1、安装一些基本的编译库
[root@localhost ~]# yum install gcc gcc-c++ autoconf libjpeg libjpeg-devel libpng libpng-devel freetype freetype-devel libxml2 libxml2-devel zlib zlib-devel glibc glibc-devel glib2 glib2-devel bzip2 bzip2-devel ncurses ncurses-devel cURL cURL-devel e2fsprogs e2fsprogs-devel krb5 krb5-devel libidn libidn-devel openssl openssl-devel
2、设置时间同步
[root@localhost ~]# yum install ntp[root@localhost ~]# vi /etc/crontab*/5 * * * * ntpdate ntp.api.bz &> /dev/null
3、优化最大文件数限制
[root@localhost ~]# vi /etc/security/limits.conf* soft nofile 65535* hard nofile 65535
4、优化TCP/IP内核参数
[root@localhost ~]# > /etc/sysctl.conf[root@localhost ~]# vi /etc/sysctl.confnet.ipv4.ip_forward = 1net.ipv4.conf.default.rp_filter = 1net.ipv4.conf.default.accept_source_route = 0kernel.sysrq = 0kernel.core_uses_pid = 1net.ipv4.tcp_syncookies = 1kernel.msgmnb = 65536kernel.msgmax = 65536kernel.shmmax = 68719476736kernel.shmall = 4294967296net.ipv4.tcp_max_tw_buckets = 6000net.ipv4.tcp_sack = 1net.ipv4.tcp_window_scaling = 1net.ipv4.tcp_rmem = 4096 87380 4194304net.ipv4.tcp_wmem = 4096 16384 4194304net.core.wmem_default = 8388608net.core.rmem_default = 8388608net.core.rmem_max = 16777216net.core.wmem_max = 16777216net.core.netdev_max_backlog = 262144net.core.somaxconn = 262144net.ipv4.tcp_max_orphans = 3276800net.ipv4.tcp_max_syn_backlog = 262144net.ipv4.tcp_timestamps = 0net.ipv4.tcp_synack_retries = 1net.ipv4.tcp_syn_retries = 1net.ipv4.tcp_tw_recycle = 1net.ipv4.tcp_tw_reuse = 1net.ipv4.tcp_mem = 94500000 915000000 927000000net.ipv4.tcp_fin_timeout = 1net.ipv4.tcp_keepalive_time = 1200net.ipv4.ip_local_port_range = 1024 65535[root@localhost ~]# sysctl -p #使配置生效
5、关闭IPv6的支持
[root@localhost ~]# chkconfig ip6tables off[root@localhost ~]# vi /etc/modprobe.d/ipv6.confalias net-pf-10 offalias ipv6 off
6、关闭SELINUX
[root@localhost ~]# vi /etc/sysconfig/selinux......SELINUX=disabled #这里设置为disabled......
7、配置ssh
[root@localhost ~]# vi /etc/ssh/sshd_configPort 65232Protocol 2PermitRootLogin noUseDNS no
8、关闭不需要的服务,除了以下列出的服务,其他的一律关闭
crondirqbalancenetworksshdrsyslogiptables
9、系统用户文件权限设置
chmod 644 /etc/passwdchmod 600 /etc/shadowchmod 644 /etc/groupchmod 600 /etc/gshadow