logoalt Hacker News

Ansible battle tested hardening for Linux, SSH, Nginx, MySQL

42 pointsby walterbelllast Wednesday at 5:38 PM10 commentsview on HN

Comments

yjftsjthsd-hyesterday at 7:34 PM

"battle tested" how? Widely deployed? Red teamed and shown to actually help?

show 1 reply
TacticalCoderyesterday at 10:40 PM

The Linux hardening list lists quite some modifications but what hardening is made to SSH compared to a stock config? For Linux they summarize the list of hardened changes but for SSH I couldn't find it.

For SSH it's basically a list of default values with a comment saying "change this if you must". Some summary as to what is hardened compared to a stock SSH install would be nice.

show 1 reply
Spivakyesterday at 8:58 PM

These playbooks apply the CIS benchmarks, very very useful for compliance. I use them at $dayjob to build our base AMIs.

As for whether they actually harden your servers, that's up for you to decide if you think that CIS actually helps. It certainly does reduce attack surface.

show 2 replies
mhbyesterday at 7:58 PM

What does this mean?

show 1 reply