yequari.com

Server Administration Basics

These are the first steps I do to setup a brand new server

TODO: Provide explanations for what all this actually does and why you should do it.

Add user

useradd -m yequari
passwd yequari
usermod -aG sudo yequari

Copy SSH key

Assuming you are currently root, trying to set up SSH on your new user

mkdir /home/yequari/.ssh
echo <pubkey> >> /home/yequari/.ssh/authorized_keys
chown -R yequari:yequari /home/yequari/.ssh
chmod 0700 /home/yequari/.ssh
chmod 0600 /home/yequari/.ssh/authorized_keys

Disable Password Auth

Edit /etc/ssh/sshd_config

PasswordAuthenticaion no
KbdInteractiveAuthentication no

Restart ssh service

sudo systemctl restart ssh.service

Install fail2ban and ufw

sudo apt install fail2ban ufw

Set up firewall

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

To allow connection to port from only specific hosts

sudo ufw allow from <host_ip> to any port <port#>

See DigitalOcean Community for more ufw tips

Tags: