vi /etc/ssh/sshd_config
change “Port 22” if needed add “PermitRootLogin yes”
service sshd stop service sshd start apt-get update apt-get upgrade apt-get dist-upgrade
cp -a /root/.bashrc /root/.bashrc_ sed -i "s/# export LS_OPTIONS/export LS_OPTIONS/g" /root/.bashrc sed -i "s/# eval \"\`dircolors\`\"/eval \"\`dircolors\`\"/g" /root/.bashrc sed -i "s/# alias ls=/alias ls=/g" /root/.bashrc sed -i "s/# alias ll=/alias ll=/g" /root/.bashrc sed -i "s/# alias l=/alias l=/g" /root/.bashrc . /root/.bashrc
apt-get update apt-get install vim sysstat atop jnettop htop less iotop screen bootlogd
cp -a /etc/vim/vimrc /etc/vim/vimrc_ sed -i "s/\"syntax on/syntax on/g" /etc/vim/vimrc update-alternatives --set 'editor' "$(command -v 'vim.basic')"
cp -a /etc/sysctl.conf /etc/sysctl.conf_ cat << 'EOF' >> /etc/sysctl.conf
net.core.rmem_max = 16777216 net.core.wmem_max = 16777216
net.ipv4.tcp_rmem = 4096 87380 16777216 net.ipv4.tcp_wmem = 4096 65536 16777216
EOF
sysctl -p
cat << 'EOF' >> /etc/sysctl.conf
vm.swappiness = 1 EOF
sysctl -p
cp -a /etc/hdparm.conf /etc/hdparm.conf_ cat << 'EOF' >> /etc/hdparm.conf
/dev/sda { write_cache = off }
EOF
sed -i "s/^exit 0/for disk in \/sys\/block\/sd\?\/queue\/scheduler; do echo cfq > \$disk; done\n\nexit 0\n/g" /etc/rc.local
if [ ! -d "/opt/admin_scripts" ];then mkdir /opt/admin_scripts; fi echo "sed $'s/\^\[/\E/g;s/\[1G\[/\[27G\[/' /var/log/boot" > /opt/admin_scripts/bootlogd_showlog.sh chmod 750 /opt/admin_scripts/bootlogd_showlog.sh
[ /etc/default/grub ] #GRUB_CMDLINE_LINUX_DEFAULT="quiet" <-- disable line GRUB_CMDLINE_LINUX="systemd.log_target=kmsg systemd.log_level=debug" <-- add line
Tuning pour mount si ext3 :
vi /etc/fstab
Ajouter “,data=ordered,barrier=1” pour tous les filesystems sensibles Voir : http://serverfault.com/questions/279571/lvm-dangers-and-caveats
Changer le mot de passe initial :
passwd
Enregistrer un mot de passe généré par keepass et mettre à jour le keepass.
Si ce serveur ne dois pas être éteint souvent, installer molly-guard :
apt-get install molly-guard
Si serveur avec IDRAC sur eth0 :
echo "NETDOWN=no" >> /etc/default/halt
/!\ rebooter /!\
reboot
Kernel samepage Merging /sys/kernel/mm/ksm/run