back

Linux Server Hardening (Ubuntu)

A practical, beginner-friendly project to harden an Ubuntu server using security best practices.

Table of Contents

  1. Github Repository
  2. Config Files
  3. Validation Screenshots
  4. Tutorial Video in BN

Scope

This project focuses on:

  • Initial server baseline and inventory
  • SSH hardening with key-based authentication
  • Firewall and network controls
  • Brute-force mitigation (Fail2ban)
  • Automatic security updates
  • Logging and auditing basics
  • Backup and recovery readiness
  • Validation checklist and ongoing maintenance

Quick Start

  1. Read Project Overview
  2. Follow the guides in order (00 → 13)
  3. Execute commands carefully and test access after each critical change
  4. Complete Validation & Security Checklist
  5. Check out the Project Demonstration on Youtube

Safety Notes

  • Always keep one active root/console session while hardening SSH and firewall settings.
  • Test new SSH config in a second session before disconnecting your original session.
  • Back up config files before changes (see Appendix B).
  • Do not disable password auth until SSH keys are verified.
Copyright © 2026 Mahidul Haque. This post is licensed under a CC BY-NC-ND 4.0 license. You may read, learn, and share links to this post for non‑commercial, educational purposes, as long as you give appropriate attribution. You may not copy, reproduce, adapt, distribute, or use this work commercially without explicit permission.