Verified live against a real Debian 12: the hardening actions work end-to-end (root + password self-lockout guards refuse correctly, auto-updates and ufw enable, disabling password auth persists and blocks password logins). One gap surfaced: on a minimal image without rsyslog the distro-default fail2ban sshd jail (logpath /var/log/auth.log) fails to start — "Have not found any log file". Pin the sshd jail to `backend = systemd` (reads the journal) via a jail.d drop-in on enable: log-source-agnostic and valid on every supported (systemd) target. fail2ban then comes up active with the sshd jail reading the journal. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Console/Commands | ||
| Events | ||
| Http | ||
| Jobs | ||
| Livewire | ||
| Models | ||
| Notifications | ||
| Providers | ||
| Rules | ||
| Services | ||
| Support | ||