Lynis Audit

Lynis: security audit
91
Hardening index / 100
Host
srv-monitor
OS
Ubuntu 22.04.4 LTS
Lynis version
Lynis 3.0.9
Last scan
10.10.2026 23:23:48
Warnings
3
Suggestions
5
Tests completed
274
Components
Firewall Malware
Security score
91%
Excellent protection level
Warnings (3)
AUTH-9286

Configure password aging limits in /etc/login.defs

Details
SSH-7408

Consider hardening SSH configuration (AllowTcpForwarding)

Details
KRNL-5820

If not required, consider disabling core dumps

Details
Recommendations (5)
BOOT-5122 Set a password on GRUB boot loader
ACCT-9622 Enable process accounting
HRDN-7220 Consider installing a compiler-hardening toolkit
PKGS-7370 Install debsums utility for verification of packages
NETW-3200 Determine if protocol DCCP is really needed and disable otherwise

Reading a Lynis audit report in a browser

Lynis prints a long, colourful report to the terminal and writes the same thing to /var/log/lynis-report.dat in a format nobody wants to read twice. This page parses that file and shows what the run actually found: the hardening index, the warnings that need attention, and the suggestions with their test IDs so you can look up what each one means.

The hardening index is a score out of 100, and it is worth saying plainly that 100 is not a target. Lynis suggests hardening for every scenario it knows about, including ones that do not apply to your server. A web host that scores in the high seventies with every warning consciously reviewed is in better shape than one that scores ninety by installing packages it does not need.

What moves the number most on a typical VPS: disabling password authentication over SSH, setting up unattended security upgrades, adding a file integrity tool, and tightening kernel parameters through sysctl. Each of those has its own page in this panel.