[SOLVED] information on hardening my linux laptop

This forum is dedicated to basic help and support :

Ask here your questions about basic installation and usage of Mageia. For example you may post here all your questions about getting Mageia isos and installing it, configuring your printer, using your word processor etc.

Try to ask your questions in the right sub-forum with as much details as you can gather. the more precise the question will be, the more likely you are to get a useful answer

[SOLVED] information on hardening my linux laptop

Postby nwtmg » Sep 2nd, '18, 11:16

Hi,
Using mageia 5 on a toshiba laptop with 2 gig of ram and openbox. Looking for information on hardening my version of linux. i have checked on google and they all mention various other versions but nothing particular to mageia. Thanks for your support.
Last edited by nwtmg on Sep 3rd, '18, 20:17, edited 1 time in total.
nwtmg
 
Posts: 155
Joined: Jun 2nd, '15, 22:14

Re: information on hardening my linux laptop

Postby JoesCat » Sep 3rd, '18, 00:34

Mageia has software called "msec" (you have GUI access and setup through the Mageia Control Center).

For most users, the default settings are recommended and fine for least fuss.
If you know what you want to do, you can set the permissions harder, and also customize as you like.

In terms of some customization, I've twiddled a little with it and explain it on installing a self-start boinc here:
http://www.joescat.com/boinc/
FYI - This howto needs updating (from 2009), and msec had a big upgrade (improvements and files moved) but the basic info here is ok for what you're interested in doing.

If you're interested in customizations, you can edit settings like:
For example setting permissions for /home from 755 to 750 and other setting customizations with reduced group and other accesses. One item of note is that newer software (today) appears to have the concepts of users less understood, so if you had older programs like (example cups) running as user=printer, now it seems the defaults are user root, where more programs seem to default to root....this goes against your attempts to harden by running daemons as non-root with less privledges.

You mention mageia5... If you're going for a new install, you may want to think of mageia6 since it's a long term release version. Mageia5 support ended fairly recently. Additionally, if you are installing fresh from a live distro, I would recommend start with creating a new user (for your install), and removing "live" after install (live is user 1000. new user starting at 1001).
User avatar
JoesCat
 
Posts: 177
Joined: Sep 15th, '11, 04:27
Location: Richmond, BC, Canada

Re: information on hardening my linux laptop

Postby doktor5000 » Sep 3rd, '18, 13:10

As mentioned, if you think about hardening, first thing would be to upgrade to Mageia 6, as 5 is basically already end of life: https://www.mageia.org/en-gb/support/#lifecycle

Regarding hardening itself, take a look at http://doc.mageia.org/mcc/6/en/content/msecgui.html and https://wiki.mageia.org/en/Msec for some more information.
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 17659
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: information on hardening my linux laptop

Postby wintpe » Sep 3rd, '18, 13:25

you may also want to look at the CIS standards for some background to many of the settings.

we use this on rhel, where we dont have msec.

im sure msec covers some of this already, but its interesting that theres a standard for hardening, and this is also what security scanners such as qualys use.

its not the be all and end all, understand these settings and their impact before going forward with them, but its a good check list.

the doc is free to download, you just have to register.

https://www.cisecurity.org/

regards peter
Redhat 6 Certified Engineer (RHCE)
Sometimes my posts will sound short, or snappy, however its realy not my intention to offend, so accept my apologies in advance.
wintpe
 
Posts: 1204
Joined: May 22nd, '11, 17:08
Location: Rayleigh,, Essex , UK

Re: [SOLVED] information on hardening my linux laptop

Postby nwtmg » Sep 3rd, '18, 20:18

Thanks to all for the assistance. Will take a look at all the recommended solutions. Marked as solved.
nwtmg
 
Posts: 155
Joined: Jun 2nd, '15, 22:14

Re: [SOLVED] information on hardening my linux laptop

Postby doktor5000 » Sep 4th, '18, 07:13

On a related note, I can also recommend Lynis: https://cisofy.com/lynis/
It's good to take an audit scan of your system which might highlight things that you should take a look at.
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 17659
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany


Return to Basic support

Who is online

Users browsing this forum: No registered users and 1 guest