Transcription of Security Guide - A Guide to Securing Red Hat Enterprise Linux
1 Red Hat Enterprise Linux 6 Security GuideA Guide to Securing Red Hat Enterprise LinuxSecurity GuideRed Hat Enterprise Linux 6 Security GuideA Guide to Securing Red Hat Enterprise LinuxEdition 2010 Red Hat, text of and illustrations in this document are licensed by Red Hat under a Creative CommonsAttribution Share Alike Unported license ("CC-BY-SA"). An explanation of CC-BY-SA is availableat In accordance with CC-BY-SA, if you distribute thisdocument or an adaptation of it, you must provide the URL for the original Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert,Section 4d of CC-BY-SA to the fullest extent permitted by applicable Hat, Red Hat Enterprise Linux , the Shadowman logo, JBoss, MetaMatrix, Fedora, the InfinityLogo, and RHCE are trademarks of Red Hat, Inc.
2 , registered in the United States and other is the registered trademark of Linus Torvalds in the United States and other is a registered trademark of Oracle and/or its is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United Statesand/or other is a registered trademark of MySQL AB in the United States, the European Union and other trademarks are the property of their respective owners. 1801 Varsity Drive Raleigh, NC 27606-2072 USA Phone: +1 919 754 3700 Phone: 888 733 4281 Fax: +1 919 754 3701 The Red Hat Enterprise Linux Security Guide is designed to assist users and administrators inlearning the processes and practices of Securing workstations and servers against local and remoteintrusion, exploitation and malicious on Red Hat Enterprise Linux but detailing concepts and techniques valid for all Linuxsystems, this Guide details the planning and the tools involved in creating a secured computingenvironment for the data center, workplace, and proper administrative knowledge, vigilance, and tools.
3 Systems running Linux can be both fullyfunctional and secured from most common intrusion and exploit vii1. Document Conventions .. Typographic Conventions .. Pull-quote Conventions .. Notes and Warnings .. ix2. We Need Feedback! .. ix1. Security Overview Introduction to Security .. What is Computer Security ? .. SELinux .. Security Controls .. Conclusion .. Vulnerability Assessment .. Thinking Like the Enemy.
4 Defining Assessment and Testing .. Evaluating the Tools .. Attackers and Vulnerabilities .. A Quick History of Hackers .. Threats to Network Security .. Threats to Server Security .. Threats to Workstation and Home PC Security .. Common Exploits and Attacks .. Security Updates .. Updating Packages .. Verifying Signed Packages .. Installing Signed Packages .. Applying the Changes .. 172. Securing Your Network Workstation Security .. Evaluating Workstation Security .. BIOS and Boot Loader Security .
5 Password Security .. Administrative Controls .. Available Network Services .. Personal Firewalls .. Security Enhanced Communication Tools .. Server Security .. Securing Services With TCP Wrappers and xinetd .. Securing Portmap .. Securing NIS .. Securing NFS .. Securing the Apache HTTP Server .. Securing FTP .. Securing Sendmail .. Verifying Which Ports Are Listening .. TCP Wrappers and xinetd .. TCP Wrappers .. TCP Wrappers Configuration Files .. xinetd .. xinetd Configuration Files .. Additional Resources .. Virtual Private Networks (VPNs) .. How Does a VPN Work?
6 67 Security Openswan .. Firewalls .. Netfilter and IPTables .. Basic Firewall Configuration .. Using IPTables .. Common IPTables Filtering .. FORWARD and NAT Rules .. Malicious Software and Spoofed IP Addresses .. IPTables and Connection Tracking .. IPv6 .. Additional Resources .. IPTables .. Packet Filtering .. Command Options for IPTables .. Saving IPTables Rules .. IPTables Control Scripts .. IPTables and IPv6 .. Additional Resources .. 943. Encryption Data at Rest.
7 Full Disk Encryption .. File Based Encryption .. Data in Motion .. Virtual Private Networks .. Secure Shell .. OpenSSL PadLock Engine .. LUKS Disk Encryption .. LUKS Implementation in Red Hat Enterprise Linux .. Manually Encrypting Directories .. Step-by-Step Instructions .. What you have just accomplished.. Links of Interest .. Using GNU Privacy Guard (GnuPG) .. Creating GPG Keys in GNOME .. Creating GPG Keys in KDE .. Creating GPG Keys Using the Command Line .. About Public Key Encryption .. 1014. General Principles of Information Security Tips, Guides, and Tools.
8 1035. Secure Installation Disk Partitions .. Utilize LUKS Partition Encryption .. 1056. Software Maintenance Install Minimal Software .. Plan and Configure Security Updates .. Adjusting Automatic Updates .. Install Signed Packages from Well Known Repositories .. 1077. Federal Standards and Regulations Introduction .. Federal Information Processing Standard (FIPS) .. National Industrial Security Program Operating Manual (NISPOM).
9 Payment Card Industry Data Security Standard (PCI DSS) .. Security Technical Implementation Guide .. 1108. References 111A. Encryption Standards Synchronous Encryption .. Advanced Encryption Standard - AES .. Data Encryption Standard - DES .. Public-key Encryption .. Diffie-Hellman .. RSA .. DSA .. SSL/TLS .. Cramer-Shoup Cryptosystem .. ElGamal Encryption .. 116B. Revision History 117viviiPreface1.
10 Document ConventionsThis manual uses several conventions to highlight certain words and phrases and draw attention tospecific pieces of PDF and paper editions, this manual uses typefaces drawn from the Liberation Fonts1 set. TheLiberation Fonts set is also used in HTML editions if the set is installed on your system. If not,alternative but equivalent typefaces are displayed. Note: Red Hat Enterprise Linux 5 and later includesthe Liberation Fonts set by Typographic ConventionsFour typographic conventions are used to call attention to specific words and phrases. Theseconventions, and the circumstances they apply to, are as BoldUsed to highlight system input, including shell commands, file names and paths. Also used to highlightkeycaps and key combinations.