End-User Configs
The following controls are excluded from hardened Linux images. Applicability varies by image type. VM images typically require bootloader and SSH configuration, while container images may require runtime-level security settings.
Configure these controls based on your environment and security policies.
On this page:
Virtual machine images
-
CIS 1.4.1: Set Boot Loader Password in
grub2GRUB2 should have a superuser account and password to prevent unauthorized changes to boot settings. This is left to end-user configuration because the password is a credential unique to your environment, a preset value in a shared image would be the same across all deployments, defeating the control.
-
CIS 5.1.6: Limit user access
SSH by default allows any local account to log in. Restrict access using AllowUsers/AllowGroups (whitelist) or DenyUsers/DenyGroups (blacklist) in sshd_config (space-separated names, optionally user@host; no numeric UIDs/GIDs). This is left to end-user configuration because valid users/groups are environment-specific and usually don't exist until after deployment.
-
CIS 6.2.1.2.3: Enable
systemd-journal-uploadServicesystemd-journal-upload forwards logs to a remote host, preserving audit trails even if an attacker gets local root, and enables cross-system correlation for detecting distributed attacks. This is left to end-user configuration because it requires your specific log-collection endpoint and credentials, which aren't known at image-build time.