Re: Resurrecting the Securing Debian Manual

"Dave P." <[email protected]> Tue, 10 Jun 2025 09:10:14 -0400
Newsgroups gmane.linux.debian.devel.security,gmane.linux.debian.devel.documentation
Message-ID <CAFnCXarkD+aZ36o2T1w0HqPdCZaYijhmi0C_QrUjFSNjs-MASw@mail.gmail.com>
--0000000000007456950637376b73
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Excellent idea Noah, especially Debian *server* security. I'm willing to
help. The Wiki option sounds like the best way to me.
Some points:
- SSH server security
- Firewalls: I think someone mentioned nftables, and that is optimal. But
for people choosing between UFW and firewalld front-end tools, why
firewalld will usually be preferable.
- Monitoring/auditing: top/htop/etc, process termination, AIDE/Lynis/etc
- Minimizing the attack surface
- Modern backup strategies
- Looking at the current manual, user security needs to be updated as well.

Thanks for taking this on. As you say, the current manual has
been out-of-date for a long time and is not easily reviseable.
If you would like additional help, please email or contact me at my Discord
<https://discord.com/invite/mggw8VGzUp> server. I support Debian servers
for several customers and use Debian 12 and sid on the client side. Also, I
wrote an SSH server security manual for a customer; it can be reused for
this purpose.

Dave

On Mon, Jun 9, 2025 at 12:21=E2=80=AFPM Noah Meyerhans <[email protected]> w=
rote:

> Hi all.  The Securing Debian Manual (the harden-doc package) is
> woefully out of date and doesn't provide accurate guidance for
> operating modern software in the current threat landscape.  I'd like
> to begin the task of updating it to reflect current best practice and
> to document current tools and technologies.
>
> Most basically, I wonder if folks think this is a worthy idea.  The
> landscape has changed significantly since harden-doc was first
> written.  Default configurations don't require as much hardening, and
> there are lots more available resources.  Maybe harden-doc has
> stagnated because there's no real need for it?
>
> Assuming we do revive the doc, here are some ideas of what I'd like to
> do with the document.  I'd like to also get feedback, ideas, and
> contributions from others interested in the topic.
>
> 1. More background information on principles such as:
>    a. Threat modeling
>    b. Defense in depth
>    c. Least privilege
> 2. Modern server deployment practices, such as:
>    a. Sandboxing (with systemd, containers, etc)
>    b. Image-based deployments, including cloud
>    c. Update deployment strategies for large fleets
> 3. Data privacy:
>    a. VPNs, wireguard, etc
>    b. Disk encryption
> 4. Workstation best practices, including:
>    a. Ssh key generation and handling
>    b. Basic browser hygine
>    c. Password managers and other password hygine
>
> My inclination is to primarily focus on general principles rather than
> try to document specific settings in specific packages, as in the
> current document's Chapter 5 ("Securing services running on your
> system").  It'll make sense to document some approaches to safe usage of
> the most common software (firefox, openssh, etc), but I don't believe
> that it's feasible to provide useful advice for a meaningful subset of
> Debian packages.
>
> Should we maybe consider maintaining this document on wiki.debian.org,
> rather than being a centrally maintained document? The wiki may scale
> better to multiple contributors, leading to better content and more
> active maintenance.
>
> If you've got ideas for other topics, I'd love to hear them.
>
> noah
>
>

--0000000000007456950637376b73
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div class=3D"gmail_default" style=3D"fon=
t-family:tahoma,sans-serif;font-size:small">Excellent idea Noah, especially=
 Debian <i>server</i> security. I&#39;m willing to help. The Wiki option so=
unds like the best way to me.=C2=A0 <br></div><div class=3D"gmail_default" =
style=3D"font-family:tahoma,sans-serif;font-size:small">Some points:</div><=
div class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-siz=
e:small">- SSH server security <br></div><div class=3D"gmail_default" style=
=3D"font-family:tahoma,sans-serif;font-size:small">- Firewalls: I think som=
eone mentioned nftables, and that is optimal. But for people choosing betwe=
en UFW and firewalld front-end tools, why firewalld will usually be prefera=
ble.</div><div class=3D"gmail_default" style=3D"font-family:tahoma,sans-ser=
if;font-size:small">- Monitoring/auditing: top/htop/etc, process terminatio=
n, AIDE/Lynis/etc</div><div class=3D"gmail_default" style=3D"font-family:ta=
homa,sans-serif;font-size:small">- Minimizing the attack surface</div><div =
class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-size:sm=
all">- Modern backup strategies</div><div class=3D"gmail_default" style=3D"=
font-family:tahoma,sans-serif;font-size:small">- Looking at the current man=
ual, user security needs to be updated as well.</div><div class=3D"gmail_de=
fault" style=3D"font-family:tahoma,sans-serif;font-size:small"><br></div><d=
iv class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-size=
:small">Thanks for taking this on. As you say, the current manual has been=
=C2=A0out-of-date for a long time and is not easily reviseable.<br></div><d=
iv class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-size=
:small"></div><div class=3D"gmail_default" style=3D"font-family:tahoma,sans=
-serif;font-size:small">If you would like additional help, please email or =
contact me at my <a href=3D"https://discord.com/invite/mggw8VGzUp">Discord<=
/a> server. I support Debian servers for several customers and use Debian 1=
2 and sid on the client side. Also, I wrote an SSH server security manual f=
or a customer; it can be reused for this purpose.</div><div class=3D"gmail_=
default" style=3D"font-family:tahoma,sans-serif;font-size:small"><br></div>=
<div class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif;font-si=
ze:small">Dave<br></div></div><br><div class=3D"gmail_quote"><div dir=3D"lt=
r" class=3D"gmail_attr">On Mon, Jun 9, 2025 at 12:21=E2=80=AFPM Noah Meyerh=
ans &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">noahm@debian.=
org</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg=
in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e=
x">Hi all.=C2=A0 The Securing Debian Manual (the harden-doc package) is<br>
woefully out of date and doesn&#39;t provide accurate guidance for<br>
operating modern software in the current threat landscape.=C2=A0 I&#39;d li=
ke<br>
to begin the task of updating it to reflect current best practice and<br>
to document current tools and technologies.<br>
<br>
Most basically, I wonder if folks think this is a worthy idea.=C2=A0 The<br=
>
landscape has changed significantly since harden-doc was first<br>
written.=C2=A0 Default configurations don&#39;t require as much hardening, =
and<br>
there are lots more available resources.=C2=A0 Maybe harden-doc has<br>
stagnated because there&#39;s no real need for it?<br>
<br>
Assuming we do revive the doc, here are some ideas of what I&#39;d like to<=
br>
do with the document.=C2=A0 I&#39;d like to also get feedback, ideas, and<b=
r>
contributions from others interested in the topic.<br>
<br>
1. More background information on principles such as:<br>
=C2=A0 =C2=A0a. Threat modeling<br>
=C2=A0 =C2=A0b. Defense in depth<br>
=C2=A0 =C2=A0c. Least privilege<br>
2. Modern server deployment practices, such as:<br>
=C2=A0 =C2=A0a. Sandboxing (with systemd, containers, etc)<br>
=C2=A0 =C2=A0b. Image-based deployments, including cloud<br>
=C2=A0 =C2=A0c. Update deployment strategies for large fleets<br>
3. Data privacy:<br>
=C2=A0 =C2=A0a. VPNs, wireguard, etc<br>
=C2=A0 =C2=A0b. Disk encryption<br>
4. Workstation best practices, including:<br>
=C2=A0 =C2=A0a. Ssh key generation and handling<br>
=C2=A0 =C2=A0b. Basic browser hygine<br>
=C2=A0 =C2=A0c. Password managers and other password hygine<br>
<br>
My inclination is to primarily focus on general principles rather than<br>
try to document specific settings in specific packages, as in the<br>
current document&#39;s Chapter 5 (&quot;Securing services running on your<b=
r>
system&quot;).=C2=A0 It&#39;ll make sense to document some approaches to sa=
fe usage of<br>
the most common software (firefox, openssh, etc), but I don&#39;t believe<b=
r>
that it&#39;s feasible to provide useful advice for a meaningful subset of<=
br>
Debian packages.<br>
<br>
Should we maybe consider maintaining this document on <a href=3D"http://wik=
i.debian.org" rel=3D"noreferrer" target=3D"_blank">wiki.debian.org</a>,<br>
rather than being a centrally maintained document? The wiki may scale<br>
better to multiple contributors, leading to better content and more<br>
active maintenance.<br>
<br>
If you&#39;ve got ideas for other topics, I&#39;d love to hear them.=C2=A0 =
<br>
<br>
noah<br>
<br>
</blockquote></div>
</div>

--0000000000007456950637376b73--