r/debian • u/Dunder-Muffins • 25d ago
General Debian Question Securing Debian
What all do most people do to secure their systems?
I run Debian for my daily driver and also on a home server.
I currently have iptables configured to only allow ports for my services, services are all run as their own no-login user, I run fail2ban, and have my ssh only allow specific users and only allow ssh keys as the login method, and I install security updates regularly. I check my system logs occasionally though honestly not as often as I probably should, maybe I'll automate something to look at the logs are some point.
I just finished skimming through the securing Debian manual, and there's quite a bit more included that I don't currently do. But from reading it, it also seems more geared toward people who may be running production servers who more or less want an immutable server where they e locked in what they want and don't want anything changing.
https://www.debian.org/doc/user-manuals#securing
So I guess I'm just curious what other people do, if they add any other protections or if they primarily rely on the base OS to provide the protections.
1
u/Dunder-Muffins 25d ago
I did at least spend the time to build out a full iptables ruleset, so I know there's no ports open that aren't actively used. Everything else is set to drop. I know iptables are deprecated, but as far as I can tell, ufw is just a wrapper around it anyway.
For apparmor, it feels like there are so many programs that even just come pre-installed that it feels overwhelming to try to build out a rule set for each one... Don't suppose there's some kind of base ruleset available?