Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@arne" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>arne</span></a></span> I can recommend <a href="https://infosec.space/tags/Canonical" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Canonical</span></a>'s documentation re: <a href="https://infosec.space/tags/UbuntuLTS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UbuntuLTS</span></a>...</p><ul><li>I recommend <em>"<a href="https://infosec.space/tags/ConfigirationByException" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConfigirationByException</span></a>"</em> as good distros are hardened from the get-go.</li></ul><p>Maybe just do <a href="https://infosec.space/tags/Pubkey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Pubkey</span></a>-based <a href="https://infosec.space/tags/SSH" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SSH</span></a> auth and/or <a href="https://infosec.space/tags/Fail2Ban" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fail2Ban</span></a> for anyone failing 3 logins or not being inside the <em>"Managment LAN"</em>...</p>