Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Bare essentials?
PostPosted: Sun Aug 23, 2009 2:39 pm 
Offline
Senior Member
User avatar

Joined: Fri Jan 02, 2009 11:31 am
Posts: 141
Website: http://faroutscience.com
Location: Texas / Kansas
I am setting up a CentoS 5.2 LAMP server.

Beyond apache, php, and mysql, what are the essential services that should be enabled? What modules should only be enabled for apache and php to maximize security?

I am only interested in the bare minimum to operate a secure server.

Thank you, Jeff


Top
   
 Post subject:
PostPosted: Sun Aug 23, 2009 8:16 pm 
Offline
Senior Member
User avatar

Joined: Sun Jan 18, 2009 2:41 pm
Posts: 830
fos wrote:
Beyond apache, php, and mysql, what are the essential services that should be enabled?

Well, there are basic ones like anacron/atd/crond, syslog, and network. Others like lvm2-monitor and restorecond are enabled on a CentOS Linode I deal with, though I don't know if they're strictly necessary. Of course you'll probably want iptables, sshd, and maybe one of fail2ban or denyhosts.
This is the list on my host (which also runs postfix and mailman in addition to a LAMP site):
Code:
$ /sbin/chkconfig --list | fgrep '3:on'
anacron         0:off   1:off   2:on    3:on    4:on    5:on    6:off
atd             0:off   1:off   2:off   3:on    4:on    5:on    6:off
crond           0:off   1:off   2:on    3:on    4:on    5:on    6:off
fail2ban        0:off   1:off   2:off   3:on    4:on    5:on    6:off
gpm             0:off   1:off   2:on    3:on    4:on    5:on    6:off
httpd           0:off   1:off   2:on    3:on    4:on    5:on    6:off
iptables        0:off   1:off   2:on    3:on    4:on    5:on    6:off
lvm2-monitor    0:off   1:on    2:on    3:on    4:on    5:on    6:off
mailman         0:off   1:off   2:on    3:on    4:on    5:on    6:off
mysqld          0:off   1:off   2:on    3:on    4:on    5:on    6:off
network         0:off   1:off   2:on    3:on    4:on    5:on    6:off
postfix         0:off   1:off   2:on    3:on    4:on    5:on    6:off
postgrey        0:off   1:off   2:on    3:on    4:on    5:on    6:off
restorecond     0:off   1:off   2:on    3:on    4:on    5:on    6:off
sshd            0:off   1:off   2:on    3:on    4:on    5:on    6:off
syslog          0:off   1:off   2:on    3:on    4:on    5:on    6:off
xfs             0:off   1:off   2:on    3:on    4:on    5:on    6:off

We haven't bothered to prune off things like gpm and xfs; I imagine disabling these wouldn't break anything...


Top
   
 Post subject:
PostPosted: Mon Aug 24, 2009 4:45 pm 
Offline
Senior Member
User avatar

Joined: Fri Jan 02, 2009 11:31 am
Posts: 141
Website: http://faroutscience.com
Location: Texas / Kansas
Thank you Vance. That is just the kind of thing I was looking for.

Jeff


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group