15、Kingbasees人大金仓数据库加固

设置密码长度8位以上,由数字、字母、特殊符号组成,密码90天修改一次

ALTER USER system IDENTIFIED BY “new_password” PASSWORD EXPIRE;

ALTER PROFILE DEFAULT LIMIT PASSWORD_LIFE_TIME 90;

ALTER PROFILE DEFAULT LIMIT PASSWORD_REUSE_TIME UNLIMITED PASSWORD_REUSE_MAX UNLIMITED;

密码加密存储

ALTER USER system IDENTIFIED BY “new_password”;

用户登录失败5次锁定10分钟,登录空闲超时30分钟自动退出

ALTER PROFILE DEFAULT LIMIT FAILED_LOGIN_ATTEMPTS 5 PASSWORD_LOCK_TIME 10/1440;

ALTER PROFILE DEFAULT LIMIT IDLE_TIME 30;

建立三个账户:qwer(系统管理员),qazx(安全管理员),wsxc(审计管理员)

CREATE USER qwer IDENTIFIED BY “password”;

GRANT DBA TO qwer;

CREATE USER qazx IDENTIFIED BY “password”;

GRANT CONNECT, RESOURCE TO qazx;

CREATE USER wsxc IDENTIFIED BY “password”;

GRANT SELECT, INSERT, UPDATE, DELETE ON audit_table TO wsxc;

实现权限分离

GRANT DBA TO qwer;

GRANT CONNECT, RESOURCE TO qazx;

GRANT SELECT, INSERT, UPDATE, DELETE ON audit_table TO wsxc;

删除无用的账户

DROP USER testuser;

禁止root远程登录

ALTER USER sys IDENTIFIED BY “new_password”;

GRANT CREATE SESSION TO sys;

开启ssh,关闭telnet

systemctl enable sshd

systemctl disable telnet

关闭未使用的端口

firewall-cmd –zone=public –remove-port=port_number/tcp

firewall-cmd –zone=public –remove-port=port_number/udp

配置仅允许192.168.1.5登录,并禁用134、445、139端口

firewall-cmd –permanent –zone=public –add-rich-rule=‘rule family=“ipv4” source address=“192.168.1.5” accept’

firewall-cmd –permanent –zone=public –remove-port=134/tcp

firewall-cmd –permanent –zone=public –remove-port=445/tcp

firewall-cmd –permanent –zone=public –remove-port=139/tcp

日志发送到192.168.1.1

sed -i ’s/^#*.loghost.$/loghost 192.168.1.1/g’ /etc/syslog.conf

systemctl restart syslog

重启服务器使配置生效

reboot