RH253 Red Hat Networking & Security Administration
UNIT 1 – Introduction to System Services
Objectives
Agenda
Service Management
Services Managed by init
System V service Management
Chkconfig
Xinetd managed Series
The xinetd Daemon
The/etc/sysconfig/ files
Fault Analysis
End of Unit 1
Lab: Introduction to System Services
UNIT 2 – Organizing Network Systems
Objectives
Agenda
Domain Name SystemDNS
Zones, Domains & Delegation
Name Server Hierarchy
The DNS Server
Berkeley Internet Name Domain (BIND)
Service Profile: DNS
Configuring BIND
Global Options
Address Match Lists and ac1
Rndc
Master and Slave Zones
Reverse Lookup Zones
Special Zones
Zone Files
Resource Records (RR)
SOA (Start of Authority)
NS (Name Server)
Main Record Types
Example Zone File
Round Robin Load Sharing through DNS
Delegating Subdomains
BIND Syntax Utilities
Caching-only Name Server
BIND Utilities
Advanced BIND Features
DHCP Overview
Service Profile: DHCP
Configuring a DHCP Server
End of Unit 2
Lab: Organizing Networked Systems
UNIT 3 – Network File Sharing Services
Objectives
Agenda
NFS File Service (NFS)
SFS Server
Client-side NFS
FTP
Service Profile: FTP
Samba Services
Samba Daemons
Service Profile: SMB
Configuring Samba
Overview of smb.conf Sections
Configuraring File and Directory Sharing
Printing to the Samba Server
Authentication Methods
Passwords
Samba Client Tools: smbclient
Nmblookup
Smbmount
Samba mouts in /etc/fstab
End of Unit 3
Lab: Network File Sharing Services
UNIT 4 – Electronic Mail Services
Objectives
Agenda
Sendmail Features
Security and “Anti-Spam” Features
An Email Review
Server Operations
Service Profile: Sendmail
Main Configuration Files
Other Configuration Files
Sendmail Configuration with the m4 Macro Language
Sendmail m4 Macro File: Introduction
Sendmail m4 Macro File: Features
Sendmail Client Configuration
Other Valuable m4 directives
Additional Sendmail Configuration Files
/etc/mail/virtusertable
/etc/mail/access
Blacklisting Recipients
Debugging Sendmail
Using alternatives
Postfix
Service Profile:Postfix
Configuring postfix
Additional Postfix Configuration
Enhanced Postfix Configuration
Procmail Delivery
Procmail sample Configuration
End of Unit 4
Lab: Electronic Mail Services
UNIT 5 – The HTTP Service
Objectives
Agenda
Apache Overview
Service Profile:HTTPD
Apache Configuration
Apache Server Configuration
Virtual Hosts
Apache Namespace Configuration
Apache Access Configuration
Using .htaccess Files
CGI
Notable Apache Modules
Apache Encrypted Web Server
Squid Web Proxy Cache
Service Profile: Squid
End of Unit 5
Lab: The HTTP Service
UNIT 6 – Security Concerns and Policy
Objectives
Agenda
Definition of Security
Attacks from the Network
Principles of Security
Security Practices
Diagnostic Utilities
Which Services Are Running?
Remote service Detecting
Isolate Vulnerabilities
Security Policy: the System
Security Policy: the People
Response Strategies
Additional Resources
End of Unit 7
Lab: Security Concerns and Policy
UNIT 7 – Authentication Services
Objectives
Agenda
Authentication Basics
Service Profile: PAM
PAM Operation
/etc/pam.d/system-auth
Core PAM Modules
Authentication Modules
Miscellaneous PAM Modules
Password Security
Password Policy
Resource Limits
User Access Control
Single User Mode
Sudo
Authentication Troubleshooting
NIS Overview
Service Profile: NIS
NIS Server Topology
Configuring an NIS Server
NIS Client Configuration
NIS Troubleshooting
End of Unit 8
Lab: Authentication Services
UNIT 8 – System Monitoring
Objectives
Agenda
Introduction to System Monitoring
File System Analysis
Set User and Ground ID Permissions
Typical Problematic Permissions
EXT2 Filesystem Attributes
System Log Files
Syslogd and klogd configuration
Advanced syslogd configuration
Log File Analysis
Monitoring and Limiting Processes
Processes Monitoring Utilities
System Activity Reporting
Process Accounting Tools
End of Unit
Lab: System Monitoring
UNIT 9 – Security Networks
Objectives
Agenda
Routing Principles
Net filter Overview
Net filter Architecture
Net Filter Tables and Chains
Net filter Packet Flow
Rule matching
Rule Targets
Simple Example
Basic Chain Operations
Directional Filtering
Connection Tracking
Network Address Translation (NAT)
Rule persistence
The “Bastion Host”
End of Unit 10
Lab: Security Networks
UNIT 10 – Securing Services
Objectives
Agenda
System Startup Control
Securing the Service
Tcp-wrappers Configuration
Daemon Specification
Advanced Syntax
Options
Example
Securing xinetd-managed services
Xinetd Access Control
Host Patterns
Advanced security Options
End of Unit 11
Lab: Securing Services
UNIT 11 – Securing Data
Objectives
Agenda
The Need for Encryption
Cryptographic building Blocks
Random Numbers
One-Way Hashes
Symmetric Encryption
Asymmetric Encryption l
Asymmetric Encryption ll
Public Key Infrastructures
Digital Certificates
Generating Digital Certificates
OpenSSH Overview
OpenSSH Authentication
The OpenSSH Server
Service Profile:SSH
OpenSSH Server Configuration
The OpenSSH Client
Protecting Your Keys
Applications: RPM