Re: Resurrecting the Securing Debian Manual
"Dave P." <[email protected]> Tue, 10 Jun 2025 09:10:14 -0400
| Newsgroups | gmane.linux.debian.devel.security,gmane.linux.debian.devel.documentation |
|---|---|
| Message-ID | <CAFnCXarkD+aZ36o2T1w0HqPdCZaYijhmi0C_QrUjFSNjs-MASw@mail.gmail.com> |
--0000000000007456950637376b73 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Excellent idea Noah, especially Debian *server* security. I'm willing to help. The Wiki option sounds like the best way to me. Some points: - SSH server security - Firewalls: I think someone mentioned nftables, and that is optimal. But for people choosing between UFW and firewalld front-end tools, why firewalld will usually be preferable. - Monitoring/auditing: top/htop/etc, process termination, AIDE/Lynis/etc - Minimizing the attack surface - Modern backup strategies - Looking at the current manual, user security needs to be updated as well. Thanks for taking this on. As you say, the current manual has been out-of-date for a long time and is not easily reviseable. If you would like additional help, please email or contact me at my Discord <https://discord.com/invite/mggw8VGzUp> server. I support Debian servers for several customers and use Debian 12 and sid on the client side. Also, I wrote an SSH server security manual for a customer; it can be reused for this purpose. Dave On Mon, Jun 9, 2025 at 12:21=E2=80=AFPM Noah Meyerhans <[email protected]> w= rote: > Hi all. The Securing Debian Manual (the harden-doc package) is > woefully out of date and doesn't provide accurate guidance for > operating modern software in the current threat landscape. I'd like > to begin the task of updating it to reflect current best practice and > to document current tools and technologies. > > Most basically, I wonder if folks think this is a worthy idea. The > landscape has changed significantly since harden-doc was first > written. Default configurations don't require as much hardening, and > there are lots more available resources. Maybe harden-doc has > stagnated because there's no real need for it? > > Assuming we do revive the doc, here are some ideas of what I'd like to > do with the document. I'd like to also get feedback, ideas, and > contributions from others interested in the topic. > > 1. More background information on principles such as: > a. Threat modeling > b. Defense in depth > c. Least privilege > 2. Modern server deployment practices, such as: > a. Sandboxing (with systemd, containers, etc) > b. Image-based deployments, including cloud > c. Update deployment strategies for large fleets > 3. Data privacy: > a. VPNs, wireguard, etc > b. Disk encryption > 4. Workstation best practices, including: > a. Ssh key generation and handling > b. Basic browser hygine > c. Password managers and other password hygine > > My inclination is to primarily focus on general principles rather than > try to document specific settings in specific packages, as in the > current document's Chapter 5 ("Securing services running on your > system"). It'll make sense to document some approaches to safe usage of > the most common software (firefox, openssh, etc), but I don't believe > that it's feasible to provide useful advice for a meaningful subset of > Debian packages. > > Should we maybe consider maintaining this document on wiki.debian.org, > rather than being a centrally maintained document? The wiki may scale > better to multiple contributors, leading to better content and more > active maintenance. > > If you've got ideas for other topics, I'd love to hear them. > > noah > > --0000000000007456950637376b73 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><div class=3D"gmail_default" style=3D"fon= t-family:tahoma,sans-serif;font-size:small">Excellent idea Noah, especially= Debian <i>server</i> security. I'm willing to help. The Wiki option so= unds like the best way to me.=C2=A0 <br></div><div class=3D"gmail_default" = style=3D"font-family:tahoma,sans-serif;font-size:small">Some points:</div><= div class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-siz= e:small">- SSH server security <br></div><div class=3D"gmail_default" style= =3D"font-family:tahoma,sans-serif;font-size:small">- Firewalls: I think som= eone mentioned nftables, and that is optimal. But for people choosing betwe= en UFW and firewalld front-end tools, why firewalld will usually be prefera= ble.</div><div class=3D"gmail_default" style=3D"font-family:tahoma,sans-ser= if;font-size:small">- Monitoring/auditing: top/htop/etc, process terminatio= n, AIDE/Lynis/etc</div><div class=3D"gmail_default" style=3D"font-family:ta= homa,sans-serif;font-size:small">- Minimizing the attack surface</div><div = class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-size:sm= all">- Modern backup strategies</div><div class=3D"gmail_default" style=3D"= font-family:tahoma,sans-serif;font-size:small">- Looking at the current man= ual, user security needs to be updated as well.</div><div class=3D"gmail_de= fault" style=3D"font-family:tahoma,sans-serif;font-size:small"><br></div><d= iv class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-size= :small">Thanks for taking this on. As you say, the current manual has been= =C2=A0out-of-date for a long time and is not easily reviseable.<br></div><d= iv class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-size= :small"></div><div class=3D"gmail_default" style=3D"font-family:tahoma,sans= -serif;font-size:small">If you would like additional help, please email or = contact me at my <a href=3D"https://discord.com/invite/mggw8VGzUp">Discord<= /a> server. I support Debian servers for several customers and use Debian 1= 2 and sid on the client side. Also, I wrote an SSH server security manual f= or a customer; it can be reused for this purpose.</div><div class=3D"gmail_= default" style=3D"font-family:tahoma,sans-serif;font-size:small"><br></div>= <div class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-si= ze:small">Dave<br></div></div><br><div class=3D"gmail_quote"><div dir=3D"lt= r" class=3D"gmail_attr">On Mon, Jun 9, 2025 at 12:21=E2=80=AFPM Noah Meyerh= ans <<a href=3D"mailto:[email protected]" target=3D"_blank">noahm@debian.= org</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg= in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e= x">Hi all.=C2=A0 The Securing Debian Manual (the harden-doc package) is<br> woefully out of date and doesn't provide accurate guidance for<br> operating modern software in the current threat landscape.=C2=A0 I'd li= ke<br> to begin the task of updating it to reflect current best practice and<br> to document current tools and technologies.<br> <br> Most basically, I wonder if folks think this is a worthy idea.=C2=A0 The<br= > landscape has changed significantly since harden-doc was first<br> written.=C2=A0 Default configurations don't require as much hardening, = and<br> there are lots more available resources.=C2=A0 Maybe harden-doc has<br> stagnated because there's no real need for it?<br> <br> Assuming we do revive the doc, here are some ideas of what I'd like to<= br> do with the document.=C2=A0 I'd like to also get feedback, ideas, and<b= r> contributions from others interested in the topic.<br> <br> 1. More background information on principles such as:<br> =C2=A0 =C2=A0a. Threat modeling<br> =C2=A0 =C2=A0b. Defense in depth<br> =C2=A0 =C2=A0c. Least privilege<br> 2. Modern server deployment practices, such as:<br> =C2=A0 =C2=A0a. Sandboxing (with systemd, containers, etc)<br> =C2=A0 =C2=A0b. Image-based deployments, including cloud<br> =C2=A0 =C2=A0c. Update deployment strategies for large fleets<br> 3. Data privacy:<br> =C2=A0 =C2=A0a. VPNs, wireguard, etc<br> =C2=A0 =C2=A0b. Disk encryption<br> 4. Workstation best practices, including:<br> =C2=A0 =C2=A0a. Ssh key generation and handling<br> =C2=A0 =C2=A0b. Basic browser hygine<br> =C2=A0 =C2=A0c. Password managers and other password hygine<br> <br> My inclination is to primarily focus on general principles rather than<br> try to document specific settings in specific packages, as in the<br> current document's Chapter 5 ("Securing services running on your<b= r> system").=C2=A0 It'll make sense to document some approaches to sa= fe usage of<br> the most common software (firefox, openssh, etc), but I don't believe<b= r> that it's feasible to provide useful advice for a meaningful subset of<= br> Debian packages.<br> <br> Should we maybe consider maintaining this document on <a href=3D"http://wik= i.debian.org" rel=3D"noreferrer" target=3D"_blank">wiki.debian.org</a>,<br> rather than being a centrally maintained document? The wiki may scale<br> better to multiple contributors, leading to better content and more<br> active maintenance.<br> <br> If you've got ideas for other topics, I'd love to hear them.=C2=A0 = <br> <br> noah<br> <br> </blockquote></div> </div> --0000000000007456950637376b73--