配置规范问题:
麒麟的加固
1.检查设备密码复杂度策略
/etc/pam.d/password-auth 添加
/etc/pam.d/system-auth
password requisite pam_cracklib.so ucredit=-1 lcredit=-1 dcredit=-1
在password required pam_cracklib.so 后添加 minlen=6
2.检查是否设置口令生存周期
在文件/etc/login.defs中设置
默认值
PASS_MAX_DAYS 99999
PASS_MIN_DAYS 0
PASS_MIN_LEN 5
PASS_WARN_AGE 7
在文件/etc/login.defs中设置
PASS_MAX_DAYS 90 #检查口令更改最长时间
PASS_MIN_DAYS 6 #检查口令更改最小间隔天数
PASS_MIN_LEN 6 #设置口令最小长度
PASS_WARN_AGE 30 #检查口令过期前警告天数
3.检查重要目录或文件权限设置
chmod 750 /etc/rc.d/init.d
chmod 750 /tmp
chmod 750 /etc/rc6.d
chmod 750 /etc/rc5.d
chmod 750 /etc/rc4.d
chmod 750 /etc/rc3.d
chmod 750 /etc/rc2.d
chmod 750 /etc/rc1.d
chmod 750 /etc/rc0.d/
chmod 600 /etc/security
chmod 600 /boot/grub2/grub.cfg
chmod 644 /etc/services
chmod 644 /etc/group
4.检查重要文件属性设置 用 lsattr 查看权限 chattr -i 去掉权限
检查/etc/gshadow文件属性 chattr +i /etc/gshadow
检查/etc/shadow文件属性 chattr +i /etc/shadow
检查/etc/group文件属性 chattr +i /etc/group
检查/etc/passwd文件属性 chattr +i /etc/passwd
chattr +i /etc/gshadow
chattr +i /etc/shadow
chattr +i /etc/group
chattr +i /etc/passwd
5.mysql配置规范
检查是否禁止mysql以管理员账号权限运行
[mysqld]配置段中添加 user=mysql
更改root用户名 并删除测试数据库test
mysql> update user set user="syzl" where user="root";
mysql> flush privileges;
mysql> show databases;
mysql> drop database test;
mysql> flush privileges;
mysql配置规范
[mysqld]
user=mysql
slow_query_log = 1
log_error = /usr/local/mysql/mysql.err
slow_query_log = ON #开启慢查询
long_query_time =1 #设置慢查询时间 超过一秒的记录
log_bin = mysql-bin
server_id = 134
log-bin=mysql-bin
log-bin-index=master-bin.index
expire_logs_days = 7
binlog_format=row
slave_skip_errors=1062
log_slave_updates=1
max_connections = 1000
max_connection_errors=1000
wait_timeout=864000
interactive_timeout=864000
local-infile=0
character_set_server=utf8
init_connect='SET NAMES utf8'
basedir=/usr/local/mysql
datadir=/usr/local/mysql/data
socket=/tmp/mysql.sock
symbolic-links = 0
#不区分大小写
lower_case_table_names = 1
##不开启sql严格模式
sql_mode = "STRICT_TRANS_TABLES,ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION"
log-error=/var/log/mysqld.log
pid-file=/usr/local/mysql/data/mysqld.pid
max_allowed_packet = 15M
6.