Page 1 of 2

Any guidelines for hardening the Nagios Core VM?

Posted: Mon May 11, 2015 1:16 pm
by byau
We purchased nagios vm and our customer has given us a directive to harden all linux boxes and linux based boxes, including nagios vm.

Does anyone have a hardening guide for it?  Customer did provide us with a CentOS hardening guide to use which looks to just be made of general CentOS hardening tips found on the internet.

Any input or suggestions?
Thank you

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Mon May 11, 2015 1:30 pm
by ssax
Here is the documentation that we have for security, you could also look at using ModSecurity, etc.

http://nagios.sourceforge.net/docs/nagi ... urity.html

http://nagios.sourceforge.net/docs/nagi ... urity.html

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Tue May 12, 2015 12:35 pm
by byau
Appreciate it thank you!

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Tue May 12, 2015 2:41 pm
by ssax
No problem, can we mark this as resolved and lock the topic?

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Thu May 14, 2015 3:05 am
by byau
Hi, I will be going through the links today and tomorrow. Can I keep it open in case I have further questions?

We should be able to lock it as resolved by next Tuesday at the latest, hopefully earlier

Is this okay?

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Thu May 14, 2015 1:11 pm
by ssax
Sure, no problem, we'll leave it open.

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Fri May 15, 2015 5:36 pm
by byau
Hello - Can I attach or post the hardening guide sent to me and have someone look through it and give me their recommendations? I understand that your recommendations of the hardening guide will not be run through any QA cycle of any sort and it is to our risk to test it and rollback.

That being said, you guys know the internals of nagios and I would love to hear your thoughts on the hardening guide as to what should not be changed, what changes are likely okay because it likely won't affect nagios, etc.

The easiest way was to snapshot the relevant parts as images and paste into word doc to help protect customer identity and also take out a lot of the extra text in there.

Can someone at Nagios provide me some thoughts? Thank you!

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Fri May 15, 2015 5:38 pm
by byau
The entire doc with snapshots too large, it is in three parts

Thanks!

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Fri May 15, 2015 5:39 pm
by byau
part 3.
thanks!

Re: Any guidelines for hardening the Nagios Core VM?

Posted: Mon May 18, 2015 10:08 am
by abrist
Alright, many things are covered in this doc. It looks good on face, but many of these suggestions are environment and configuration dependent.
Has your security or ops teams looked this?
Do you have any questions about specific items from the doc?