{"id":73183,"date":"2023-10-31T15:51:19","date_gmt":"2023-10-31T07:51:19","guid":{"rendered":"https:\/\/version-2.com\/?p=73183"},"modified":"2023-10-24T15:53:05","modified_gmt":"2023-10-24T07:53:05","slug":"how-to-secure-your-rocky-linux-server","status":"publish","type":"post","link":"https:\/\/version-2.com\/zh\/2023\/10\/how-to-secure-your-rocky-linux-server\/","title":{"rendered":"How to Secure Your Rocky Linux Server"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"73183\" class=\"elementor elementor-73183\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-35fe5dd post-content elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"35fe5dd\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;cef08c3&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-409a2e9a\" data-id=\"409a2e9a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5a8be8f elementor-widget elementor-widget-text-editor\" data-id=\"5a8be8f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<article><p class=\"is-active\">Securing your Rocky Linux server is of paramount importance in today\u2019s digital landscape, where cyber threats and attacks are becoming increasingly sophisticated.\u00a0<\/p><p>Whether you are running a blog or hosting critical business applications, ensuring the security of your server is essential to protect sensitive data, maintain privacy, and prevent unauthorized access.<\/p><p>Servers often store valuable information that could be detrimental if compromised, including personal information, financial records, or confidential business data. A security breach can lead to data theft, identity theft, financial losses, and reputational damage for both individuals and organizations.<\/p><p>Securing Rocky Linux is also essential for ensuring the smooth and uninterrupted functioning of critical applications and services. A compromised server may experience downtime, leading to disruptions in services, loss of productivity, and customer dissatisfaction. By implementing robust security measures, server administrators can decrease the risk of downtime and maintain a reliable and secure environment for their users.<\/p><p>Next, a compromised server can be utilized for malicious purposes for further attacks, such as distributed denial-of-service (DDoS) attacks or spreading malware to other connected systems and acting as bot machines centrally managed by bad actors. By securing Rocky Linux, administrators not only protect their own infrastructure but also contribute to overall internet safety by preventing the server from being exploited in cybercriminal activities.<\/p><p>In this tutorial, we will walk you through the best practices and essential security steps to secure your Rocky Linux server.<\/p><p>We must note that the steps covered here are not exhaustive, and you should always stay updated with the latest security recommendations and patches to maintain a robust security posture.\u00a0<\/p><h2 id=\"step1\" class=\"wp-block-heading\">Step 1: Log in to your Rocky Linux server via SSH<\/h2><p>For this step, you need to make sure that you have a terminal or SSH (Secure Shell) client installed on your local machine. If you\u2019re using Linux or macOS, you can use the built-in terminal application. For Windows users, you will most likely use the PuTTY SSH client.<\/p><p>Open the terminal and type the following command replacing <strong>username<\/strong> and <strong>server_ip_address<\/strong> with your own.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>ssh username@server_ip_address<\/p><\/div><\/div><p>After you enter your password you will be logged into to your server.<\/p><figure class=\"wp-block-image size-full\"><img decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99555\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png?resize=512%2C52&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1-300x30.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"52\" \/><\/figure><h2 id=\"step2\" class=\"wp-block-heading\">Step 2: Update the server packages and set automatic security updates<\/h2><p>It is very important to keep your server up to date, especially since there are often security updates that minimize the risk of breach or potential system crash.<\/p><p>We have the option to manually update packages in Rocky Linux and that allows you to carefully review and test updates before applying them to your system, ensuring compatibility and stability. Also, it is always a good idea to update your system manually when you boot a new server that you will use.<\/p><p>In order to check available updates on your system, you can run the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo dnf check-update<\/p><\/div><\/div><p>You will get a similar output:<\/p><figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99557\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/2-1.png?resize=512%2C183&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/2-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/2-1-300x107.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"183\" \/><\/figure><p>If you are on a new system, you can proceed with updating all listed packages by running the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo dnf update<\/p><\/div><\/div><figure class=\"wp-block-image size-full\"><img decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99558\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/3-1.png?resize=512%2C268&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/3-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/3-1-300x157.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"268\" \/><\/figure><p>Press <strong>y<\/strong> and hit <strong>Enter<\/strong> to continue.<\/p><p>This process will download all the necessary packages from the designated repositories, upgrade to new versions, remove old packages, and perform cleanup for the package cache.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99559\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/4-1.png?resize=512%2C206&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/4-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/4-1-300x121.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"206\" \/><\/figure><p>If you have a system where you already have various packages installed, specific versions that could potentially have issues if upgraded to the latest version, or that may conflict with your other packages, the better solution is to perform the minimal upgrade by running the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo dnf upgrade-minimal<\/p><\/div><\/div><p>You can use this command only if you want to perform updates for packages that have essential bug fixes and various security patches, without the risk of breaking changes.<\/p><p>Next, we can enable automatic updates and use the special package designed to automate the installation of security patches and other crucial upgrades for your Rocky Linux server.\u00a0<\/p><p>To set up the automatic update process, we need to install the <strong>dnf-automatic<\/strong> package which is not available by default on your Rocky Linux server.\u00a0<\/p><p>This command requires higher permissions so make sure you execute it with your sudo or root user:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo dnf install dnf-automatic<\/p><\/div><\/div><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99560\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/5-1.png?resize=512%2C146&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/5-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/5-1-300x86.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"146\" \/><\/figure><p>Once the installation is complete, we need to edit the config file related to it:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo vi \/etc\/dnf\/automatic.conf<\/p><\/div><\/div><p>In your configuration file under <strong>\/etc\/dnf\/automatic.conf<\/strong>, find the line that starts with <strong>upgrade_type<\/strong>, and press the <strong>i <\/strong>key in order to enter the edit mode in your Vi editor and replace the value from <strong>default<\/strong> to <strong>security<\/strong>.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99561\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/6-1.png?resize=512%2C99&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/6-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/6-1-300x58.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"99\" \/><\/figure><p>Since it is recommended to modify the default behavior to only include security upgrades, this will ensure automatic updates will not introduce breaking changes for your packages.<\/p><p>In order to write the changes and exit the file using Vi, press <strong>Shift<\/strong> and<strong> :<\/strong> then type <strong>wq <\/strong>and press <strong>Enter<\/strong>.\u00a0<\/p><p>Finally, we need to make sure that <strong>dnf-automatic<\/strong> service is enabled by default the next time we start or reboot our system.\u00a0<\/p><p>We can do that by running the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo systemctl enable dnf-automatic-install.timer<\/p><\/div><\/div><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99562\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/7-1.png?resize=512%2C20&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/7-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/7-1-300x12.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"20\" \/><\/figure><p>The <strong>dnf-automatic-install.timer<\/strong> is a systemd timer unit that runs our <strong>dnf-automatic-install<\/strong> service. By default, it is scheduled to activate every day at 6 a.m., with a randomized delay of up to one hour.<\/p><h2 id=\"step3\" class=\"wp-block-heading\">Step 3: Add sudo users<\/h2><p>When you boot the system for the first time, by default the root user has full control and unrestricted access to all system resources. Running daily tasks with the root user is not ideal as there is a high probability that any mistake or malicious command executed by the root user can have drastic consequences for your system. In order to minimize these risks, the concept of sudo users was introduced which gives more granular control over access potential actions that a user can run on Linux servers.<\/p><p>You can start by adding a new user to your Rocky Linux server:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>adduser jumpcloud<\/p><\/div><\/div><p>Next, we will run the command so we can create a strong password for our newly created user:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>passwd jumpcloud<\/p><\/div><\/div><p>After that, you can make sure that your user exists and has its own group if you run the <em>id<\/em> command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>id jumpcloud<\/p><\/div><\/div><p>You can see a similar output:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99563\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/8-2.png?resize=512%2C35&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/8-2.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/8-2-300x21.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"35\" \/><\/figure><p>The next step consists of elevating the permissions of our <em>jumpcloud<\/em> user so it can execute sudo commands.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo usermod -aG wheel jumpcloud<\/p><\/div><\/div><p>In this case, the user \u201cjumpcloud\u201d will be added to the \u201cwheel\u201d group, providing it administrative privileges on the system.<\/p><p>If you\u2019d like more details on creating sudo users and managing sudo access on Rocky Linux, check out the following tutorial: <a href=\"https:\/\/jumpcloud.com\/blog\/how-to-create-sudo-users-on-rocky-linux\">How to Create Sudo Users for Rocky Linux<\/a>.<\/p><h2 id=\"step4\" class=\"wp-block-heading\">Step 4: Secure SSH\u00a0<\/h2><p>SSH (Secure Shell) provides remote access to your server and is often targeted by attackers. To <a href=\"https:\/\/jumpcloud.com\/support\/configure-ssh-settings\" target=\"_blank\" rel=\"noreferrer noopener\">enhance SSH security<\/a> we can implement certain security measures.<\/p><p>First, we can change the default port for our SSH server by changing the config file related to it.<\/p><p>We advise you to create a backup of your configuration file if it gets corrupted, so you can run the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo cp \/etc\/ssh\/sshd_config \/etc\/ssh\/sshd_config_backup<\/p><\/div><\/div><p>Next, we will edit the configuration file.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo vi \/etc\/ssh\/sshd_config<\/p><\/div><\/div><p>SSH typically operates on the well-known port 22, making it a prime target for attackers, mainly due to the rise of highly automated attacks in recent times. To enhance security, consider changing the default SSH port. This simple step adds an extra layer of obscurity, making it harder for attackers to find and target your SSH service. By choosing an unused port between 1024 and 65535, you can significantly reduce the number of automated attacks directed at your server.<\/p><p>Alternatively, you could opt to set up a <a href=\"https:\/\/jumpcloud.com\/blog\/jump-servers-obsolete\">hardened jump box<\/a>, also known as a jump host. Additional hardening and security can be layered onto the jump box instead of directly opening up ports on your server to the web.\u00a0<\/p><p>In our case we will use port 2222, so you can scroll down and find Port 22 line:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99564\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/9-1.png?resize=512%2C80&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/9-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/9-1-300x47.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"80\" \/><\/figure><p>Press <strong>i<\/strong> for edit, uncomment that line, and instead of 22, replace with 2222.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99565\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/10-1.png?resize=512%2C78&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/10-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/10-1-300x46.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"78\" \/><\/figure><p>Press <strong>Escape<\/strong> and type<strong> :wq<\/strong> to write the changes and exit the file.<\/p><p>Just above the port number configuration, note that changing the SSH port requires updating the SELinux configuration. SELinux, which originates from Red Hat, is enabled by default on Rocky Linux. Its main purpose is to restrict actions that Linux processes and users can perform on the system, as that will minimize the impact of security breaches or unauthorized access. SELinux follows the principle of least privilege, granting processes and users only the essential permissions required for their intended tasks.<\/p><p>However, it is worth noting that the <strong>semanage<\/strong> command might not be readily available on Rocky Linux. To verify the necessary dependencies, we can run a check:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>yum provides \/usr\/sbin\/semanage<\/p><\/div><\/div><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99566\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/11-1.png?resize=512%2C61&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/11-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/11-1-300x36.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"61\" \/><\/figure><p>From here we can see that we need to install additional Python libraries, and we can do so by running the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo yum install policycoreutils-python-utils<\/p><\/div><\/div><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99567\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/12-1.png?resize=512%2C159&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/12-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/12-1-300x93.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"159\" \/><\/figure><p>Type <strong>y<\/strong>, and hit <strong>Enter<\/strong> which will install the package.<\/p><p>Next, you can use this command which tells SELinux that the SSH service is now running on the new port 2222.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo semanage port -a -t ssh_port_t -p tcp 2222<\/p><\/div><\/div><p>Now, we need to add an exception to our firewall so we don\u2019t get a connection refused error.<\/p><p>Rocky Linux uses firewalld, so we can add the rule:\u00a0<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo firewall-cmd \u2013zone=public \u2013add-port=2222\/tcp \u2013permanent<\/p><\/div><\/div><p>Next, we should reload the firewall so it starts using the new rule we added:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>firewall-cmd \u2013reload<\/p><\/div><\/div><p>Now, let\u2019s give our SSH server a restart to implement the updated configuration and initiate SSH logging via port 2222. It\u2019s time to apply the changes and get started with enhanced security.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo systemctl restart sshd<\/p><\/div><\/div><p>Now you can try and log in to your Rocky Linux server by adding the <strong>-p<\/strong> option and adding our new port number.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>ssh -p 2222 username@server_ip_address<\/p><\/div><\/div><p>We can use <a href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\">SSH key<\/a> authorization in order to secure our server further. We will also disable logging with the password in our SSH configuration.<\/p><p>By following this method, the possibility of brute force attacks on passwords is completely eradicated, guaranteeing that only users that possess the matching private keys gain access to the system.\u00a0<\/p><p>In case you don\u2019t already have an SSH key pair on your local machine, you can create one.<\/p><p>To start, open a terminal on your local machine and enter the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>ssh-keygen -t rsa<\/p><\/div><\/div><p>This command will ask you to select a location to save the keys and set an optional passphrase for added security. The passphrase is also recommended.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99568\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/13-1.png?resize=512%2C166&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/13-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/13-1-300x97.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"166\" \/><\/figure><p>Once you have generated your SSH key pair, you need to copy the public key to your Rocky Linux server. You can use the ssh-copy-id command to do this.\u00a0<\/p><p>In our case we will run the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>ssh-copy-id -p 2222 -i ~\/.ssh\/jumpcloud_rockylinux.pub jumpcloud@194.195.240.58<\/p><\/div><\/div><p>You will get a similar output:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99569\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/14-1.png?resize=512%2C91&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/14-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/14-1-300x53.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"91\" \/><\/figure><p>Next, this command will prompt you to enter your user password on the remote server. Once you provide the password, the public key will be copied to the <strong>~\/.ssh\/authorized_keys<\/strong> file on the server.<\/p><p>Before we can log into the server, we need to change the permissions to our key file and assign them permissions with the value 400.\u00a0<\/p><p>We can do so by running the following command in our local terminal:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>chmod 400 ~\/.ssh\/jumpcloud_rockylinux<\/p><\/div><\/div><p>Next, we will connect with our server:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>ssh -i ~\/.ssh\/jumpcloud_rockylinux -p 2222 jumpcloud@194.195.240.58<\/p><\/div><\/div><p>This command will load the private key through the specified path on the local machine and also use the custom port that we set.<\/p><p>You should be able to log in without entering a password because the server is now configured to use SSH keys for authentication.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99570\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/15.png?resize=512%2C33&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/15.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/15-300x19.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"33\" \/><\/figure><p>We can disable password logging and use only SSH keys by editing the configuration file again:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo vi \/etc\/ssh\/sshd_config<\/p><\/div><\/div><p>We need to uncomment the part related to the <strong>PubkeyAuthentication<\/strong> and set it to <strong>yes<\/strong>:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99571\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/16.png?resize=512%2C94&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/16.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/16-300x55.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"94\" \/><\/figure><p>Next, we need to change the <strong>PasswordAuthentication<\/strong> to <strong>no<\/strong>:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99572\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/17.png?resize=512%2C95&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/17.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/17-300x56.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"95\" \/><\/figure><p>We can also disable SSH logging with the root username:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99573\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/18.png?resize=465%2C183&#038;ssl=1\" sizes=\"(max-width: 465px) 100vw, 465px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/18.png 465w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/18-300x118.png 300w\" alt=\"tutorial screenshot\" width=\"465\" height=\"183\" \/><\/figure><p>This will also enhance the security of your SSH, but keep in mind that you need to have at least one sudo user already so you don\u2019t get locked out or become unable to perform higher privilege tasks.<\/p><p>Save the file, and then restart the SSH service so it loads the new configuration.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo systemctl restart sshd<\/p><\/div><\/div><p>With key-based authentication now enforced, the need to enter a password during login should be eliminated. This security enhancement ensures that only users with the appropriate SSH keys can access the server.<\/p><h2 id=\"step5\" class=\"wp-block-heading\">Step 5: Install and configure Fail2Ban<\/h2><p>Fail2Ban is a very useful tool for protecting your Rocky Linux server from brute force attacks and unauthorized access attempts. By monitoring log files and automatically banning suspicious IP addresses, Fail2Ban adds an extra layer of security to your system.\u00a0<\/p><p>Fail2Ban is not included in the default software repositories of Rocky Linux. Nevertheless, you can easily access it through the <a href=\"https:\/\/docs.fedoraproject.org\/en-US\/epel\/\" target=\"_blank\" rel=\"noreferrer noopener\">Enhanced Packages for Enterprise Linux (EPEL) repository<\/a>, a source for third-party packages on Red Hat and Rocky Linux. If you haven\u2019t yet added the EPEL repository to your system\u2019s package sources, you can easily incorporate the repository using <strong>dnf<\/strong>, similar to installing any other package.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo dnf install epel-release -y<\/p><\/div><\/div><p>After this step, we need to install the Fail2Ban service. We can do so by running the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo dnf install fail2ban<\/p><\/div><\/div><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99574\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/19.png?resize=512%2C205&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/19.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/19-300x120.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"205\" \/><\/figure><p>This will install various dependencies also related to modules that work together with SELinux, Sendmail, or the firewalld service.<\/p><p>Next, we can create a new file called \u201c<strong>jail.local<\/strong>\u201d where we will store our custom configuration:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo vi \/etc\/fail2ban\/jail.local<\/p><\/div><\/div><p>Here we can build our custom config where we will override default values:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>[DEFAULT]<br \/># here you can overwrite some defaults:<br \/>[sshd]<br \/>enabled = true<br \/>port \u00a0 \u00a0 = ssh,2222<br \/>filter \u00a0 = sshd<br \/>bantime\u00a0 = 30m<br \/>findtime\u00a0 = 5m<br \/>maxretry = 3<\/p><\/div><\/div><p>We will change the default values from the original <strong>jail.conf <\/strong>file.<\/p><p>The <strong>bantime<\/strong> parameter defines the duration that an IP address will be banned after multiple failed login attempts. By default, it is set to 10 minutes. We can adjust this value to 30 minutes.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>bantime = 30m\u00a0\u00a0<\/p><\/div><\/div><p>The <strong>findtime<\/strong> parameter specifies the time window during which repeated failed login attempts will be counted. The default value is 10 minutes. Setting <strong>findtime<\/strong> to more than 10 minutes (600 seconds) can be beneficial in scenarios where you want to be less sensitive to temporary spikes in failed login attempts. For instance, if you have legitimate users who sometimes mistype their passwords, a longer <strong>findtime<\/strong> allows them more time to reattempt without getting banned.<\/p><p>On the other hand, setting <strong>findtime<\/strong> to less than 10 minutes can make Fail2Ban more responsive to potential attacks. If there\u2019s a rapid and sustained increase in failed login attempts within a short time, a shorter <strong>findtime<\/strong> can trigger the ban sooner, reducing the attack surface and blocking the malicious attempts more promptly.\u00a0<\/p><p>In our case, we will reduce the time to five minutes.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>findtime = 5m<\/p><\/div><\/div><p>The <strong>maxretry<\/strong> parameter defines the number of consecutive failed login attempts allowed before banning an IP address. By default, it is set to 5. We can adjust it so that it is limited to three attempts.<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>maxretry = 3\u00a0<\/p><\/div><\/div><p>After editing and saving the configuration file, we can enable the service so that it starts every time we boot the system:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo systemctl enable fail2ban<\/p><\/div><\/div><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99575\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/20.png?resize=512%2C31&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/20.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/20-300x18.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"31\" \/><\/figure><p>We can start the service by running the following command:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo systemctl start fail2ban<\/p><\/div><\/div><p>While we are logged in to our SSH session, we can use another terminal and try to log in with some non-existent username and without an SSH key:<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>ssh -p 2222 jumpcloud3@194.195.240.58<\/p><\/div><\/div><p>After three bad attempts, our IP address will be banned temporarily for further login attempts:<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99576\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/21.png?resize=512%2C127&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/21.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/21-300x74.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"127\" \/><\/figure><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99577\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/22.png?resize=512%2C35&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/22.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/22-300x21.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"35\" \/><\/figure><p>For the last attempt, we get the \u201cConnection refused\u201d error, which is clearly the ban action of our service that honors our configuration parameters.\u00a0<\/p><p>By default, the log file related to the Fail2Ban service is stored in <strong>\/var\/log\/fail2ban.log<\/strong> and we can check the latest Fail2Ban events:\u00a0<\/p><div class=\"wp-block-cgb-code-block code-block\"><div class=\"code-block-snippet is-type-body-default\"><p>sudo tail \/var\/log\/fail2ban.log<\/p><\/div><\/div><p>We can see logged events about our IP address and the exact timestamp when the Fail2Ban service banned our IP address from further attempts.\u00a0<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-recalc-dims=\"1\" class=\"wp-image-99578\" src=\"https:\/\/i0.wp.com\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/23.png?resize=512%2C39&#038;ssl=1\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/23.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/23-300x23.png 300w\" alt=\"tutorial screenshot\" width=\"512\" height=\"39\" \/><\/figure><p>The ban applies to subsequent connection attempts from that IP address. For test purposes, if you are still logged into the server from your initial SSH session, it will not be affected by the ban. However, if you log out and try to establish a new SSH connection, the new connection attempt might be blocked by the ban.<\/p><h2 class=\"wp-block-heading\">Conclusion<\/h2><p>In this tutorial we covered multiple ways to enhance the security of your Rocky Linux server, from patch management to user privilege and access management, to securing SSH and event logging. You should also learn <a href=\"https:\/\/jumpcloud.com\/blog\/enabling-fde-on-rocky-linux-9\">how to enable full-disk encryption<\/a> as well.<\/p><p>If you\u2019re an IT admin or MSP provider managing multiple Linux instances, putting these best practices into place can quickly become an overly time-consuming, manual process. That\u2019s where a truly unified endpoint management solution like JumpCloud can help.<\/p><p>With JumpCloud\u2019s open directory platform in place, you can apply key security configurations and policies to various groups of users and devices all at once, regardless of whether your fleet consists of Linux, macOS, Windows, iOS, or Android systems.\u00a0<\/p><\/article>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2004c86 elementor-widget elementor-widget-shortcode\" data-id=\"2004c86\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"57539\" class=\"elementor elementor-57539\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6b25dc0d elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"6b25dc0d\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3cc1b37d\" data-id=\"3cc1b37d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-52c4a230 elementor-widget elementor-widget-text-editor\" data-id=\"52c4a230\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>About JumpCloud<\/strong><br \/>At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Securing your Rocky Linux server is of paramount import [&hellip;]<\/p>\n","protected":false},"author":149011790,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1016,1075,61],"tags":[1017,1076],"class_list":["post-73183","post","type-post","status-publish","format-standard","hentry","category-jumpcloud","category-year2023","category-press-release","tag-jumpcloud","tag-1076"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Secure Your Rocky Linux Server - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server\" \/>\n<meta property=\"og:locale\" content=\"zh_HK\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Secure Your Rocky Linux Server - Version 2\" \/>\n<meta property=\"og:description\" content=\"Securing your Rocky Linux server is of paramount import [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-31T07:51:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png\" \/>\n<meta name=\"author\" content=\"tracylamv2\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"tracylamv2\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9810\u8a08\u95b1\u8b80\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"19 \u5206\u9418\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/10\\\/how-to-secure-your-rocky-linux-server\\\/\"},\"author\":{\"name\":\"tracylamv2\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\"},\"headline\":\"How to Secure Your Rocky Linux Server\",\"datePublished\":\"2023-10-31T07:51:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/10\\\/how-to-secure-your-rocky-linux-server\\\/\"},\"wordCount\":2892,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/1-1.png\",\"keywords\":[\"JumpCloud\",\"2023\"],\"articleSection\":[\"JumpCloud\",\"2023\",\"Press Release\"],\"inLanguage\":\"zh-HK\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/10\\\/how-to-secure-your-rocky-linux-server\\\/\",\"url\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server\",\"name\":\"How to Secure Your Rocky Linux Server - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/1-1.png\",\"datePublished\":\"2023-10-31T07:51:19+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server#breadcrumb\"},\"inLanguage\":\"zh-HK\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server#primaryimage\",\"url\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/1-1.png\",\"contentUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/1-1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/how-to-secure-your-rocky-linux-server#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Secure Your Rocky Linux Server\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"zh-HK\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\",\"name\":\"tracylamv2\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"caption\":\"tracylamv2\"},\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/author\\\/tracylamv2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Secure Your Rocky Linux Server - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server","og_locale":"zh_HK","og_type":"article","og_title":"How to Secure Your Rocky Linux Server - Version 2","og_description":"Securing your Rocky Linux server is of paramount import [&hellip;]","og_url":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server","og_site_name":"Version 2","article_published_time":"2023-10-31T07:51:19+00:00","og_image":[{"url":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png","type":"","width":"","height":""}],"author":"tracylamv2","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"tracylamv2","\u9810\u8a08\u95b1\u8b80\u6642\u9593":"19 \u5206\u9418"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server#article","isPartOf":{"@id":"https:\/\/version-2.com\/2023\/10\/how-to-secure-your-rocky-linux-server\/"},"author":{"name":"tracylamv2","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365"},"headline":"How to Secure Your Rocky Linux Server","datePublished":"2023-10-31T07:51:19+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/2023\/10\/how-to-secure-your-rocky-linux-server\/"},"wordCount":2892,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png","keywords":["JumpCloud","2023"],"articleSection":["JumpCloud","2023","Press Release"],"inLanguage":"zh-HK"},{"@type":"WebPage","@id":"https:\/\/version-2.com\/2023\/10\/how-to-secure-your-rocky-linux-server\/","url":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server","name":"How to Secure Your Rocky Linux Server - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png","datePublished":"2023-10-31T07:51:19+00:00","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server#breadcrumb"},"inLanguage":"zh-HK","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server"]}]},{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server#primaryimage","url":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png","contentUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/10\/1-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/blog\/how-to-secure-your-rocky-linux-server#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/"},{"@type":"ListItem","position":2,"name":"How to Secure Your Rocky Linux Server"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"zh-HK"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365","name":"tracylamv2","image":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","caption":"tracylamv2"},"url":"https:\/\/version-2.com\/zh\/author\/tracylamv2\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-j2n","jetpack_featured_media_url":"","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/73183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/users\/149011790"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/comments?post=73183"}],"version-history":[{"count":4,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/73183\/revisions"}],"predecessor-version":[{"id":73187,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/73183\/revisions\/73187"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/media?parent=73183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/categories?post=73183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/tags?post=73183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}