This is the checklist I follow whenever I set up a new Ubuntu server.
Generate New SSH Key
ssh-keygen -o -a 100 -t ed25519 -f ~/.ssh/id_ed25519 -C "you@example.com"eval "$(ssh-agent -s)"
# macOS Sierra 10.12.2 or latervim ~/.ssh/config###Host * AddKeysToAgent yes UseKeychain yes IdentityFile ~/.ssh/id_ed25519 IdentityFile ~/.ssh/id_rsa # Keep the old key file###ssh-add -K ~/.ssh/id_ed25519
ssh -i ~/.ssh/id_ed25519 root@hostnameAdd New User
adduser risanusermod -aG sudo risanAdd SSH Key
Log in as the new user and add our public key:
sudo su risancdmkdir ~/.sshchmod 700 ~/.sshvim ~/.ssh/authorized_keys###Copy from our machine: pbcopy < ~/.ssh/id_ed25519.pub###chmod 600 ~/.ssh/authorized_keysThen harden the SSH server:
sudo vim /etc/ssh/sshd_config
Port 2270PermitRootLogin noPasswordAuthentication no # defaultPubkeyAuthentication yes # defaultChallengeResponseAuthentication no # default
sudo service ssh restartSet the default editor, the timezone, and install NTP:
sudo update-alternatives --config editorsudo dpkg-reconfigure tzdatasudo apt-get install ntpInstall Nginx
sudo add-apt-repository -y ppa:nginx/stablesudo apt-get updatesudo apt-get install -y nginxsudo service nginx start
sudo mv /etc/nginx /etc/nginx.baksudo git clone https://github.com/risan/nginx-config.git /etc/nginxInstall PHP
sudo add-apt-repository -y ppa:ondrej/phpsudo apt-get updatesudo apt-get install -y php7.1-fpm php7.1-cli php7.1-common php7.1-curl php7.1-mysql php7.1-sqlite3 php7.1-gd php7.1-xml php7.1-mcrypt php7.1-mbstringiptables
sudo iptables -A INPUT -i lo -j ACCEPTsudo iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPTsudo iptables -A INPUT -p tcp --dport 22 -j ACCEPTsudo iptables -A INPUT -p tcp --dport 2270 -j ACCEPTsudo iptables -A INPUT -p tcp --dport 80 -j ACCEPTsudo iptables -A INPUT -p tcp --dport 443 -j ACCEPTsudo iptables -P INPUT DROP
sudo apt-get install -y iptables-persistent netfilter-persistentsudo service netfilter-persistent startFail2Ban
sudo apt-get install -y fail2bansudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.localsudo service fail2ban restart