Difference between revisions of "SELinux,Fail2ban,Security Configurations"

From Rhomicom Wiki
Jump to navigation Jump to search
Line 51: Line 51:
 
   sudo fail2ban-client status wordpress3
 
   sudo fail2ban-client status wordpress3
 
   sudo fail2ban-client status http-get-post-dos
 
   sudo fail2ban-client status http-get-post-dos
 +
== Install Letsencrypt ==
 +
  dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm
 +
  # (for centos 8) dnf config-manager --set-enabled PowerTools
 +
  sudo dnf install certbot python3-certbot-nginx
 +
  OR dnf install certbot python3-certbot-apache
 +
 +
  certbot --version
 +
  certbot --nginx
 +
  OR certbot --apache
 +
 +
  certbot renew
 +
  certbot certificates
 +
  certbot certonly --apache
 +
  certbot certonly --nginx
 +
 +
  echo "0 0,12 * * * root python3 -c 'import random; import time; time.sleep(random.random() * 3600)' && certbot renew -q" | sudo tee -a /etc/crontab > /dev/null

Revision as of 12:09, 30 January 2021

Install firewalld

 sudo yum install firewalld
 sudo systemctl start firewalld
 sudo systemctl enable firewalld
 sudo systemctl status firewalld
 sudo firewall-cmd --permanent --add-service=http
 sudo firewall-cmd --permanent --add-service=https
 sudo firewall-cmd --permanent --list-all
 sudo firewall-cmd --reload
 nano /etc/firewalld/firewalld.conf
 # AllowZoneDrifting=no

SELinux Permissions

 setsebool -P httpd_can_network_connect 1
 setsebool -P httpd_exe