Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Red Hat, Inc.

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical, task-oriented hardening manual for anyone responsible for locking down Red Hat Enterprise Linux 8 servers and workstations—from install-time choices through crypto policy, compliance scanning, disk encryption, auditing, and device control. Best for sysadmins, security engineers, and Linux practitioners who want concrete RHEL 8 procedures rather than abstract theory. 【Book Arc】 - **Opening (~0%–12%)**: Frames the security mindset and vocabulary—confidentiality, integrity, availability; physical, technical, and administrative controls; vulnerability assessment methodology; and common threats to networks, servers, and workstations. Solves the "why and what" before the "how." - **Early (~12%–28%)**: Moves into build-time and baseline hardening: BIOS/UEFI security, disk partitioning, restricting network connectivity during install, minimal package installation, and post-install procedures, then system-wide cryptographic policies (including FIPS mode) and PKCS #11 hardware-backed keys. - **Early–Middle (~28%–36%)**: Covers shared system certificates and trust-store management, then configuration-compliance and vulnerability scanning with OpenSCAP, Red Hat OVAL feeds, and remediation to a chosen baseline (including Ansible-based remediation). - **Middle (~36%–52%)**: Consolidates the conceptual core—security controls, vulnerability assessment phases (reconnaissance, readiness, reporting), and the argument that security must be designed in, not bolted on after intrusion. - **Late (~52%–80%)**: Applies hardening to storage and access: network-bound disk encryption (NBDE) with Tang, Clevis, and TPM 2.0; LUKS enrollment and high-availability NBDE; system auditing with auditd and auditctl; application whitelisting; and USBGuard for intrusive USB devices. - **Ending (~80%–100%)**: The excerpts do not cover the closing chapters in detail; the table of contents suggests the book continues through the auditing, whitelisting, and USB-protection material listed above. 【Key Takeaways】 - **Security is a lifecycle, not a one-time task** (Middle): The book stresses that hardening spans planning, installation, configuration, monitoring, and remediation—organizations that treat security as an afterthought pay for it postmortem. - **CIA triad anchors every decision** (Middle): Confidentiality, integrity, and availability are the yardsticks for evaluating controls; availability is often formalized in SLAs, which matters when hardening could disrupt service. - **Controls come in three flavors** (Middle): Physical, technical, and administrative controls each address different risks; effective hardening combines all three rather than relying on technology alone. - **Crypto policy is centralized in RHEL 8** (Early): System-wide cryptographic policies let you set strong defaults, switch to legacy-compatible or FIPS modes, and opt individual applications out—reducing per-service cipher drift. - **Compliance is measurable and remediable** (Early–Middle): OpenSCAP scanning against baselines, OVAL vulnerability feeds, and automated remediation (including Ansible playbooks) turn "are we compliant?" into a repeatable workflow. - **Disk encryption can be network-bound** (Late): NBDE with Tang, Clevis, and TPM 2.0 enables automated unlocking of LUKS volumes, with high-availability options via Shamir's Secret Sharing. - **Auditing and allowlisting close the loop** (Late): auditd/auditctl rules, application whitelisting, and USBGuard provide detection and control over what runs and what connects. - **Vulnerability assessment has phases** (Middle): Reconnaissance → readiness → reporting, with findings classified by risk, gives a structured method rather than ad-hoc checking. 【Reading Tips】 - **Deep-read the early chapters** on install-time hardening and crypto policies; these decisions are hard to reverse later and set the tone for everything else. - **Skim the conceptual opening** if you already know CIA and control categories, but slow down on vulnerability assessment methodology—it frames the scanning chapters. - **Treat the late chapters as reference procedures**: NBDE, auditd, whitelisting, and USBGuard are best consulted when you actually deploy those features. - **Pair scanning chapters with your compliance target**: identify your baseline (e.g., PCI-DSS, STIG) before reading remediation sections so the OpenSCAP profiles make sense. - **Watch for the FIPS and crypto-policy trade-offs**: enabling strict modes can break legacy applications, so note the opt-out and modifier mechanisms. 【Coverage Limits】 This guide is based on stratified excerpts covering roughly the first half of the book plus table-of-contents entries for later chapters; detailed content of the closing chapters (auditing, whitelisting, USBGuard) is inferred from headings rather than full text.
Page 4
ies and are used with the OpenStack Foundation's permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack...
View in text
Page 5
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ....
View in text
Page 7
D ENROLLMENT OF LUKS-ENCRYPTED VOLUMES USING KICKSTART 9.10. CONFIGURING AUTOMATED UNLOCKING OF A LUKS-ENCRYPTED REMOVABLE STORAGE DEVICE 9.11. DEPLOYING HIG...
View in text
Page 11
deter or prevent unauthorized access to sensitive material. Examples of physical controls are: Closed-circuit surveillance cameras Motion or thermal alarm sy...
View in text
Page 13
nce between vulnerability assessments and penetration tests. Think of a vulnerability assessment as the first step to a penetration test. The information gle...
View in text
Page 15
r because it may not be as popular as other server software. Developers and system administrators often find exploitable bugs in server applications and publ...
View in text
Page 17
trokes and mouse clicks made by the client over the network. This problem was fixed in the SSH version 2 protocol, but it is up to the user to keep track of...
View in text
Page 20
n alleviate the burdens of multi- seat security deployments. Denial of Service (DoS) attacks Attacker or group of attackers coordinate against an organizatio...
View in text
Tags
AI categories
CybersecurityLinuxDevOps
linux
Publisher: Red Hat, Inc.
Publish Year: 2020
Language: English
File Format: PDF
File Size: 970.3 KB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…