深色模式
Linux 基线加固:关闭无用服务与修改默认配置
摘要:基线加固的目标是把一台默认安装的机器收到"最小可用"状态。本文按服务、账号口令、内核参数、文件权限、日志五个维度给出可复制命令。具体条目请以你组织的基线标准为准,本文只给通用做法。
适用环境
bash
cat /etc/os-release
systemctl --version
getenforce 2>/dev/null || echo "no SELinux"
command -v aa-status >/dev/null && aa-status --enabled && echo "AppArmor on"1
2
3
4
2
3
4
操作步骤
1. 关闭无用服务与端口
bash
systemctl list-unit-files --state=enabled | grep -E 'telnet|rsh|ftp|rpcbind|cups|avahi|nfs|smb|xinetd'
ss -lntup
# 逐个确认后关闭(示例)
systemctl disable --now avahi-daemon cups rpcbind 2>/dev/null1
2
3
4
2
3
4
不要一次性批量 disable --now
先 systemctl list-unit-files 确认用途,尤其是 rpcbind/nfs 可能被存储挂载依赖。逐台灰度。
2. 账号与口令策略
bash
# 口令复杂度:确认 pam_pwquality 已启用
grep -n pam_pwquality /etc/pam.d/system-auth /etc/pam.d/common-password 2>/dev/null
# RHEL 8+ 可用 authselect 开启(若系统使用 authselect)
authselect current 2>/dev/null && authselect enable-feature with-pwquality
cat >/etc/security/pwquality.conf.d/99-hardening.conf <<'EOF'
minlen = 12
dcredit = -1
ucredit = -1
lcredit = -1
ocredit = -1
retry = 3
EOF1
2
3
4
5
6
7
8
9
10
11
12
2
3
4
5
6
7
8
9
10
11
12
口令有效期与失败锁定:
bash
sed -i 's/^PASS_MAX_DAYS.*/PASS_MAX_DAYS 90/' /etc/login.defs
sed -i 's/^PASS_MIN_DAYS.*/PASS_MIN_DAYS 1/' /etc/login.defs
sed -i 's/^PASS_WARN_AGE.*/PASS_WARN_AGE 14/' /etc/login.defs
chage -M 90 -W 14 opsuser
chage -l opsuser1
2
3
4
5
2
3
4
5
清理无用系统账号:
bash
awk -F: '$3>=1000 && $3<65534 {print $1, $3}' /etc/passwd
for u in games news ftp gopher; do usermod -L $u 2>/dev/null; done
awk -F: '$2=="" {print "空口令账号:", $1}' /etc/shadow1
2
3
2
3
3. 内核参数(sysctl)加固
bash
cat >/etc/sysctl.d/99-hardening.conf <<'EOF'
net.ipv4.ip_forward = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.rp_filter = 1
net.ipv4.icmp_echo_ignore_broadcasts = 1
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.all.accept_source_route = 0
kernel.dmesg_restrict = 1
kernel.kptr_restrict = 2
kernel.yama.ptrace_scope = 1
fs.suid_dumpable = 0
EOF
sysctl --system1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
路由/网关机器不要关 ip_forward
net.ipv4.ip_forward = 0 会直接断掉转发功能。网关、K8s 节点、VPN 服务器需保留为 1 并另行加固。
4. 文件权限与危险位
bash
chmod 600 /etc/shadow /etc/gshadow
chmod 644 /etc/passwd /etc/group
stat -c '%a %n' /etc/passwd /etc/shadow /etc/ssh/sshd_config
find / -xdev -type f -perm -0002 -not -path "/proc/*" -not -path "/tmp/*" -ls 2>/dev/null | head
find / -xdev -perm -4000 -type f -ls 2>/dev/null | head1
2
3
4
5
2
3
4
5
5. 强制访问控制
bash
# SELinux
getenforce
setenforce 1
sed -i 's/^SELINUX=.*/SELINUX=enforcing/' /etc/selinux/config
# AppArmor(Debian 系)
systemctl enable --now apparmor && aa-status1
2
3
4
5
6
2
3
4
5
6
直接把 SELinux 设为 enforcing 可能导致业务起不来
先在 Permissive 下运行一段时间,用 ausearch -m AVC 观察拒绝日志并生成策略,再切 Enforcing。
6. 日志与审计
bash
systemctl enable --now rsyslog auditd
cat >/etc/audit/rules.d/99-baseline.rules <<'EOF'
-w /etc/passwd -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/sudoers -p wa -k sudoers
-w /etc/ssh/sshd_config -p wa -k sshd_config
-w /var/log/ -p wa -k logs
EOF
augenrules --load && auditctl -l | tail -51
2
3
4
5
6
7
8
9
2
3
4
5
6
7
8
9
7. 自动更新安全补丁
bash
# RHEL
dnf install -y dnf-automatic && systemctl enable --now dnf-automatic.timer
# Debian/Ubuntu
apt-get install -y unattended-upgrades && dpkg-reconfigure -f noninteractive unattended-upgrades1
2
3
4
2
3
4
验证
bash
systemctl is-enabled avahi-daemon cups 2>/dev/null # 应为 disabled
sysctl net.ipv4.ip_forward kernel.dmesg_restrict
stat -c '%a %n' /etc/shadow # 600/000
auditctl -l | wc -l
awk -F: '$2=="" {print}' /etc/shadow # 无输出
chage -l opsuser | grep -E 'Maximum|Warning'1
2
3
4
5
6
2
3
4
5
6
判定标准:无用服务已关闭;sysctl 生效且重启后仍生效;无空口令账号;auditd 规则已加载。
常见坑
关服务关掉了依赖组件
rpcbind 关掉可能让 NFS 挂载失效,cups 关掉影响打印。务必先在测试机验证并逐台灰度。
改了 login.defs 对已有账号不生效
login.defs 只影响新建账号。存量账号要用 chage -M 90 -W 14 单独设置。
sysctl 改完没持久化
只 sysctl -w 是临时的。必须写进 /etc/sysctl.d/*.conf 并执行 sysctl --system,重启后核对。
SELinux/AppArmor 直接上 enforcing 导致业务中断
走 Permissive → 收集 AVC → 生成策略 → Enforcing 的流程;实在无法适配时要有正式例外审批与补偿控制。
口令策略改严后锁死自己
修改前确认至少一个账号可正常登录,并准备好带外控制台。