<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=DEBIAN_-_Hardening</id>
	<title>DEBIAN - Hardening - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=DEBIAN_-_Hardening"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=DEBIAN_-_Hardening&amp;action=history"/>
	<updated>2026-05-02T18:47:45Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=DEBIAN_-_Hardening&amp;diff=823&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=DEBIAN_-_Hardening&amp;diff=823&amp;oldid=prev"/>
		<updated>2026-01-17T06:30:10Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 06:30, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Scope and Assumptions ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Scope and Assumptions ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=DEBIAN_-_Hardening&amp;diff=719&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == Scope and Assumptions == This documentation describes a post-installation hardening script targeting Debian GNU/Linux (stable or LTS). The script is assumed to be executed with root privileges in a controlled environment and adapted to the system’s role (server, VM, workstation, appliance).  Assumptions: * System is freshly installed or recently provisioned * Administrator has console or out-of-band access * System role is clearly defined before a...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=DEBIAN_-_Hardening&amp;diff=719&amp;oldid=prev"/>
		<updated>2025-12-20T16:44:46Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == Scope and Assumptions == This documentation describes a post-installation hardening script targeting Debian GNU/Linux (stable or LTS). The script is assumed to be executed with root privileges in a controlled environment and adapted to the system’s role (server, VM, workstation, appliance).  Assumptions: * System is freshly installed or recently provisioned * Administrator has console or out-of-band access * System role is clearly defined before a...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== Scope and Assumptions ==&lt;br /&gt;
This documentation describes a post-installation hardening script targeting Debian GNU/Linux (stable or LTS).&lt;br /&gt;
The script is assumed to be executed with root privileges in a controlled environment and adapted to the system’s role (server, VM, workstation, appliance).&lt;br /&gt;
&lt;br /&gt;
Assumptions:&lt;br /&gt;
* System is freshly installed or recently provisioned&lt;br /&gt;
* Administrator has console or out-of-band access&lt;br /&gt;
* System role is clearly defined before applying hardening&lt;br /&gt;
* No automated configuration management is yet enforcing security state&lt;br /&gt;
&lt;br /&gt;
== Security Concepts and Threat Model ==&lt;br /&gt;
The hardening script is designed around the following security concepts:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Principle of Least Privilege&amp;#039;&amp;#039;&amp;#039; – services, users, and processes only receive strictly required permissions&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Defense in Depth&amp;#039;&amp;#039;&amp;#039; – multiple independent layers (kernel, filesystem, network, services)&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Secure by Default&amp;#039;&amp;#039;&amp;#039; – deny-all baseline, explicit allow rules&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Attack Surface Reduction&amp;#039;&amp;#039;&amp;#039; – disable unused services, protocols, and kernel features&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Auditability&amp;#039;&amp;#039;&amp;#039; – security-relevant events are logged and traceable&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Fail-Safe Defaults&amp;#039;&amp;#039;&amp;#039; – misconfiguration leads to denial rather than silent allowance&lt;br /&gt;
&lt;br /&gt;
Threats addressed:&lt;br /&gt;
* Remote service exploitation&lt;br /&gt;
* Credential brute-force and lateral movement&lt;br /&gt;
* Local privilege escalation&lt;br /&gt;
* Persistence via scheduled tasks or startup units&lt;br /&gt;
* Data exfiltration and log tampering&lt;br /&gt;
&lt;br /&gt;
== Script Architecture and Execution Model ==&lt;br /&gt;
The hardening script should be modular and idempotent.&lt;br /&gt;
&lt;br /&gt;
Recommended structure:&lt;br /&gt;
* 00-env-check.sh&lt;br /&gt;
* 10-packages.sh&lt;br /&gt;
* 20-kernel.sh&lt;br /&gt;
* 30-auth.sh&lt;br /&gt;
* 40-network.sh&lt;br /&gt;
* 50-services.sh&lt;br /&gt;
* 60-filesystem.sh&lt;br /&gt;
* 70-audit.sh&lt;br /&gt;
* 80-maintenance.sh&lt;br /&gt;
&lt;br /&gt;
Example execution guard:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
if [ &amp;quot;$(id -u)&amp;quot; -ne 0 ]; then&lt;br /&gt;
  echo &amp;quot;Must be run as root&amp;quot;&lt;br /&gt;
  exit 1&lt;br /&gt;
fi&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Idempotency is achieved by:&lt;br /&gt;
* Using declarative configuration files&lt;br /&gt;
* Avoiding destructive inline edits&lt;br /&gt;
* Checking state before applying changes&lt;br /&gt;
&lt;br /&gt;
== Package Management Hardening ==&lt;br /&gt;
Remove unnecessary packages and enforce secure package handling.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
apt purge telnet rsh-client rsh-server talk talkd xinetd -y&lt;br /&gt;
apt install --no-install-recommends \&lt;br /&gt;
  sudo ufw fail2ban auditd apparmor apparmor-utils -y&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable automatic installation of suggested packages:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
echo &amp;#039;APT::Install-Suggests &amp;quot;false&amp;quot;;&amp;#039; &amp;gt; /etc/apt/apt.conf.d/99nosuggests&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== User Accounts and Authentication ==&lt;br /&gt;
Ensure proper password policies and account controls.&lt;br /&gt;
&lt;br /&gt;
Password aging and complexity:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
sed -i &amp;#039;s/^PASS_MAX_DAYS.*/PASS_MAX_DAYS   90/&amp;#039; /etc/login.defs&lt;br /&gt;
sed -i &amp;#039;s/^PASS_MIN_DAYS.*/PASS_MIN_DAYS   7/&amp;#039; /etc/login.defs&lt;br /&gt;
sed -i &amp;#039;s/^PASS_WARN_AGE.*/PASS_WARN_AGE   14/&amp;#039; /etc/login.defs&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Lock system accounts:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
for u in sync shutdown halt games; do&lt;br /&gt;
  usermod -L &amp;quot;$u&amp;quot;&lt;br /&gt;
done&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restrict su access:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
dpkg-statoverride --update --add root sudo 4750 /bin/su&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== SSH Daemon Hardening ==&lt;br /&gt;
Harden remote access while preventing lockout.&lt;br /&gt;
&lt;br /&gt;
Configuration changes in /etc/ssh/sshd_config:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
PermitRootLogin no&lt;br /&gt;
PasswordAuthentication no&lt;br /&gt;
ChallengeResponseAuthentication no&lt;br /&gt;
UsePAM yes&lt;br /&gt;
X11Forwarding no&lt;br /&gt;
MaxAuthTries 3&lt;br /&gt;
LoginGraceTime 20&lt;br /&gt;
AllowGroups sshusers&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Validate before restart:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
sshd -t &amp;amp;&amp;amp; systemctl reload ssh&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network Stack and Firewall ==&lt;br /&gt;
Apply a default-deny firewall policy.&lt;br /&gt;
&lt;br /&gt;
UFW example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ufw default deny incoming&lt;br /&gt;
ufw default allow outgoing&lt;br /&gt;
ufw allow 22/tcp&lt;br /&gt;
ufw enable&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Kernel network hardening:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF &amp;gt; /etc/sysctl.d/99-hardening.conf&lt;br /&gt;
net.ipv4.conf.all.rp_filter=1&lt;br /&gt;
net.ipv4.conf.default.rp_filter=1&lt;br /&gt;
net.ipv4.tcp_syncookies=1&lt;br /&gt;
net.ipv4.icmp_echo_ignore_broadcasts=1&lt;br /&gt;
net.ipv4.conf.all.accept_redirects=0&lt;br /&gt;
net.ipv4.conf.all.send_redirects=0&lt;br /&gt;
EOF&lt;br /&gt;
sysctl --system&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Kernel and Memory Protections ==&lt;br /&gt;
Enable exploit mitigation features.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
echo &amp;quot;kernel.kptr_restrict=2&amp;quot; &amp;gt;&amp;gt; /etc/sysctl.d/99-hardening.conf&lt;br /&gt;
echo &amp;quot;kernel.dmesg_restrict=1&amp;quot; &amp;gt;&amp;gt; /etc/sysctl.d/99-hardening.conf&lt;br /&gt;
echo &amp;quot;fs.protected_symlinks=1&amp;quot; &amp;gt;&amp;gt; /etc/sysctl.d/99-hardening.conf&lt;br /&gt;
echo &amp;quot;fs.protected_hardlinks=1&amp;quot; &amp;gt;&amp;gt; /etc/sysctl.d/99-hardening.conf&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Filesystem and Mount Options ==&lt;br /&gt;
Harden mount points against code execution and abuse.&lt;br /&gt;
&lt;br /&gt;
Example /etc/fstab entries:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
tmpfs /tmp tmpfs defaults,noexec,nosuid,nodev 0 0&lt;br /&gt;
tmpfs /var/tmp tmpfs defaults,noexec,nosuid,nodev 0 0&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Apply immediately:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
mount -o remount /tmp&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Mandatory Access Control (AppArmor) ==&lt;br /&gt;
Enforce confinement for critical services.&lt;br /&gt;
&lt;br /&gt;
Enable and enforce:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
systemctl enable apparmor&lt;br /&gt;
systemctl start apparmor&lt;br /&gt;
aa-enforce /etc/apparmor.d/*&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check status:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aa-status&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Auditing and Logging ==&lt;br /&gt;
Ensure security-relevant events are recorded.&lt;br /&gt;
&lt;br /&gt;
Audit rules example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF &amp;gt; /etc/audit/rules.d/hardening.rules&lt;br /&gt;
-w /etc/passwd -p wa -k identity&lt;br /&gt;
-w /etc/shadow -p wa -k identity&lt;br /&gt;
-w /etc/sudoers -p wa -k scope&lt;br /&gt;
-w /var/log/auth.log -p wa -k authlog&lt;br /&gt;
EOF&lt;br /&gt;
augenrules --load&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Prevent log tampering:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
chattr +a /var/log/auth.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Scheduled Tasks and Persistence Controls ==&lt;br /&gt;
Review and restrict scheduled execution.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
chmod 700 /etc/cron.*&lt;br /&gt;
ls -l /etc/cron.d&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable atd if unused:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
systemctl disable --now atd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Automatic Security Updates ==&lt;br /&gt;
Ensure timely patching.&lt;br /&gt;
&lt;br /&gt;
Enable unattended-upgrades:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
apt install unattended-upgrades -y&lt;br /&gt;
dpkg-reconfigure unattended-upgrades&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verification:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
unattended-upgrade --dry-run&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
Common issues and recovery guidance.&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Lost SSH access&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
** Verify sshd configuration syntax with  &amp;lt;nowiki&amp;gt;sshd -t&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
** Use local console or recovery mode&lt;br /&gt;
** Temporarily allow password authentication&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Firewall blocking services&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
** Check active rules:  &amp;lt;nowiki&amp;gt;ufw status verbose&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
** Disable temporarily:  &amp;lt;nowiki&amp;gt;ufw disable&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;AppArmor breaking services&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
** Identify denied actions in  &amp;lt;nowiki&amp;gt;/var/log/syslog&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
** Switch profile to complain mode:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aa-complain /etc/apparmor.d/profile-name&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;System boot issues after sysctl changes&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
** Boot with single-user mode&lt;br /&gt;
** Remove problematic file from  &amp;lt;nowiki&amp;gt;/etc/sysctl.d/&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
* Debian Security Documentation  &lt;br /&gt;
  https://www.debian.org/security/&lt;br /&gt;
&lt;br /&gt;
* Debian Hardening Guide  &lt;br /&gt;
  https://www.debian.org/doc/manuals/securing-debian-manual/&lt;br /&gt;
&lt;br /&gt;
* CIS Debian Linux Benchmark  &lt;br /&gt;
  https://www.cisecurity.org/&lt;br /&gt;
&lt;br /&gt;
* AppArmor Documentation  &lt;br /&gt;
  https://gitlab.com/apparmor/apparmor/-/wikis/home&lt;br /&gt;
&lt;br /&gt;
* Linux Audit Framework  &lt;br /&gt;
  https://linux-audit.com/&lt;br /&gt;
&lt;br /&gt;
* NIST Security Guidelines  &lt;br /&gt;
  https://csrc.nist.gov/&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>