---
title: "Linux server security checklist: from fresh install to hardened | StreetHosting"
description: "A practical Linux server hardening checklist: sudo user, SSH key, firewall, updates, Fail2ban, backups and the principle of least privilege, in the right order."
url: "https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist"
type: "page"
language: "en-US"
---

Infrastructure · 3 min · Intermediate

Published on Jun 17, 2026 · Updated on Jun 17, 2026

# Linux server security checklist

A freshly created server is far too open. This checklist puts the hardening steps in order, turning a default machine into a server that is hard to break into.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Security and hardening](https://streethosting.com.br/en/guides/topics/security) [Linux administration](https://streethosting.com.br/en/guides/topics/linux)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=Linux%20server%20security%20checklist%3A%20from%20fresh%20install%20to%20hardened&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist "Share on LinkedIn") [](https://wa.me/?text=Linux%20server%20security%20checklist%3A%20from%20fresh%20install%20to%20hardened%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flinux-server-security-checklist "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist.md)

In this guide 5 sections

* [Why harden a server](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#por-que-hardening)
* [Secure access](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#acesso)
* [Network and firewall](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#rede)
* [Maintenance and backups](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#manutencao)
* [Final checklist](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#checklist-final)

Quick answer

To make a **Linux server secure**, follow this order: create a user with sudo, turn on SSH key login and disable root, set up the firewall to allow only what is needed, keep the system updated, enable Fail2ban and keep tested off-site backups. The common thread is the principle of least privilege.

## Why harden a server[](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#por-que-hardening)

A freshly created server ships with open settings and gets scanned by bots minutes after it comes online. Hardening is the process of closing those gaps in order. Each step adds a layer, and together they turn a default machine into a hard target. It is the organized version of [protecting the server against brute force](https://streethosting.com.br/en/guides/infrastructure/protect-ssh-from-brute-force).

## Secure access[](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#acesso)

1. Create a user with sudo and stop using root day to day.
2. Set up login with an [SSH key and secure SSH](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps).
3. Disable direct root login and password authentication.
4. Use strong passwords wherever a password is still needed.

## Network and firewall[](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#rede)

Close the network to anything that is not in use. Configure the firewall to allow only the necessary ports and turn on [Fail2ban](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup) to ban anyone who keeps trying to break in. The less exposed you are, the smaller the attack surface.

Never leave databases or panels open to the entire internet. Expose each service only to the people who need it, through the firewall.

## Maintenance and backups[](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#manutencao)

Security is not a one-time event, it is a routine. Keep the system updated to close known vulnerabilities and keep tested off-site backups. Without a backup, a break-in or a mistake means total loss. With one, it is a recoverable scare.

Automate what you can: security updates and scheduled backups lower the chance of forgetting the basics when the day gets busy.

## Final checklist[](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#checklist-final)

* User with sudo and root disabled over SSH
* Key login on and password login off
* Firewall allowing only what is needed
* Fail2ban active against brute force
* System updated regularly
* Off-site, tested backups

This checklist puts your machine well above the default. To host on protected infrastructure in Brazil, check out the [Ryzen VPS](https://streethosting.com.br/en/vps/ryzen) and [dedicated servers](https://streethosting.com.br/en/dedicated).

In this guide

* [Why harden a server](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#por-que-hardening)
* [Secure access](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#acesso)
* [Network and firewall](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#rede)
* [Maintenance and backups](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#manutencao)
* [Final checklist](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist#checklist-final)

## Frequently asked questions

Where do I start securing a Linux server?

With access. Create a user with sudo, set up SSH key login and disable root login. That alone closes the doors automated attacks target most, before anything else.

What is the principle of least privilege?

It means giving each user and service only the permissions they actually need. That way, if something is compromised, the damage stays contained. Avoid running everything as root and separate responsibilities.

Is updating the system really that important?

It is one of the most important steps. Updates fix known vulnerabilities that attackers exploit at scale. An outdated server is an easy target, even if everything else is configured well.

Do backups count as security?

Yes, a lot. Backups are your safety net against ransomware, accidental deletion and intrusion. Even the best-protected server needs tested off-site backups to recover from the worst case.

Next step

See Ryzen VPS

Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.

[See Ryzen VPS](https://streethosting.com.br/en/vps/ryzen)

[See dedicated servers Exclusive hardware in São Paulo with NVMe and Anti-DDoS.](https://streethosting.com.br/en/dedicated) [See VPS plans Root VPS in Brazil with NVMe and Anti-DDoS.](https://streethosting.com.br/en/vps)

## Related guides

[VPS Intermediate How to secure SSH on a Linux VPS: keys, passwords, fail2ban SSH is usually the first target on any VPS with a public IP. This guide walks through a practical routine that cuts the risk without complicating your day: an ED25519 key, password-free login, admin access through sudo, blocking of automated attempts and a periodic review of authorized keys. 4 min Read guide](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps) [VPS Intermediate How to set up Fail2Ban on a VPS: SSH, Nginx and repeat offenders Fail2Ban reads your logs, spots the IPs that fail too often and bans them in the firewall. Learn how to set it up on Ubuntu 24.04, where the package defaults change how jails behave, and how to manage bans day to day. 8 min Read guide](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup) [Infrastructure Intermediate Protect SSH from brute force: a layered strategy Minutes after an IP goes live, bots start trying root and leaked passwords on SSH. This guide builds the defense in layers, from sshd\_config to a VPN, without locking your team out of the server. 8 min Read guide](https://streethosting.com.br/en/guides/infrastructure/protect-ssh-from-brute-force)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
