{"id":12416,"date":"2026-08-03T09:22:12","date_gmt":"2026-08-03T07:22:12","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=12416"},"modified":"2026-08-03T09:22:17","modified_gmt":"2026-08-03T07:22:17","slug":"almalinux-security-hardening-checklist-for-production-servers","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/","title":{"rendered":"AlmaLinux Security Hardening Checklist for Production Servers"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Apply a security hardening checklist before a new AlmaLinux server hosts a website, application, database, or internal service. A repeatable baseline reduces common risks while keeping required services available. Hardening does not replace ongoing monitoring, patching, backups, or incident response.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Separate_essential_controls_from_environment-specific_settings\" >Separate essential controls from environment-specific settings<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Complete_the_initial_account_access_review\" >Complete the initial account access review<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Secure_SSH_before_restricting_remote_access\" >Secure SSH before restricting remote access<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Configure_the_firewall_for_required_services\" >Configure the firewall for required services<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Keep_SELinux_enabled_and_verify_its_mode\" >Keep SELinux enabled and verify its mode<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Install_updates_and_reduce_the_service_footprint\" >Install updates and reduce the service footprint<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Set_up_logging_and_review_events\" >Set up logging and review events<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Review_file_ownership_and_permissions\" >Review file ownership and permissions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/almalinux-security-hardening-checklist-for-production-servers\/#Verify_the_baseline_before_deployment\" >Verify the baseline before deployment<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Separate_essential_controls_from_environment-specific_settings\"><\/span>Separate essential controls from environment-specific settings<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Apply the essential controls to every production server: limit account access, secure SSH, enable a firewall, keep SELinux active, install updates, collect logs, and review file permissions. Environment-specific controls depend on the services that the server will run.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-2073252252\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">For example, a web server may need HTTP and HTTPS access, while a database server may need to accept connections only from an application server. Open only the ports required by the approved service design. Do not copy a firewall rule set from another server without checking its purpose.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Complete_the_initial_account_access_review\"><\/span>Complete the initial account access review<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create a named administrator account for each person who needs access. Use individual accounts instead of sharing one administrator login.<\/li>\n\n\n\n<li>Grant administrative privileges only to accounts that require them. Use controlled elevation for administrative commands.<\/li>\n\n\n\n<li>Review existing users, groups, home directories, and login shells. Remove or disable accounts that are not required.<\/li>\n\n\n\n<li>Use strong, unique passwords where passwords are allowed. Do not store passwords in scripts or shared notes.<\/li>\n\n\n\n<li>Confirm that access remains available through the named administrator account before changing or disabling any default access.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Keep a separate recovery path for the server. Before changing authentication settings, verify that console or out-of-band access is available if the environment provides it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Secure_SSH_before_restricting_remote_access\"><\/span>Secure SSH before restricting remote access<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">SSH is the main remote administration service on many Linux servers. Restrict it to the administrators and authentication methods that the server needs.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use SSH keys for administrator access where possible.<\/li>\n\n\n\n<li>Limit SSH access to approved users or groups.<\/li>\n\n\n\n<li>Disable direct root login after another administrative access path has been tested.<\/li>\n\n\n\n<li>Disable password authentication only after key-based access works in a new session.<\/li>\n\n\n\n<li>Review the SSH configuration for unused options and keep the service on a port and network path that match the environment.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Make one SSH change at a time. Keep the current session open and test a separate session after each authentication change. This helps prevent a routine configuration change from interrupting administration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Configure_the_firewall_for_required_services\"><\/span>Configure the firewall for required services<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Enable the host firewall and use a deny-by-default approach for inbound connections where the environment supports it. Allow SSH only from approved administration networks when possible.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>List the services that must be reachable from outside the server.<\/li>\n\n\n\n<li>Map each service to its required port and source network.<\/li>\n\n\n\n<li>Allow only those connections through the firewall.<\/li>\n\n\n\n<li>Remove temporary rules and unused services.<\/li>\n\n\n\n<li>Test each required service from its expected network.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Do not block a port simply because it is unfamiliar. First identify the process using it and confirm whether the service is required. Firewall rules should match the server role and its network design.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Keep_SELinux_enabled_and_verify_its_mode\"><\/span>Keep SELinux enabled and verify its mode<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">SELinux provides mandatory access controls in addition to normal Linux ownership and permission checks. For a production baseline, keep SELinux enabled and use enforcing mode unless the application has a documented, tested reason to use another setting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check the current mode and review denial messages when a service cannot access a file, port, or resource. Do not disable SELinux as the first response to an application problem. Correct the file context, service configuration, or policy requirement after identifying the cause. Test changes in a safe window so normal services are not disrupted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Install_updates_and_reduce_the_service_footprint\"><\/span>Install updates and reduce the service footprint<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Apply available AlmaLinux security and system updates before deployment. Reboot when an update requires it, then confirm that the expected services started normally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review installed packages and enabled services. Remove software that is not needed, and disable services that are not part of the server role. Fewer running services reduce the number of components that need access control, patching, and monitoring.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Set_up_logging_and_review_events\"><\/span>Set up logging and review events<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm that system logs are being collected and retained for a period that fits the operational and legal requirements of the environment. Include authentication events, privilege elevation, service failures, firewall activity, and SELinux events where available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Protect logs from unauthorized changes and make sure log storage cannot silently fill the system disk. If logs are sent to a separate system, verify that the receiving system is available and that events can be searched. Logging is useful only when someone reviews alerts and important events.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Review_file_ownership_and_permissions\"><\/span>Review file ownership and permissions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Check sensitive files, application directories, upload locations, backups, and service configuration files. Assign ownership to the service account or administrator role that needs it. Remove write access that is not required, especially for files executed by a service.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do not make application or configuration directories world-writable.<\/li>\n\n\n\n<li>Keep private keys, credentials, and backups readable only by approved accounts.<\/li>\n\n\n\n<li>Separate writable upload or data paths from executable application code where the application design allows it.<\/li>\n\n\n\n<li>Review permissions after deployments and package changes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Verify_the_baseline_before_deployment\"><\/span>Verify the baseline before deployment<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Test administrator access through the approved SSH method.<\/li>\n\n\n\n<li>Confirm that root login and password access match the approved policy.<\/li>\n\n\n\n<li>List firewall rules and test only the required inbound services.<\/li>\n\n\n\n<li>Confirm that SELinux is enabled and enforcing, if that is the approved baseline.<\/li>\n\n\n\n<li>Check update status and confirm that required services are running.<\/li>\n\n\n\n<li>Generate a test authentication or service event and verify that it appears in the expected logs.<\/li>\n\n\n\n<li>Review ownership and permissions for configuration, credential, data, and backup paths.<\/li>\n\n\n\n<li>Record the final settings, open ports, service list, and any approved exceptions.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Repeat these checks after major changes, not only during the initial setup. A hardened server still needs ongoing monitoring, timely updates, log review, access reviews, and tested recovery procedures.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[42],"manual_kb_tag":[],"class_list":["post-12416","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-miscellaneous"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12416\/revisions"}],"predecessor-version":[{"id":12429,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12416\/revisions\/12429"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=12416"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=12416"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=12416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}