Boards.ie uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Click here to find out more x
Post Reply  
 
Thread Tools Search this Thread
18-07-2012, 16:26   #1
Standard Toaster
ǝpıɹ ǝɥʇ ǝʞɐʇ 'ʇǝʞɔıʇ ǝɥʇ ʎnq
 
Standard Toaster's Avatar
 
Join Date: Nov 2002
Posts: 9,080
Hardening scripts

Hey,

Was just looking to see if anyone has any hardening scripts for the likes of Red Hat-CentOS 5->6 and Solaris 9->11?

I've a number of servers to harden and would like to automate it if possible. These would be mainly web servers.

I have a generic script based on CIS_Redhat_Linux_5_Benchmark_v2.0.0 for RH to harden the box which I'll post up later.

Any input?
Standard Toaster is offline  
Advertisement
19-07-2012, 22:17   #2
Saganist
Registered User
 
Saganist's Avatar
 
Join Date: Feb 2010
Location: The Wall
Posts: 844
For Solaris google SUNWjass.

Its a hardening package that should do the business.
Saganist is offline  
Thanks from:
19-07-2012, 23:34   #3
Standard Toaster
ǝpıɹ ǝɥʇ ǝʞɐʇ 'ʇǝʞɔıʇ ǝɥʇ ʎnq
 
Standard Toaster's Avatar
 
Join Date: Nov 2002
Posts: 9,080
Cheers for that, will have a sniff of it tomorrow.
Standard Toaster is offline  
17-08-2012, 09:52   #4
madhatter76
Registered User
 
Join Date: Feb 2009
Posts: 63
Bumping this again.

for RHEL there are several scripts from https://fedorahosted.org/aqueduct/. But they seems to be outdated and not updated anymore.

Could you post or send or give tghe link please the one you have for CIS_Redhat_Linux_5_Benchmark_v2.0.0 which is the latest?
madhatter76 is offline  
Thanks from:
18-08-2012, 09:47   #5
croo
Moderator
 
Join Date: Aug 2006
Location: Westmeath
Posts: 885
Quote:
Originally Posted by Standard Toaster View Post
Hey,

Was just looking to see if anyone has any hardening scripts for the likes of Red Hat-CentOS 5->6 and Solaris 9->11?

I've a number of servers to harden and would like to automate it if possible. These would be mainly web servers.

I have a generic script based on CIS_Redhat_Linux_5_Benchmark_v2.0.0 for RH to harden the box which I'll post up later.

Any input?
I haven't tried it in many years but I used to run Bastille on my debian servers way back to harden them.

A little googling tells me you can run it on redhat too
http://bastille-linux.sourceforge.ne...astille_on.htm

I assume you enabled SELinux on the install.
croo is offline  
Advertisement
18-08-2012, 09:59   #6
syklops
Registered User
 
syklops's Avatar
 
Join Date: Sep 2004
Location: Athlone, Ireland
Posts: 11,743
If you didn't already, read the hardening guide from the NSA:
http://www.nsa.gov/ia/_files/os/redh...guide-i731.pdf

Its for RHEL 5 but most things should work for RHEL 6. There are many commands mentioned, so just put them together into a script(each command on a new line).
syklops is offline  
(2) thanks from:
24-08-2012, 20:49   #7
Ant
Registered User
 
Join Date: Sep 2001
Location: Baile Átha Cliath
Posts: 411
Quote:
Originally Posted by syklops View Post
If you didn't already, read the hardening guide from the NSA:
http://www.nsa.gov/ia/_files/os/redh...guide-i731.pdf

Its for RHEL 5 but most things should work for RHEL 6. There are many commands mentioned, so just put them together into a script(each command on a new line).
That's a great document. It gives just the right amount of explanatory information for the likes of me who doesn't want to just run some hardening script without knowing exactly what it's doing. A while back, I was helping another friend with a CentOS system and it took me a while to figure out what all those default services were doing. This would have been very useful at the time.

Unfortunately, I'm currently an Ubuntu user so it'll take extra time to transfer the instructions in this guide to an Ubuntu system.
Ant is offline  
Thanks from:
26-08-2012, 22:41   #8
syklops
Registered User
 
syklops's Avatar
 
Join Date: Sep 2004
Location: Athlone, Ireland
Posts: 11,743
Quote:
Originally Posted by Ant View Post
That's a great document. It gives just the right amount of explanatory information for the likes of me who doesn't want to just run some hardening script without knowing exactly what it's doing. A while back, I was helping another friend with a CentOS system and it took me a while to figure out what all those default services were doing. This would have been very useful at the time.

Unfortunately, I'm currently an Ubuntu user so it'll take extra time to transfer the instructions in this guide to an Ubuntu system.
I started work on a new version for RHEL 6, but my circumstances have changed a little and need to dive into OpenVMS(which is about as open as I am a lobster), so if you need any further help let me know.
syklops is offline  
Thanks from:
Post Reply

Quick Reply
Message:
Remove Text Formatting
Bold
Italic
Underline

Insert Image
Wrap [QUOTE] tags around selected text
 
Decrease Size
Increase Size
Please sign up or log in to join the discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search