Security — Defense in Depth on RHEL
Security — Defense in Depth on RHEL
Security is not a feature you add at the end — it is a layer you build into every decision. This category documents system hardening, SELinux, certificate management and compliance on RHEL 10.
What this category covers
| Topic | Status |
|---|---|
| SELinux — enforcing mode, contexts, booleans | ✅ |
| SELinux — semanage, audit2allow, ausearch | ✅ |
| Firewall — firewall-cmd, zones, rich rules | ✅ |
| HTTPS — self-signed certificates, openssl | ✅ |
| SSH hardening — keys, port, AllowUsers | ⬜ |
| Fail2ban — SSH and Nginx brute force | ⬜ |
| Let’s Encrypt with Certbot | ⬜ |
| CIS Benchmark — RHEL hardening | ⬜ |
| OpenSCAP — compliance scanning | ⬜ |
| auditd — system activity logging | ⬜ |
Posts in this category cover Module 09 — Security and Module 32 — Compliance of the roadmap.
This post is licensed under CC BY 4.0 by the author.