Mon serveur YunoHost
Matériel: Scaleway VPS
Version de YunoHost: 3.6.4.6
J’ai accès à mon serveur : SSH + webadmin
Êtes-vous dans un contexte particulier ou avez-vous effectué des modifications particulières sur votre instance ? : non
Description du problème
Bonjour à tous,
Je travaille sur le durcissement de la sécurité de mon système. J’utilise l’outil Lynis pour évaluer les points de faiblesses. Pouvez-vous me donner votre avis sur ces sujets, est-ce que suivre ces recommendations risque de compromettre le fonctionnement de yunohost ? ou ses mises à jour futuress :
- MongoDB instance allows any user to access databases [DBS-1820]
https://cisofy.com/lynis/controls/DBS-1820/ - Configure the ‘requirepass’ setting for Redis [DBS-1884]
- Details : /etc/redis/redis.conf
- Solution : configure ‘requirepass’ setting in /etc/redis/redis.conf
https://cisofy.com/lynis/controls/DBS-1884/
- Use the ‘rename-command CONFIG’ setting for Redis [DBS-1886]
- Details : /etc/redis/redis.conf
- Solution : configure ‘rename-command CONFIG’ in /etc/redis/redis.conf
https://cisofy.com/lynis/controls/DBS-1886/
- Turn off PHP information exposure [PHP-2372]
- Details : expose_php = Off
https://cisofy.com/lynis/controls/PHP-2372/
- Details : expose_php = Off
- Change the allow_url_fopen line to: allow_url_fopen = Off, to disable downloads via PHP [PHP-2376]
https://cisofy.com/lynis/controls/PHP-2376/
Merci
/
My YunoHost server
Hardware: Scaleway VPS
YunoHost version: 3.6.4.6
I have access to my server : SSH + webadmin
Are you in a special context or did you perform some particular tweaking on your YunoHost instance ? : no
Description of my issue
Good morning, everyone,
I am working on hardening the security of my system. I use the Lynis tool to assess weaknesses. Can you give me your opinion on these topics, will following these recommendations compromise the functioning of yunohost? or its future updates?
- MongoDB instance allows any user to access databases [DBS-1820]
https://cisofy.com/lynis/controls/DBS-1820/ - Configure the ‘requirepass’ setting for Redis [DBS-1884]
- Details : /etc/redis/redis.conf
- Solution : configure ‘requirepass’ setting in /etc/redis/redis.conf
https://cisofy.com/lynis/controls/DBS-1884/
- Use the ‘rename-command CONFIG’ setting for Redis [DBS-1886]
- Details : /etc/redis/redis.conf
- Solution : configure ‘rename-command CONFIG’ in /etc/redis/redis.conf
https://cisofy.com/lynis/controls/DBS-1886/
- Turn off PHP information exposure [PHP-2372]
- Details : expose_php = Off
https://cisofy.com/lynis/controls/PHP-2372/
- Details : expose_php = Off
- Change the allow_url_fopen line to: allow_url_fopen = Off, to disable downloads via PHP [PHP-2376]
https://cisofy.com/lynis/controls/PHP-2376/
Thanks,
M