Post

Security — Defense in Depth on RHEL

Security — Defense in Depth on RHEL

Security is not a feature you add at the end — it is a layer you build into every decision. This category documents system hardening, SELinux, certificate management and compliance on RHEL 10.


What this category covers

TopicStatus
SELinux — enforcing mode, contexts, booleans
SELinux — semanage, audit2allow, ausearch
Firewall — firewall-cmd, zones, rich rules
HTTPS — self-signed certificates, openssl
SSH hardening — keys, port, AllowUsers
Fail2ban — SSH and Nginx brute force
Let’s Encrypt with Certbot
CIS Benchmark — RHEL hardening
OpenSCAP — compliance scanning
auditd — system activity logging

Posts in this category cover Module 09 — Security and Module 32 — Compliance of the roadmap.

This post is licensed under CC BY 4.0 by the author.