
Description
Minutes after a new VPS goes live, its SSH log fills with password brute-force attempts from around the world, and most hardening tutorials either cover a tip or two or dump commands without explaining them. How To Secure A Linux Server is an open guide with over 30,000 GitHub stars that explains why each step matters, how it works and what it achieves before giving the exact steps.
It starts before installation and runs through SSH, accounts, firewalls, intrusion detection, auditing and kernel settings, turning a bare machine into a solid production server. It is licensed CC BY-SA 4.0, and a community Ansible playbook can apply the whole thing automatically.
SSH hardening: Key-based login, AllowGroups, a tightened sshd_config, removing short Diffie-Hellman moduli and 2FA for SSH.
The basics: Limit sudo and su, sandbox apps with FireJail, NTP, secure /proc, enforce strong passwords, and automatic security updates with alerts.
Network: UFW firewall setup, Docker and UFW together, and intrusion detection with PSAD, Fail2Ban and CrowdSec.
Auditing: AIDE integrity monitoring, ClamAV, Rkhunter and chkrootkit, logwatch reports, Lynis audits and OSSEC host intrusion detection.
Danger zone: sysctl kernel hardening, GRUB passwords, disabling root login and changing the default umask, each with its risks spelled out.
Email alerts: Use MSMTP or Exim4 so the server mails you about security events.
It starts before installation and runs through SSH, accounts, firewalls, intrusion detection, auditing and kernel settings, turning a bare machine into a solid production server. It is licensed CC BY-SA 4.0, and a community Ansible playbook can apply the whole thing automatically.
Features
SSH hardening: Key-based login, AllowGroups, a tightened sshd_config, removing short Diffie-Hellman moduli and 2FA for SSH.
The basics: Limit sudo and su, sandbox apps with FireJail, NTP, secure /proc, enforce strong passwords, and automatic security updates with alerts.
Network: UFW firewall setup, Docker and UFW together, and intrusion detection with PSAD, Fail2Ban and CrowdSec.
Auditing: AIDE integrity monitoring, ClamAV, Rkhunter and chkrootkit, logwatch reports, Lynis audits and OSSEC host intrusion detection.
Danger zone: sysctl kernel hardening, GRUB passwords, disabling root login and changing the default umask, each with its risks spelled out.
Email alerts: Use MSMTP or Exim4 so the server mails you about security events.

