Example: bankruptcy

Red Hat Enterprise Linux 8 Security hardening

red hat Enterprise Linux 8 Security hardeningSecuring red hat Enterprise Linux 8 Last Updated: 2022-06-13 red hat Enterprise Linux 8 Security hardeningSecuring red hat Enterprise Linux 8 Legal NoticeCopyright 2022 red hat , text of and illustrations in this document are licensed by red hat under a Creative CommonsAttribution Share Alike Unported license ("CC-BY-SA"). An explanation of CC-BY-SA isavailable In accordance with CC-BY-SA, if you distribute this document or an adaptation of it, you mustprovide the URL for the original Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert,Section 4d of CC-BY-SA to the fullest extent permitted by applicable Hat, red hat Enterprise Linux , the Shadowman logo, the red hat logo, JBoss, OpenShift,Fedora, the Infinity logo, and RHCE are trademarks of red hat , Inc.

Mar 18, 2022 · Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted by applicable law. Red Hat, Red Hat Enterprise Linux, the Shadowman logo, the Red Hat logo, JBoss, OpenShift,

Tags:

  Security, Linux, Enterprise, Hardening, Red hat, Red hat enterprise linux 8 security hardening, Red hat enterprise

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Red Hat Enterprise Linux 8 Security hardening

1 red hat Enterprise Linux 8 Security hardeningSecuring red hat Enterprise Linux 8 Last Updated: 2022-06-13 red hat Enterprise Linux 8 Security hardeningSecuring red hat Enterprise Linux 8 Legal NoticeCopyright 2022 red hat , text of and illustrations in this document are licensed by red hat under a Creative CommonsAttribution Share Alike Unported license ("CC-BY-SA"). An explanation of CC-BY-SA isavailable In accordance with CC-BY-SA, if you distribute this document or an adaptation of it, you mustprovide the URL for the original Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert,Section 4d of CC-BY-SA to the fullest extent permitted by applicable Hat, red hat Enterprise Linux , the Shadowman logo, the red hat logo, JBoss, OpenShift,Fedora, the Infinity logo, and RHCE are trademarks of red hat , Inc.

2 , registered in the United Statesand other is the registered trademark of Linus Torvalds in the United States and other is a registered trademark of Oracle and/or its is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United Statesand/or other is a registered trademark of MySQL AB in the United States, the European Union andother is an official trademark of Joyent. red hat is not formally related to or endorsed by theofficial Joyent open source or commercial OpenStack Word Mark and OpenStack logo are either registered trademarks/service marksor trademarks/service marks of the OpenStack Foundation, in the United States and othercountries and are used with the OpenStack Foundation's permission.

3 We are not affiliated with,endorsed or sponsored by the OpenStack Foundation, or the OpenStack other trademarks are the property of their respective title assists users and administrators in learning the processes and practices of securingworkstations and servers against local and remote intrusion, exploitation, and malicious on red hat Enterprise Linux but detailing concepts and techniques valid for all Linuxsystems, this guide details the planning and the tools involved in creating a secured computingenvironment for the data center, workplace, and home. With proper administrative knowledge,vigilance, and tools, systems running Linux can be both fully functional and secured from mostcommon intrusion and exploit.

4 Table of ContentsMAKING OPEN SOURCE MORE INCLUSIVEPROVIDING FEEDBACK ON red hat DOCUMENTATIONCHAPTER 1. OVERVIEW OF Security hardening IN WHAT IS COMPUTER Security ? STANDARDIZING CRYPTOGRAPHIC SOFTWARE AND Security Physical Technical Administrative VULNERABILITY Defining assessment and Establishing a methodology for vulnerability Vulnerability assessment Security Threats to network Threats to server Threats to workstation and home PC COMMON EXPLOITS AND ATTACKSCHAPTER 2. SECURING RHEL DURING BIOS AND UEFI BIOS Non-BIOS-based systems DISK RESTRICTING NETWORK CONNECTIVITY DURING THE INSTALLATION INSTALLING THE MINIMUM AMOUNT OF PACKAGES POST-INSTALLATION PROCEDURESCHAPTER 3.

5 INSTALLING A RHEL 8 SYSTEM WITH FIPS MODE FEDERAL INFORMATION PROCESSING STANDARD (FIPS) INSTALLING THE SYSTEM WITH FIPS MODE ADDITIONAL RESOURCESCHAPTER 4. USING SYSTEM-WIDE CRYPTOGRAPHIC SYSTEM-WIDE CRYPTOGRAPHIC POLICIESTool for managing crypto policiesStrong crypto defaults by removing insecure cipher suites and protocolsCipher suites and protocols disabled in all policy levelsCipher suites and protocols enabled in the crypto-policies SWITCHING THE SYSTEM-WIDE CRYPTOGRAPHIC POLICY TO MODE COMPATIBLE WITH SWITCHING THE SYSTEM TO FIPS ENABLING FIPS MODE IN A LIST OF RHEL APPLICATIONS USING CRYPTOGRAPHY THAT IS NOT COMPLIANT WITH FIPS EXCLUDING AN APPLICATION FROM FOLLOWING SYSTEM-WIDE CRYPTO Examples of opting out of system-wide crypto CUSTOMIZING SYSTEM-WIDE CRYPTOGRAPHIC POLICIES WITH DISABLING SHA-1 BY CUSTOMIZING A SYSTEM-WIDE

6 CRYPTOGRAPHIC CREATING AND SETTING A CUSTOM SYSTEM-WIDE CRYPTOGRAPHIC POLICY6788889991010101212121213141519191 9191920202022222223242425252526272728293 030313334 Table of Contents1.. ADDITIONAL RESOURCESCHAPTER 5. SETTING A CUSTOM CRYPTOGRAPHIC POLICY ACROSS CRYPTOGRAPHIC POLICIES SYSTEM ROLE VARIABLES AND SETTING A CUSTOM CRYPTOGRAPHIC POLICY USING THE CRYPTOGRAPHIC POLICIES SYSTEM ADDITIONAL RESOURCESCHAPTER 6. CONFIGURING APPLICATIONS TO USE CRYPTOGRAPHIC HARDWARE THROUGH PKCS # CRYPTOGRAPHIC HARDWARE SUPPORT THROUGH PKCS # USING SSH KEYS STORED ON A SMART CONFIGURING APPLICATIONS TO AUTHENTICATE USING CERTIFICATES FROM SMART USING HSMS PROTECTING PRIVATE KEYS IN USING HSMS PROTECTING PRIVATE KEYS IN ADDITIONAL RESOURCESCHAPTER 7.

7 CONTROLLING ACCESS TO SMART CARDS USING SMART-CARD ACCESS CONTROL THROUGH TROUBLESHOOTING PROBLEMS RELATED TO PC/SC AND DISPLAYING MORE DETAILED INFORMATION ABOUT POLKIT AUTHORIZATION TO ADDITIONAL RESOURCESCHAPTER 8. USING SHARED SYSTEM THE SYSTEM-WIDE TRUST ADDING NEW MANAGING TRUSTED SYSTEM ADDITIONAL RESOURCESCHAPTER 9. SCANNING THE SYSTEM FOR CONFIGURATION COMPLIANCE AND CONFIGURATION COMPLIANCE TOOLS IN VULNERABILITY red hat Security Advisories OVAL Scanning the system for Scanning remote systems for CONFIGURATION COMPLIANCE Configuration compliance in Possible results of an OpenSCAP Viewing profiles for configuration Assessing configuration compliance with a specific REMEDIATING THE SYSTEM TO ALIGN WITH A SPECIFIC REMEDIATING THE SYSTEM TO ALIGN WITH A SPECIFIC BASELINE USING AN SSG CREATING A REMEDIATION ANSIBLE PLAYBOOK TO ALIGN THE SYSTEM WITH A SPECIFIC CREATING A REMEDIATION BASH SCRIPT FOR A LATER SCANNING THE SYSTEM WITH A CUSTOMIZED PROFILE USING SCAP Using SCAP Workbench to scan

8 And remediate the Customizing a Security profile with SCAP Additional DEPLOYING SYSTEMS THAT ARE COMPLIANT WITH A Security PROFILE IMMEDIATELY AFTER Profiles not compatible with Server with Deploying baseline-compliant RHEL systems using the graphical Deploying baseline-compliant RHEL systems using Kickstart3536363638393939414142424343434 5464747474849505050505152535354545556575 8596060616364646566 red hat Enterprise Linux 8 Security hardening2.. SCANNING CONTAINER AND CONTAINER IMAGES FOR ASSESSING Security COMPLIANCE OF A CONTAINER OR A CONTAINER IMAGE WITH A SCAP Security GUIDE PROFILES SUPPORTED IN RHEL ADDITIONAL RESOURCESCHAPTER 10. CHECKING INTEGRITY WITH INSTALLING PERFORMING INTEGRITY CHECKS WITH UPDATING AN AIDE FILE-INTEGRITY TOOLS: AIDE AND ADDITIONAL RESOURCESCHAPTER 11.

9 ENHANCING Security WITH THE KERNEL INTEGRITY THE KERNEL INTEGRITY INTEGRITY MEASUREMENT EXTENDED VERIFICATION TRUSTED AND ENCRYPTED WORKING WITH TRUSTED WORKING WITH ENCRYPTED ENABLING INTEGRITY MEASUREMENT ARCHITECTURE AND EXTENDED VERIFICATION COLLECTING FILE HASHES WITH INTEGRITY MEASUREMENT ARCHITECTURECHAPTER 12. ENCRYPTING BLOCK DEVICES USING LUKS DISK LUKS VERSIONS IN OPTIONS FOR DATA PROTECTION DURING LUKS2 ENCRYPTING EXISTING DATA ON A BLOCK DEVICE USING ENCRYPTING EXISTING DATA ON A BLOCK DEVICE USING LUKS2 WITH A DETACHED ENCRYPTING A BLANK BLOCK DEVICE USING CREATING A LUKS ENCRYPTED VOLUME USING THE STORAGE SYSTEM ROLECHAPTER 13. CONFIGURING AUTOMATED UNLOCKING OF ENCRYPTED VOLUMES USING NETWORK-BOUND DISK INSTALLING AN ENCRYPTION CLIENT - DEPLOYING A TANG SERVER WITH SELINUX IN ENFORCING ROTATING TANG SERVER KEYS AND UPDATING BINDINGS ON CONFIGURING AUTOMATED UNLOCKING USING A TANG KEY IN THE WEB BASIC NBDE AND TPM2 ENCRYPTION-CLIENT CONFIGURING MANUAL ENROLLMENT OF LUKS-ENCRYPTED CONFIGURING MANUAL ENROLLMENT OF LUKS-ENCRYPTED VOLUMES USING A TPM REMOVING A CLEVIS PIN FROM A LUKS-ENCRYPTED VOLUME CONFIGURING AUTOMATED ENROLLMENT OF LUKS-ENCRYPTED VOLUMES USING CONFIGURING AUTOMATED UNLOCKING OF A LUKS-ENCRYPTED REMOVABLE STORAGE DEPLOYING HIGH-AVAILABILITY NBDE High-available NBDE using Shamir s Secret

10 Example 1: Redundancy with two Tang Example 2: Shared secret on a Tang server and a TPM DEPLOYMENT OF VIRTUAL MACHINES IN A NBDE BUILDING AUTOMATICALLY-ENROLLABLE VM IMAGES FOR CLOUD ENVIRONMENTS USING DEPLOYING TANG AS A CONTAINER6768697476767677777879798080818 1838386888889909091929395959697981001031 05107109110111112112113113114114115 Table of Contents3.. INTRODUCTION TO THE CLEVIS AND TANG SYSTEM USING THE NBDE SERVER SYSTEM ROLE FOR SETTING UP MULTIPLE TANG USING THE NBDE CLIENT SYSTEM ROLE FOR SETTING UP MULTIPLE CLEVIS ADDITIONAL RESOURCESCHAPTER 14. AUDITING THE Linux AUDIT SYSTEM CONFIGURING AUDITD FOR A SECURE STARTING AND CONTROLLING UNDERSTANDING AUDIT LOG USING AUDITCTL FOR DEFINING AND EXECUTING AUDIT DEFINING PERSISTENT AUDIT USING PRE-CONFIGURED RULES USING AUGENRULES TO DEFINE PERSISTENT DISABLING SETTING UP AUDIT TO MONITOR SOFTWARE MONITORING USER LOGIN TIMES WITH ADDITIONAL RESOURCESCHAPTER 15.


Related search queries