Difference between revisions of "SELinux,Fail2ban,Security Configurations"
Jump to navigation
Jump to search
| Line 51: | Line 51: | ||
sudo fail2ban-client status wordpress3 | sudo fail2ban-client status wordpress3 | ||
sudo fail2ban-client status http-get-post-dos | sudo fail2ban-client status http-get-post-dos | ||
| + | == Install Letsencrypt == | ||
| + | dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm | ||
| + | # (for centos 8) dnf config-manager --set-enabled PowerTools | ||
| + | sudo dnf install certbot python3-certbot-nginx | ||
| + | OR dnf install certbot python3-certbot-apache | ||
| + | |||
| + | certbot --version | ||
| + | certbot --nginx | ||
| + | OR certbot --apache | ||
| + | |||
| + | certbot renew | ||
| + | certbot certificates | ||
| + | certbot certonly --apache | ||
| + | certbot certonly --nginx | ||
| + | |||
| + | echo "0 0,12 * * * root python3 -c 'import random; import time; time.sleep(random.random() * 3600)' && certbot renew -q" | sudo tee -a /etc/crontab > /dev/null | ||
Revision as of 12:09, 30 January 2021
Install firewalld
sudo yum install firewalld sudo systemctl start firewalld sudo systemctl enable firewalld sudo systemctl status firewalld
sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https sudo firewall-cmd --permanent --list-all sudo firewall-cmd --reload
nano /etc/firewalld/firewalld.conf # AllowZoneDrifting=no
SELinux Permissions
setsebool -P httpd_can_network_connect 1 setsebool -P httpd_exe