alegrey91 / systemd-service-hardening
Basic guide to harden systemd services
☆246Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for systemd-service-hardening
- Ansible role to apply a security baseline. Systemd edition.☆536Updated this week
- An Ansible playbook that applies the principle of the Infrastructure as Code on a QEMU/KVM environment.☆250Updated 2 years ago
- Use dropbear over wireguard.☆287Updated 3 months ago
- This Ansible role provides secure nginx configurations.☆188Updated 4 years ago
- CURSE is an SSH certificate signing server, built as an alternative to Netflix's BLESS tool, but without a dependency on AWS.☆219Updated 8 months ago
- ferm is a frontend for iptables☆344Updated 2 years ago
- Restart daemons after library updates.☆430Updated this week
- DevSec SSH Baseline - InSpec Profile☆283Updated 3 months ago
- Open source tool to help you build a valid SSL certificate chain.☆359Updated 4 years ago
- Terminal I/O logger☆316Updated last week
- How to use a Yubikey with OpenSSH without GPG☆155Updated 3 years ago
- This repository contains a tool for generating SELinux security profiles for containers☆490Updated last week
- ☆572Updated 4 months ago
- File Access Policy Daemon☆199Updated this week
- Ansible role for hardening Linux☆129Updated 4 months ago
- OpenBSD Router Boilerplate☆296Updated 5 years ago
- Ansible role for security hardening. Mirror of code maintained at opendev.org.☆670Updated last month
- harden system (linux, unix...)☆57Updated 2 weeks ago
- Two factor authentication for harddisk encryption☆614Updated 11 months ago
- Tang binding daemon☆516Updated last week
- Mini-Internet using LXC for practical works☆339Updated last year
- Provide SSH access to initramfs early user space on Fedora and other systems that use Dracut☆242Updated 2 weeks ago
- Use YubiKey to unlock a LUKS partition☆817Updated 6 months ago
- DebOps - Your Debian-based data center in a box☆1,262Updated 3 weeks ago
- PCI-DSS compliant Debian 10/11/12 hardening☆766Updated 2 months ago
- Script / daemon to blocking IP in nftables by country and black lists☆98Updated 3 months ago
- deprecated - maybe replaced by: `apparmor.d`☆87Updated 10 months ago
- ZFS Boot Environment manager for Linux☆190Updated 5 months ago
- Tools for using PIV tokens (like Yubikeys) as an SSH agent, for encrypting data at rest, and more☆194Updated 2 weeks ago
- dracut initramfs module to start dropbear sshd during boot to unlock the root filesystem with the (cryptsetup) LUKS passphrase remotely☆286Updated last year