What is the best way to secure a new Linux server?
Initial hardening steps
Start by updating all packages. Then create a regular user account with sudo privileges and disable direct root SSH login. Edit `/etc/ssh/sshd_config` to set `PermitRootLogin no` and `PasswordAuthentication no`, then restart SSH. Use SSH keys instead of passwords.
Configure a host firewall. On Ubuntu, `ufw` is common: allow OpenSSH, then enable it. On RHEL-based systems, use `firewalld`. Only open ports you actually need, such as 22 (SSH), 80 (HTTP), and 443 (HTTPS).
- Update all packages
- Create a non-root sudo user
- Disable root SSH login and password authentication
- Set up a firewall (ufw or firewalld)
- Enable automatic security updates
- Install fail2ban to block brute-force attempts
Ongoing maintenance
Security is not a one-time task. Regularly apply updates, monitor logs for suspicious activity, and remove unused services. Tools like `fail2ban` can automatically ban IPs after repeated failed logins.
For production servers, consider additional layers: SELinux or AppArmor, intrusion detection (e.g., AIDE), and centralized logging. The right level depends on your threat model and compliance needs.
Common mistakes
- Leaving password authentication enabled for SSH, which invites brute-force attacks.
- Opening all firewall ports or disabling the firewall entirely for convenience.
- Forgetting to test SSH key login before disabling password authentication, locking yourself out.
