Measure hardening against a published baseline and raise the score
Task
Audit lin-b against a published hardening baseline with Lynis, record its hardening index and top warnings, fix a set of findings -- defaults, weak settings, unneeded components -- and audit again. Document every finding you chose not to fix, with the reason, because a baseline deviation without a reason is indistinguishable from an oversight.
Steps
- Run
lynis audit systemand save the report tolab/harden/audit-before.txt. Record the hardening index inlab/harden/scores.txtasbefore: <n>. - Pick at least eight warnings or suggestions to fix: for example SSH settings, password ageing, unneeded packages, file permissions on key files, and a login banner. Record each in
lab/harden/findings.csvwith headerid,finding,action,reason, where action isfixedoraccepted. - Make the fixes, testing after each that you can still log in over SSH from lin-srv.
- Run the audit again, save it to
lab/harden/audit-after.txt, and addafter: <n>to the scores file. - For every finding marked accepted, make sure the reason says why the risk is acceptable, and who would sign that off in production.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Ei 'Hardening index' lab/harden/audit-before.txt lab/harden/audit-after.txt
awk -F': ' '/^before/ {b=$2} /^after/ {a=$2} END {print "index "b" -> "a; exit !(a>b)}' lab/harden/scores.txt
awk -F, 'NR>1 && $3=="fixed" {n++} END {print n" finding(s) fixed"}' lab/harden/findings.csv
awk -F, 'NR>1 && $3=="accepted" && $4=="" {bad++} END {print bad+0" accepted finding(s) with no reason"}' lab/harden/findings.csv
The hardening index rose, so the second command exits zero; at least eight findings were fixed; and no accepted finding lacks a reason. The index is a proxy, not the goal. What makes this a baseline is the findings file: the next audit compares against it, and anything new is drift.
Notes
On Windows, the equivalent is Microsoft's security baseline applied through Group Policy and checked with the Policy Analyzer, or a CIS-CAT scan against the CIS Benchmark for Windows Server.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.