LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 08-24-2015, 12:59 AM   #1
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Rep: Reputation: 31
Hardening OpenBSd


Dear All,

May I know what is the method to lock down/harden openbsd 5.7?


Currently, I had implemented several approaches like following.

1.No direct root login from terminal
2.No remote login approaches including ssh or telnet. I had rename the config file.
3.Remove unnecessary user or groups

Please help to expand the list. Thanks.
 
Old 08-24-2015, 05:44 AM   #2
cynwulf
Senior Member
 
Registered: Apr 2005
Posts: 2,727

Rep: Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367
OpenBSD is hardened out of the box ("secure by default"). So you're probably wasting time and effort.

http://www.openbsd.org/security.html

Have a look at kern.securelevel. but if you up it from the default without understanding what you're doing and why, you're only going to cause yourself unnecessary grief.

Yes direct root login is dangerous and unnecessary, but on a single user desktop outside of a production/enterprise environment, it's not really an issue. Use sudo(8) (or doas(1) for -current or 5.8-release) if you prefer.

If you don't need sshd, disable it in /etc/rc.conf.local, if you do then it should already be configured properly "out of the box" (rather than allowing root login by default as is the case with some OS).

http://www.openbsd.org/openssh/faq.html

If you're building ports, don't do the whole build as root, add your user to the wsrc group and set up sudo. http://www.openbsd.org/faq/faq15.html#PortsConfig (and set up a read only ports tree).

Better still: use binary packages, as there isn't likely to be any advantage to building ports yourself (unless you're running -stable?).

Last edited by cynwulf; 08-24-2015 at 05:46 AM.
 
Old 08-25-2015, 01:04 AM   #3
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Original Poster
Rep: Reputation: 31
I'm admit that OpenBSD was secure by default but still there must be area that I'm missed out to harden it further.

No x window server.
No preallocate port from range 49951 - 65535 using sysctl.
Enforce maxproc.
Enforce file descriptors
Install root kit hunter
 
Old 08-25-2015, 03:30 AM   #4
Randicus Draco Albus
Senior Member
 
Registered: May 2011
Location: Hiding somewhere on planet Earth.
Distribution: No distribution. OpenBSD operating system
Posts: 1,711
Blog Entries: 8

Rep: Reputation: 635Reputation: 635Reputation: 635Reputation: 635Reputation: 635Reputation: 635
What makes you think you must have missed something?
 
Old 08-27-2015, 01:56 PM   #5
Soderlund
Member
 
Registered: Aug 2012
Posts: 185

Rep: Reputation: 81
pf.conf could be more restrictive.
 
Old 08-27-2015, 09:56 PM   #6
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,983

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
Remove as many programs as you can also.
 
Old 08-28-2015, 02:35 PM   #7
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Void, Debian, Slackware
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
Apply all security patches.
 
Old 08-29-2015, 02:43 AM   #8
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Original Poster
Rep: Reputation: 31
Quote:
Originally Posted by hitest View Post
Apply all security patches.
Yes, I had applied all security patches. Thanks for remind.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux hardening and mysql hardening sagar666 Linux - Server 3 06-18-2014 11:47 PM
OpenBSD: nvidia drivers, screen resolution and FreeBSD binaries on OpenBSD ::: *BSD 2 08-21-2009 04:18 AM
LXer: Fsck errors in the Linux filesystem on my OpenBSD laptop NOT caused by OpenBSD LXer Syndicated Linux News 1 08-31-2008 03:15 AM
LXer: OpenBSD: The OpenBSD Foundation LXer Syndicated Linux News 0 07-26-2007 10:31 AM
Hardening RH 9 velan Red Hat 4 06-16-2004 07:40 AM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 08:53 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration