These files are not created for production server. This are created for understanding basic server security. So don't use these files in production server and also don't test this files on main system as you may lock down your own system.
These are web server config file to sercure web servers and understanding basics of web server security. These only provide basic level like firewall and secure ssh.
Added in latest update:
- OWASP-oriented security snippets for Apache2 and Nginx (easy enable/disable)
- Fail2ban baseline hardening using
jail.ddrop-in config setup.shupdated to support major distro families (Debian based, Fedora/RHEL based, Arch based)
By default it will create backups of your default configuration files. But it will still ask for overwrite permission. So if want you want create backup manually You will get a chance to do that.
Scripts supports Debian based, Fedora based and Arch based distributions.
git clone https://github.com/varun-jagtap/webserver-config
cd webserver-config
sudo bash setup.shModsecurity default rule set will be replaced with owasp coreruleset for apache2 only (best effort, distro dependent). You can get more about owasp coreruleset here
By default script will install Apache with ModSecurity (best effort across distros).
New file:
apache2/conf-available/security-owasp.conf
Enable on Debian/Ubuntu:
sudo a2enmod headers
sudo a2enconf security-owasp
sudo systemctl reload apache2Nginx will have its default but modified configuration.
New file:
nginx/conf-available/security-owasp.conf
Enable on Debian/Ubuntu style Nginx layout:
sudo install -m 0644 nginx/conf-available/security-owasp.conf /etc/nginx/conf-available/security-owasp.conf
sudo ln -sf /etc/nginx/conf-available/security-owasp.conf /etc/nginx/conf-enabled/security-owasp.conf
sudo nginx -t && sudo systemctl reload nginxIt's highly recommend to have a firewall so this will install fail2ban.
New file:
fail2ban/jail.d/owasp-baseline.local
Install:
sudo install -d /etc/fail2ban/jail.d
sudo install -m 0644 fail2ban/jail.d/owasp-baseline.local /etc/fail2ban/jail.d/owasp-baseline.local
sudo systemctl restart fail2banBy default virtual files will not be installed. So if want install it just copy the following file into:
Apache2
site.com.conf > /etc/apache2/sites-available/
And enable them with command:
sudo a2ensite filename
make sure that you have disabled the default files(000-default.conf). If you haven't then use command:
sudo a2dissite filename do disable
Nginx
site.com > /etc/nginx/sites-available/
And enable them with command:
cd /etc/nginx/site-enabled/
sudo ln -s /etc/nginx/sites-available/filenamemake sure that you have disabled the default files(default). If you haven't then use command:
cd /etc/nginx/site-enabled/
sudo rm default