15、Kingbasees人大金仓数据库加固
Categories:
少于1分钟
设置密码长度8位以上,由数字、字母、特殊符号组成,密码90天修改一次
ALTER USER system IDENTIFIED BY “new_password” PASSWORD EXPIRE;
ALTER PROFILE DEFAULT LIMIT PASSWORD_LIFE_TIME 90;
ALTER PROFILE DEFAULT LIMIT PASSWORD_REUSE_TIME UNLIMITED PASSWORD_REUSE_MAX UNLIMITED;
密码加密存储
ALTER USER system IDENTIFIED BY “new_password”;
用户登录失败5次锁定10分钟,登录空闲超时30分钟自动退出
ALTER PROFILE DEFAULT LIMIT FAILED_LOGIN_ATTEMPTS 5 PASSWORD_LOCK_TIME 10/1440;
ALTER PROFILE DEFAULT LIMIT IDLE_TIME 30;
建立三个账户:qwer(系统管理员),qazx(安全管理员),wsxc(审计管理员)
CREATE USER qwer IDENTIFIED BY “password”;
GRANT DBA TO qwer;
CREATE USER qazx IDENTIFIED BY “password”;
GRANT CONNECT, RESOURCE TO qazx;
CREATE USER wsxc IDENTIFIED BY “password”;
GRANT SELECT, INSERT, UPDATE, DELETE ON audit_table TO wsxc;
实现权限分离
GRANT DBA TO qwer;
GRANT CONNECT, RESOURCE TO qazx;
GRANT SELECT, INSERT, UPDATE, DELETE ON audit_table TO wsxc;
删除无用的账户
DROP USER testuser;
禁止root远程登录
ALTER USER sys IDENTIFIED BY “new_password”;
GRANT CREATE SESSION TO sys;
开启ssh,关闭telnet
systemctl enable sshd
systemctl disable telnet
关闭未使用的端口
firewall-cmd –zone=public –remove-port=port_number/tcp
firewall-cmd –zone=public –remove-port=port_number/udp
配置仅允许192.168.1.5登录,并禁用134、445、139端口
firewall-cmd –permanent –zone=public –add-rich-rule=‘rule family=“ipv4” source address=“192.168.1.5” accept’
firewall-cmd –permanent –zone=public –remove-port=134/tcp
firewall-cmd –permanent –zone=public –remove-port=445/tcp
firewall-cmd –permanent –zone=public –remove-port=139/tcp
日志发送到192.168.1.1
sed -i ’s/^#*.loghost.$/loghost 192.168.1.1/g’ /etc/syslog.conf
systemctl restart syslog
重启服务器使配置生效
reboot