the most trusted source for computer security training, certification and research


Bastille-Linux Scripts to Secure Linux and HP-UX

Platforms:

Bastille has been ported/extended to the following platforms:

  • Red Hat Linux
  • HP-UX
  • Mandrake Linux
  • Debian Linux
  • SuSE Linux
  • TurboLinux
SGI shipped Bastille as part of its optional ISE package for its Series 1200 Linux Servers. They had been working on their own hardening scripts and scrapped those to use Bastille. Downloads indicated 2,000-4,000 users in addition to SGI.

Bastille-Linux is ready for use to harden Linux and HP-UX systems.

Click here for the main page. Right now, that page has usage instructions and a link to our mailing lists. We currently have two mailing lists:

Bastille-linux-announce
a moderated list for announcements regarding the project. To subscribe to the announcement list, please visit the above website or follow this link.
Bastille-linux-discuss
an unmoderated list for discussion of the project. To subscribe to the discussion list, please visit the above website or follow this link.
The announce list is NOT subscribed to the discussion list, so please subscribe to both if you're so inclined. If you wish to subscribe to the digest version of the list, it's probably simplest to subscribe directly from: The mailing lists are archived at:

Thank you for taking the time to read this message, and thank you in advance for your participation and response. Thanks especially to Alan Paller and Rob Kolstad at the SANS institute for supporting this work, to Andy Johnston at the University of Maryland, Baltimore County (UMBC), Hewlett Packard, IBM and MandrakeSoft for allowing Bastille developers to work on the project on company time, and to Ben Woodard over at VA Linux/VA Software for making our Internet Presence a reality and coordinating huge portions of this work.

Jon Lasser jon@umbc.edu
Lead Coordinator

Jay Beale jay@bastille-linux.org
Lead Developer


User Reactions To Bastille Linux

Bastille-Linux should be a Red Hat user's FIRST download. Every healthcare organization utilizing Red Hat in any capacity should place running the Bastille-Linux scripts at the top of their must-do list for information security.
- James Haughom, C.T.O., Heathcare Information Sharing and Analysis Center Information Security Network

I think that Bastille's policy of user education provides the most intelligent way of securing a Linux box. Since Bastille tells the new system administrator the rationale behind every action, security is simpler to live with and more likely to work.
- Ben Stern, Mathematics Dpmt, University of Maryland

The reaction to Bastille has been excellent here, by the way. A couple of our department IT contacts and a lot of the students have raved about it, especially the ease-of-use and the run-time explanations. I think Bastille is currently doing something you can't find anyone else doing.
- S.Groppi., Harvard U.

Bastille can automate the process of locking down a machine, or it can be used interactively, both to give you control of what services get disabled or reconfigured, and also as an invaluable tutorial. Don't try to set up a Linux firewall or webserver without Bastille's help.
- J. Dunitz, Network Engineer, E-Commerce Network Resource Group, Inc.

Bastille has made me aware of many important linux security issues. I've learned a lot about configuring services and system settings from the step by step configuration program.
- Josh Soref, U. Maryland student

Bastille linux is a highly recommended way for the [ordinary users] to easily secure Redhat 6.0.
- Alan Bishoff, Maintainer, Packet Storm

Bastille forced me to think about more issues in setting up machines - issues that are too easy to gloss over when you're in a hurry. I'm also pleased to say that it tidied up some sloppy configuration and in fact made at least one of the machines here perceptibly faster than a stock RH6 install. Both of these are good things.
- Arnim Littek, Med-Dev Ltd.

I wrote also some Firewall-scripts, I tested out yours, and so far, I liked yours the most :) Great Work.
- Joerg Mertin

More comments at www.bastille-linux.org/quotes.html


Contact us: (301) 654-SANS(7267)
Monday - Friday 9am-8pm EST/EDT