Linux Security Hardening: A Practical Server Checklist
Securing a server is a set of habits, not a single action. Here is the checklist I run through on every new machine before it goes live. Securing a Linux server is not a single action but a set of habits applied consistently. After hardening dozens of production servers, I have a checklist I run through on every new machine before it goes live. The goal is not perfect security, which does reducing the obvious attack surface so that the common automated attacks fail and the real threats are easier to spot. SSH: Disable Password Login The first change I make is disabling SSH password authentication and root login. Passwords are guessed by bots constantly, and root login over SSH is the highest-value target. Key-only login removes both risks. # /etc/ssh/sshd_config PasswordAuthentication no PermitRootLogin no PubkeyAuthentication yes # Then reload sudo systemctl reload sshd Before reloading, I keep my current SSH session open and test login from a second terminal. If key login fails, I still have the open session to fix the config. Locking yourself out is the most common mistake here. Firewall: Default Deny A firewall with a default-deny policy means only the ports you…