          Linux Command Line Cheat Sheet
          mod_rewrite Cheat Sheet
          Linux RAID with mdadm Cheat Sheet