Difference between revisions of "SELinux,Fail2ban,Security Configurations"

From Rhomicom Wiki
Jump to navigation Jump to search
Line 43: Line 43:
 
   enabled = true
 
   enabled = true
  
−
   phpinfo,
+
   systemctl start fail2ban
 +
  sudo systemctl status fail2ban
 
   sudo systemctl restart fail2ban
 
   sudo systemctl restart fail2ban
 +
 
   sudo fail2ban-client status
 
   sudo fail2ban-client status
 
   sudo fail2ban-client status sshd
 
   sudo fail2ban-client status sshd
Line 51: Line 53:
 
   sudo fail2ban-client status wordpress3
 
   sudo fail2ban-client status wordpress3
 
   sudo fail2ban-client status http-get-post-dos
 
   sudo fail2ban-client status http-get-post-dos
 +
 
== Install Letsencrypt ==
 
== Install Letsencrypt ==
 
   dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm
 
   dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm

Revision as of 14:17, 30 January 2021

Install firewalld

 sudo yum install firewalld
 sudo systemctl start firewalld
 sudo systemctl enable firewalld
 sudo systemctl status firewalld
 sudo firewall-cmd --permanent --add-service=http
 sudo firewall-cmd --permanent --add-service=https
 sudo firewall-cmd --permanent --list-all
 sudo firewall-cmd --reload
 nano /etc/firewalld/firewalld.conf
 # AllowZoneDrifting=no

SELinux Permissions

 setsebool -P httpd_can_network_connect 1
 setsebool -P httpd_execmem 1
 setsebool -P httpd_setrlimit 1
 setsebool -P httpd_can_sendmail 1
 setsebool -P allow_httpd_mod_auth_pam 1
 setsebool -P httpd_mod_auth_pam 1
 setsebool -P httpd_read_user_content 1
 setsebool -P httpd_run_stickshift 1
 setsebool -