Question : has anyone evaluated their Proxmox box with Lynis ?

Glowsome

Renowned Member
Jul 25, 2017
178
45
68
51
The Netherlands
www.comsolve.nl
Just a general question, as the topic said.

I myself have both a cluster and a standalone machine for testing purposes.
This machine is the result of a debian-install-move to proxmox based on the Wiki and Buster distro, running the latest 6.x version.

When running Lynis security audit https://downloads.cisofy.com/lynis/lynis-3.0.5.tar.gz it kind of scared me, as the default score was well below what i had expected on the box.
I started out with an index of like 52, i reconfigured some, and installing some tools stuff gaining me on a rerun to 68, stil some (imho is there to be done)

1626862613788.png

As some things are quite easily repaired/hardened some are like way beyond my understanding ( as in kernel hardening ) as i dont know the impact to ProxMox itself.
So in this i seek guidance.

In essence i am looking for a MINIMAL score of 80, so i need to gain atleast 12 points in hardening without compromising functionality.

- Glowsome
 
Last edited:
In essence i am looking for a MINIMAL score of 80, so i need to gain atleast 12 points in hardening without compromising functionality

Hi,

Lynis is a great tool. But security is not a tool, is much more like a process. It is also about the probability that a security problem to be exploited by enemys, and wat will be the impact in this case.

Sometimes, like you said, functionality is important, so you can not hardened your server. But you can minimize your attack surface with a good firewall (layer3 and/or layer7) as a simple example.

Good luck /Bafta !
 
Greetings
Did you make any progress on this topic? I'd be interested in the results.
Regards
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!