Linux Setup

First steps when setting up a new Linux server - users, SSH keys, hostname, firewall, and basic hardening

Quick checklist for a fresh Debian/Ubuntu-style server: get off root, lock down SSH, set identity, then add a firewall and basic protections.

First login

Log in as root, change the password, and update the system:

passwd
apt update && apt full-upgrade

Create a non-root user with sudo privileges:

useradd --create-home --groups sudo cam
passwd cam

Log out, then reconnect as the new user.

SSH keys

Copy your public key to the server from your local machine. If you do not have a key yet, generate one first with ssh-keygen.

ssh-copy-id cam@hostname

Confirm you can get in without a password:

ssh cam@hostname

If you need root access over SSH, install the key there too:

sudo install -d -m 700 /root/.ssh
sudo install -m 600 ~/.ssh/authorized_keys /root/.ssh/authorized_keys

Once that is working, disable password auth at least for root. Debian's default is already PermitRootLogin prohibit-password, which only allows key-based root logins.

See also SSH Keys.

Timezone, locale, and hostname

Set the timezone and verify with date:

timedatectl list-timezones
sudo timedatectl set-timezone Europe/London
date

Set a hostname and make sure /etc/hosts matches:

sudo hostnamectl set-hostname homelab
cat /etc/hosts

Example /etc/hosts:

127.0.0.1  localhost
::1        localhost  ip6-localhost  ip6-loopback
127.0.1.1  homelab

Firewall

Deny all inbound traffic and allow only the ports you need. Make sure SSH is allowed before enabling the firewall, or you will lock yourself out.

sudo apt install ufw
sudo ufw default deny incoming
sudo ufw allow 22/tcp
sudo ufw enable

Add more rules only as services are exposed. See also UFW.

Automatic security updates

Security patches should not depend on remembering to log in every few days. Logs for unattended updates live in /var/log/unattended-upgrades/.

sudo apt install unattended-upgrades apt-listchanges
sudo dpkg-reconfigure --priority=low unattended-upgrades

After that, security updates mostly take care of themselves.

Intrusion prevention

fail2ban watches authentication logs and temporarily blocks IPs that look like they are brute-forcing your services.

sudo apt install fail2ban
sudo systemctl enable --now fail2ban

Last updated on

On this page