Configuration is now held by the `.org` files. All `.nix` files are tangled from the org-mode files.
3.1 KiB
Kernel Hardening
Kernel Hardening
Some of my machines are exposed to the Internet, and therefore get
their kernel hardened. First, let me declare the Nix file’s skeleton,
with the nixos.hardened module.
{
flake.modules.nixos.hardened = {
boot = {
<<kernel-modules>>
<<kernel-options>>
};
};
}
Kernel Modules
The very first thing to do is to load the tcp_bbr kernel module. It
increases the connection speed of the system with a better congestion
control. It is particularly interesting for my servers, as they may
have to deal with high traffic if a crawler ever decides to explore
all webpages offered by some websites I host. See this article by
Nixcraft for more details.
kernelModules = ["tcp_bbr"];
Kernel Options
Next are a series of kernel options.
kernel.sysctl = {
<<sysrq-key>>
<<icmp>>
<<icmp-no-accept-redirects>>
<<icmp-no-send-redirects>>
<<ip-source-route-packets>>
<<syn>>
<<tcp-time-wait>>
<<bufferfloat>>
<<latency>>
};
First, we’ll disable the magic SysRq key. Not that I expect anyone to have physical access to my servers, but it is a really powerful tool that I’d rather have off.
"kernel.sysrq" = 0;
Next, we’ll ignore ICMP broadcasts to avoid participating in Smurf attacks, and we’ll also ignore ICMP errors.
"net.ipv4.icmp_echo_ignore_broadcasts" = 1;
"net.ipv4.icmp_ignore_bogus_error_responses" = 1;
Speaking of ICMP, we won’t accept ICMP redirects to prevent some MITM attacks.
"net.ipv4.conf.all.accept_redirects" = 0;
"net.ipv4.conf.default_accept_redirects" = 0;
"net.ipv4.conf.all.secure_redirects" = 0;
"net.ipv4.conf.default.secure_redirects" = 0;
"net.ipv6.conf.all.accept_redirects" = 0;
"net.ipv6.conf.default.accept_redirects" = 0;
And we won’t send ICMP redirects (we’re not a router).
"net.ipv4.conf.all.send_redirects" = 0;
We’re stil not a router, so we’ll refuse IP source route packets, both on IPV4 and IPV6.
"net.ipv4.conf.all.accept_source_route" = 0;
"net.ipv6.conf.all.accept_source_route" = 0;
Now, let’s get some SYN flood protection.
"net.ipv4.tcp_syncookies" = 1;
And protection against TCP time-wait assassination hazards.
"net.ipv4.tcp_rfc1337" = 1;
We will also mitigate bufferfloat, including with BBR (hey, we enabled that above!)
"net.ipv4.tcp_congestion_control" = "bbr";
"net.core.default_qdisc" = "cake";
And lastly, we’ll reduce latency on IPV4.
"net.ipv4.tcp_fastopen" = 3;
And we should be good to go!