Linux Setup
First steps when setting up a new Linux server - users, SSH keys, hostname, firewall, and basic hardening
Quick checklist for a fresh Debian/Ubuntu-style server: get off root, lock down SSH, set identity, then add a firewall and basic protections.
First login
Log in as root, change the password, and update the system:
passwd
apt update && apt full-upgradeCreate a non-root user with sudo privileges:
useradd --create-home --groups sudo cam
passwd camLog out, then reconnect as the new user.
SSH keys
Copy your public key to the server from your local machine. If you do not have a key yet, generate one first with ssh-keygen.
ssh-copy-id cam@hostnameConfirm you can get in without a password:
ssh cam@hostnameIf you need root access over SSH, install the key there too:
sudo install -d -m 700 /root/.ssh
sudo install -m 600 ~/.ssh/authorized_keys /root/.ssh/authorized_keysOnce that is working, disable password auth at least for root. Debian's default is already PermitRootLogin prohibit-password, which only allows key-based root logins.
See also SSH Keys.
Timezone, locale, and hostname
Set the timezone and verify with date:
timedatectl list-timezones
sudo timedatectl set-timezone Europe/London
dateSet a hostname and make sure /etc/hosts matches:
sudo hostnamectl set-hostname homelab
cat /etc/hostsExample /etc/hosts:
127.0.0.1 localhost
::1 localhost ip6-localhost ip6-loopback
127.0.1.1 homelabFirewall
Deny all inbound traffic and allow only the ports you need. Make sure SSH is allowed before enabling the firewall, or you will lock yourself out.
sudo apt install ufw
sudo ufw default deny incoming
sudo ufw allow 22/tcp
sudo ufw enableAdd more rules only as services are exposed. See also UFW.
Automatic security updates
Security patches should not depend on remembering to log in every few days. Logs for unattended updates live in /var/log/unattended-upgrades/.
sudo apt install unattended-upgrades apt-listchanges
sudo dpkg-reconfigure --priority=low unattended-upgradesAfter that, security updates mostly take care of themselves.
Intrusion prevention
fail2ban watches authentication logs and temporarily blocks IPs that look like they are brute-forcing your services.
sudo apt install fail2ban
sudo systemctl enable --now fail2banLast updated on