This is mostly a checklist of things that I need to research and automate.
- OpenSSH Hardening:
- Automated Security Updates
- Users/Groups
- Permissions
- Password requirements
- IPTables
- SELinux or/and GRSecurity ? (Need to research this)
- HIDS (Host-based Intrusion Detection System)
- Increase entropy by ensuring randomness
- https://www.inversoft.com/guides/2016-guide-to-user-data-security
- https://github.com/openstack/openstack-ansible-security
- https://github.com/geerlingguy/ansible-role-security
Note: If you somehow find this gist, feel free to leave comments with tips, critics, whatever...