AlmaLinux is often a control-panel server
A plain AlmaLinux server behaves like the rest of the RHEL family: authentication goes to /var/log/secure, the SSH service is sshd, updates come through dnf, and firewalld and SELinux are on after a standard installation. A large share of AlmaLinux servers are not plain, though. They run a hosting control panel, and the panel replaces several of those assumptions. cPanel's own system requirements list AlmaLinux 8, 9 and 10 among the operating systems it installs on, and no longer list Rocky Linux.
On a cPanel server the firewall is usually CSF rather than firewalld, mail is Exim, every website writes its own access log, certificates live in the panel's directories, and backups are the panel's own job. A tool that only knows the operating system misses most of what happens on such a server. SecAI recognises cPanel, Plesk and DirectAdmin and reads each from the panel's own files.
- Per-site web logs, so an attack is attributed to the website it hit rather than to the server as a whole.
- The panel's login and action logs, so a brute-force attempt against the panel itself is seen, not only one against SSH.
- The certificates the web server is configured to serve, read from the panel's layout, compared with what visitors actually receive.
- Whether Exim will relay mail for anybody, read from its own configuration, never by sending a test message.
- The panel's own record of its backups: whether a job exists, how the last run ended, and whether archives are still being written.
CSF, firewalld, and where a block lands
SecAI does not install a firewall and does not replace the one a panel manages. When an address has to be blocked for attacking SSH, the agent tries the tools in a fixed order, fail2ban, CrowdSec, CSF, firewalld and then iptables, and uses the first one the server actually runs. On a cPanel server with CSF, the block is a temporary CSF deny entry for 24 hours, labelled SecAI with the reason, that you can see and remove in CSF itself.
The safety rules are the same everywhere: an address is blocked after three sightings within thirty minutes, the block applies to that server only and expires after 24 hours, and your own address and any address you mark as trusted are never blocked. On a shared hosting server this matters more than usual, because the person locked out by a careless block is a paying customer.
ALSA advisories and AlmaLinux's own builds
AlmaLinux publishes its security fixes as ALSA advisories and ships advisory metadata with its repositories, so "sudo dnf check-update --security" and dnf-automatic's security-only mode work as they do on the rest of the family.
Since 2023 AlmaLinux aims to be compatible with Red Hat Enterprise Linux at the level of the application binary interface rather than reproducing it build for build. In practice the two are close, but AlmaLinux can publish a fix on its own schedule: on 1 July 2024 it shipped its fix for the OpenSSH vulnerability CVE-2024-6387 without waiting for the upstream update. It means the authority on whether an AlmaLinux package is fixed is AlmaLinux's advisory, not Red Hat's. SecAI matches the rpm inventory against OSV.dev's AlmaLinux data for your major release, where each advisory lists every affected binary package with the AlmaLinux build that fixes it, so the fixed version named in a finding is one you can actually install.
Builds are compared with rpm's own ordering, including the epoch. Package inventories usually omit the epoch, and read literally that makes a patched package look older than its fix. SecAI reads a missing epoch as the fix's own when both builds carry the same Enterprise Linux release tag, and otherwise leaves the finding standing. It would rather keep a finding open that could have been closed than close one on a guess.
Updates and reboots
The agent reads pending updates with "dnf check-update", once for everything and once with --security, and reports both counts with up to twenty package names. It changes nothing and installs nothing. Whether a reboot is pending comes from "needs-restarting -r", which belongs to the yum-utils package; without that package the flag cannot be read and shows as not pending.
Two defaults are worth checking on a new AlmaLinux server. AlmaLinux builds its official GenericCloud image with the firewall disabled, so a cloud server may start with no host firewall; and the systemd journal is kept in memory by default, so it is lost at every reboot while the text logs written by rsyslog survive.
On a panel server, remember that the panel updates itself and much of its software outside dnf. SecAI reports end-of-life PHP versions separately for that reason: a server can be fully up to date according to dnf and still run websites on a PHP release that no longer receives security fixes.
What is watched on an AlmaLinux server
- Authentication from /var/log/secure: SSH failures, successes after failures or from a new source, root logins, and which registered administrator key opened a session.
- Accounts and privilege: the account files, sudoers and /etc/sudoers.d, authorized_keys, setuid binaries, and the PAM stack in /etc/pam.d/system-auth and password-auth.
- Persistence: /etc/crontab, /etc/cron.d, user crontabs in /var/spool/cron, where panels keep each hosting account's jobs, and units under /etc/systemd/system, with the text of each change.
- Web roots, including /home/*/public_html: web shell candidates, screened before anything is proposed, and file changes.
- Packages: the rpm inventory matched against ALSA advisories, pending updates, and end-of-life PHP.
- Network: new outbound destinations, floods and connection exhaustion, and an open mail relay or DNS resolver.
Installing on AlmaLinux
One command, as root. The agent is a single static binary for x86_64 with no kernel module, and it does not need or conflict with a control panel. It needs systemd and the base tools already on the server.
SecAI supports current AlmaLinux releases, which today means 9 and 10. The installer verifies the agent's Ed25519 signature before it installs anything, using an OpenSSL command that exists from OpenSSL 3.0; AlmaLinux 8 ships OpenSSL 1.1.1, so the installer stops there rather than install a binary it could not verify.