Skip to content

Latest commit

 

History

56 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

This project has been created as part of the 42 curriculum by yoabied.

📄 🐪

📑 Table of Contents

📊 Project Overview

Mandatory Requirements

  • ✅ Virtual machine using VirtualBox or UTM
  • ✅ Latest stable Rocky Linux (no graphical interface)
  • ✅ LVM with at least 2 encrypted partitions
  • ✅ SSH service on port 4242 only
  • ✅ firewalld configured
  • ✅ Strong password policy implemented
  • ✅ Sudo configured with strict rules
  • ✅ Monitoring script displaying system info every 10 minutes

Bonus Requirements

  • ✅ Complex partition structure (multiple logical volumes)
  • ✅ WordPress website with Apache (httpd), MariaDB, and PHP
  • ✅ Additional useful service (FTP, Fail2ban, etc.)

🖌️Description

Virtualization

Virtualization is a technology used to create virtual representations of servers, storage, networks, and other physical machines. Virtualization software mimics the functions of physical hardware, allowing multiple virtual machines to run simultaneously on a single physical machine. Businesses use virtualization to utilize hardware resources more efficiently and achieve better returns on their investment. It also powers cloud computing services, helping organizations manage infrastructure more effectively. Additionally, virtualization is a solution for limited hardware resources, as it provides users with an isolated environment. The physical machine is called the host, while the virtual machine running on it is called the guest.

Hypervisor

It is software that sits in between the hardware and the VMs for the sake of managing resources for VMs. The hypervisor is divided into two types

Hypervisor

Type 1 (Bare Metal)

This type is a native solution that sits directly on top of the hardware. It is capable of acting as the operating system for the physical server, such as:

Type 1

Type 2 (Hosted)

It is software that sits on top of your main OS, such as:

Type 2

Resources

Instructions

Installation Workflow

A followed example of me working on the approach of how does Anaconda work in text/shell mode.

oo

2. Storage Configuration (Anaconda Shell)

We bypass the automatic partitioner to perform a custom setup using fdisk, LUKS encryption, and LVM.

Get yourself your OS iso --> You're supposed to know why you chose this last one --> create a machine on virtual box

Language --> Timezone --> Root & User Creds

(Switch to Shell) --> fdisk (Partitioning) --> LUKS (Encryption) --> LVM (Logical Volumes)

(Resume Installer) --> Mount Points --> Begin Installation

meme

Project description

On this project I involved it into setting up a secure and efficient server environment that's using Rocky Linux. The main objectives include:

iuhm

🐧 Operating System & Design Choices

1. Choice of Operating System

For this project, I chose Rocky over Debian Linux because basically why not. Rocky

Debian vs. Rocky Linux

Feature Debian Rocky Linux (Selected)
Philosophy Strictly open-source, community-driven project . Enterprise-focused, bug-for-bug compatible with RHEL.
Package Manager APT (Advanced Package Tool) & .deb packages. DNF / YUM & .rpm packages.
Stability Known for extreme stability; older but tested packages. Stable, but follows Red Hat enterprise release cycles.
Community Massive global community and documentation. Smaller community (successor to CentOS).
Use Case General purpose servers and desktops. Corporate environments requiring RHEL compatibility.

2. Design Choices & Policies

To ensure a secure and efficient server environment, the following configurations were implemented:

Security Policies

  • Password Policy: strict rules for password complexity and expiration (via pwquality).
  • Sudo: Restricted privileges with TTY usage enforcement and log archiving.
  • SSH: Root login disabled, custom port (4242), and key-based authentication preferred.

User Management

  • Root Account: Reserved solely for system administration tasks.
  • Primary User: Added to the sudo and user42 groups for elevated privileges.

Services Installed

uhm

To maintain a minimal and secure footprint, only essential services were installed:

  • SSH (OpenSSH Server): For remote access on port 4242.
  • Firewalld: For managing network traffic and ports.
  • Cron: For scheduling system maintenance tasks.
  • Git: Installed to fetch and deploy project repositories.
  • Lighttpd & WordPress: Hosted to serve a specific Unity-based video game project.

3. Technology Comparisons

VirtualBox vs. UTM

tm

VirtualBox UTM (QEMU backend)
Architecture Primarily x86 virtualization. Supports emulation of different architectures (ARM, x86, PPC).
Performance Excellent for x86-on-x86 virtualization. Native speed on Apple Silicon (M-series) via Hypervisor.framework.
OS Support Cross-platform (Windows, Linux, macOS). Exclusive to macOS/iOS.

AppArmor vs. SELinux

VS

AppArmor (Debian default) SELinux (Rocky/RHEL default)
Model Path-based access control. Profiles are attached to specific file paths. Label-based access control. Files/processes are tagged with security contexts.
Ease of Use Generally considered easier to learn and configure. Steeper learning curve; very granular but complex.
Mode Less intrusive; often defaults to "complain" mode. Highly intrusive; enforces strict policies by default ("enforcing").

UFW vs. Firewalld

UFW

UFW (Uncomplicated Firewall) Firewalld
Interface A simplified command-line wrapper for iptables/nftables. A dynamic firewall manager with support for network "zones".
Usage Designed for simplicity (e.g., ufw allow 4242). Uses XML configuration and DBus. Complex zone management.
Target Single-host servers and beginners (Debian standard). Complex network environments (RHEL standard).

Disk Partitioning

1. LVM & LUKS Configuration

For this project, I utilized LVM (Logical Volume Management) within an Encrypted (LUKS) partition. This structure allows for dynamic resizing of partitions and ensures data security at rest.

  • /boot: Unencrypted (required for bootloader).
  • LVM: Encrypted volume containing logical volumes for /root, /home, /var, etc.

2. fdisk vs. parted: A Brief Comparison

fdisk and parted are both powerful and widely used tools for partitioning disks in Linux systems. They have their advantages and specific use cases, but they also differ in some key aspects.

fdisk

fdisk is a widely used, text-based utility for managing disk partitions on Linux systems. It supports creating, deleting, and modifying partitions on a hard disk. While fdisk primarily works with MBR (Master Boot Record) partition tables, it also offers limited support for GPT (GUID Partition Table) partition tables. Some of the reasons to choose fdisk include:

  • Familiarity: fdisk has been around for a long time, and many users are accustomed to using it.
  • Simplicity: fdisk provides a straightforward interface for managing partitions, making it easier for users to accomplish their tasks.

parted

parted is another command-line utility for partitioning hard drives on Linux systems. It is more advanced than fdisk and supports a broader range of partition table formats, including MBR and GPT. Some reasons to choose parted include:

Greater compatibility: parted works with a wider variety of partition tables, making it more versatile for managing modern hard drives. Advanced features: parted offers more advanced functionality, such as resizing partitions without data loss.

Text Mode (CLI)

uhm Text Mode, often referred to as the Command Line Interface (CLI) or "Headless" mode, is a method of interacting with the computer using only text commands, without a Graphical User Interface (GUI) like GNOME or KDE.

How it works: Instead of clicking icons, the user types commands into a shell (like Bash). The system processes these text inputs and returns text outputs.

  • Performance: It consumes significantly fewer resources (RAM/CPU) because the system doesn't need to render heavy graphics.
  • Stability: Fewer moving parts (graphical drivers, window managers) means fewer things can crash.
  • Server Standard: Almost all professional servers run in text mode to maximize performance for the actual services.

⚙️ Configuration Cheatsheet

User & Group Management (Rocky Linux)

To fulfill the project requirements of managing groups, here are the commands used:

  1. Check existing groups for a user:

    groups <username>
  2. Add a user to the wheel group (Admin/Sudo rights on Rocky):

    usermod -aG wheel <username>
  3. Add a user to the user42 group (Project requirement):

    # First, create the group if it doesn't exist
    groupadd user42
    
    # Add the user
    usermod -aG user42 <username>

🔥 Firewalld Configuration

Rocky Linux uses firewalld by default.

  1. Check Status:
    systemctl status firewalld
  2. Add Port 4242 (SSH):
    firewall-cmd --permanent --add-port=4242/tcp
    firewall-cmd --reload
  3. List Open Ports:
    firewall-cmd --list-ports

🌐 WordPress & Lighttpd

To set up a WordPress site using Lighttpd on Rocky Linux, follow these steps:

  1. Install Lighttpd and PHP:
    dnf install lighttpd php php-mysqlnd -y
  2. Start and enable Lighttpd:
    systemctl start lighttpd
    systemctl enable lighttpd
  3. Download and set up WordPress:
    cd /var/www/html
    wget https://wordpress.org/latest.tar.gz
    tar -xzf latest.tar.gz
    mv wordpress/* .
    rm -rf wordpress latest.tar.gz
    chown -R lighttpd:lighttpd /var/www/html
  4. Configure Lighttpd for WordPress: Create a configuration file for your site:
    nano /etc/lighttpd/conf.d/wordpress.conf        
    Add the following content:

WordPress config files

📄 WordPress Page

Installation & Setup

Getting into wordpress on Rocky Linux, the installation process was pretty straightforward and easy to follow, I won't go into details about the installation process since it's pretty well documented online, but I will share some screenshots of the process and the final result.

in here you basicaly have the Welcome page of the WordPress installation where you have to choose a title for you wordpress page and create an admin account for it using both Username Password and email, I went with the name of Na9a's wordpress for the page and for the admin account I went with my login yoabied as a username and a random password.' Here is a screenshot of the welcome page:

Welcome Page

After that you'll meet a datebase page where you have to fill in the database credentials that you created for the WordPress page, I went with the name of wordpress for the database and wpuser as a username and a default password as it didnt matter for me, here is a screenshot of the database page:

Wordpress Databass

Learning the basics of how to make a WordPress

Setting up the page for my WordPress and since I have no time and no life I decided to not go easy on myself and make it fun, good & educational talking about personal life and all that HHHH, it's beautiful and I am proud of it, making two pages i will update it if I remember to do so, but for evaluation it was a masterpiece that I am proud of.

  • During the making of the WordPress page, I realized the fact that it seemed so much like a Canva building presentation no HTML interface just a background and some text, so I decided to build it like that and as a way to learn how to make a WordPress page I ended up with this:

WordPress page

A switch

Switch in between the idea of building a website by just a the WordPress "canvas like" interface, to building it from scratch by using HTML and Claude it wasn't that bad it was actually great like :

HTML page

🎮 Extra-service

Reaching the extra service requirement, I decided to host a Unity-based video game project on the server using Lighttpd and WordPress. This involved setting up a web server to serve the game files, at this point I was so lazy that I only ended up by having a background made up by Canva thanks to my laziness HHHH no HTML just a Canva background, other than that the game was also hosted on localhost but bounded through TCP connection via the port 2504 basically localhost:2504, the game was a simple 2D top-down game that I made in unity me and my friends through the MGJ2 GameJam themed Echo and the game is all about a little girl who's trying to find her way back home while being stuck in a old mention and that's by following the echoes of sum left behind notes,here is a screenshot of the game:

Game Screenshot

Remaking of lighttpd config file :

🖥️ Monitoring Script

#!/bin/bash

ARCH=$(uname -a)

CPU_PHYSICAL=$(lscpu | awk '/Socket\(s\)/ {print $2}')
VCPU=$(lscpu | awk '/^CPU\(s\)/ {print $2}')

RAM=$(free -m | awk '/Mem:/ { printf "%d/%dMB (%.2f%%)", $3, $2, $3*100/$2 }')

DISK=$(df -m --total | awk '/total/ {printf "%d/%dMB (%s)", $3, $2, $5}')

CPU_LOAD=$(top -bn1 | awk '/Cpu\(s\)/ {printf "%.1f%%", 100 - $8}')

LAST_BOOT=$(who -b | awk '{print $3 " " $4}')

LVM_USE=$(lsblk | grep -q lvm && echo "yes" || echo "no")

TCP_CONN=$(ss -tn state established | wc -l)

USER_LOG=$(who | awk '{print $1}' | sort -u | wc -l)

IP=$(hostname -I | awk '{print $1}')

#MAC=$(ip a | grep "link/ether" | awk '{print $2}')
MAC=$(nmcli device show | grep GENERAL.HWADDR: | head -1 | awk '{printf "%s", $2}')
SUDO_CMDS=$(journalctl _COMM=sudo | grep COMMAND | wc -l)

wall "
#Architecture: $ARCH
#CPU physical : $CPU_PHYSICAL
#vCPU : $VCPU
#Memory Usage: $RAM
#Disk Usage: $DISK
#CPU load: $CPU_LOAD
#Last boot: $LAST_BOOT
#LVM use: $LVM_USE
#Connections TCP : $TCP_CONN ESTABLISHED
#User log: $USER_LOG
#Network: IP $IP $(echo -n "(")$MAC$(echo -n ")")
#Sudo : $SUDO_CMDS cmd
"

echo " .-----------------. .----------------.  .----------------.  .----------------.
| .--------------. || .--------------. || .--------------. || .--------------. |
| | ____  _____  | || |      __      | || |    ______    | || |      __      | |
| ||_   \|_   _| | || |     /  \     | || |  .' ____ '.  | || |     /  \     | |
| |  |   \ | |   | || |    / /\ \    | || |  | (____) |  | || |    / /\ \    | |
| |  | |\ \| |   | || |   / ____ \   | || |  '_.____. |  | || |   / ____ \   | |
| | _| |_\   |_  | || | _/ /    \ \_ | || |  | \____| |  | || | _/ /    \ \_ | |
| ||_____|\____| | || ||____|  |____|| || |   \______,'  | || ||____|  |____|| |
| |              | || |              | || |              | || |              | |
| '--------------' || '--------------' || '--------------' || '--------------' |
 '----------------'  '----------------'  '----------------'  '----------------' "

Conclusion

I've successfully completed the Born2BeRoot project, setting up a secure and optimized server environment using Rocky Linux. This project covered essential skills in virtualization, disk management, and server security.

THIS README IS STILL UNDERCONSTRUCTION

Builder

About

Born2BeRoot is a system administration project from the 42 curriculum focused on building a secure Linux server using Rocky Linux inside a virtual machine. The project covers virtualization, disk encryption with LUKS, logical volume management (LVM), firewall and SSH hardening, user and permission management.....

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages