Overview
Amazon Linux 2023 hardened AMI for security-conscious EC2 workloads. CoreNova Hardened AMI helps DevSecOps and platform teams launch instances quickly without building SSH, firewall, logging, and update baselines from scratch.
Save setup time Subscribe in AWS Marketplace, launch with your EC2 key pair, and connect as ec2-user. Root SSH and password login are disabled. Typical use cases: bastion hosts, application servers, security-sensitive workloads, and compliance-oriented lab environments.
What's included
- SSH hardening: PermitRootLogin no, PasswordAuthentication no, key-only access, modern cipher suites
- firewalld: SSH (22/tcp) allowed by default; add application ports as needed
- auditd, rsyslog, and chrony enabled at boot
- AIDE integrity database initialized at build time
- Automatic security updates via dnf-automatic
Built for transparency
- Reproducible Packer-based build pipeline
- CIS-oriented OpenSCAP scan workflow (buyer retains final compliance responsibility)
- SemVer product versions with changelog
Pricing and trial
- Usage-based software pricing: $0.03/hour (Apply to all instance types; EC2 infrastructure billed separately)
- 14-day free trial on software fee
Getting started
- Subscribe in AWS Marketplace
- Launch with your key pair and security group (allow SSH from your admin CIDR-not 0.0.0.0/0 in production)
- Verify: systemctl is-active auditd firewalld chronyd rsyslog
- Verify SSH: sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication'
Important This product provides CIS-oriented hardening and OpenSCAP scan workflows. It does not constitute official CIS certification. Final compliance decisions remain with the buyer and their auditors.
Seller: CoreNova Intelligence Limited (CoreNova) Support: CoreNovaLabs@aipalnet.cn | https://aipalnet.cn
Highlights
- Amazon Linux 2023 pre-hardened in minutes-14-day free trial on software fee. SSH, firewalld, auditd, AIDE, and auto security updates already applied.
- SSH hardened out of the box: PermitRootLogin no, PasswordAuthentication no, key-only access with modern cipher suites.
- Transparent Packer build plus CIS-oriented OpenSCAP scan workflow-documented hardening, not a black-box image.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
t3.small Recommended | $0.03 |
t3.micro | $0.03 |
t3a.medium | $0.03 |
t3.medium | $0.03 |
m5.xlarge | $0.03 |
m6i.large | $0.03 |
t3.large | $0.03 |
t3a.large | $0.03 |
t3.xlarge | $0.03 |
m5.large | $0.03 |
Vendor refund policy
30-day refund on AWS Marketplace software fees for this product. Email CoreNovaLabs@aipalnet.cn with your AWS account ID and purchase date. Software fees only; EC2 charges are not refundable by the seller. We reply within 5 business days. Free trial: no software charges during the trial.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial release of CoreNova Hardened AMI for Amazon Linux 2023.
Includes: SSH hardening (no root, key-only), firewalld (SSH allowed), auditd, rsyslog, chrony, AIDE init, dnf-automatic security updates.
AMI ID (us-east-1): ami-09c3b381d6344b549
Additional details
Usage instructions
- Subscribe to this product in AWS Marketplace, then Launch instance in us-east-1.
- Choose an EC2 key pair (password login is disabled).
- Security group: allow inbound TCP 22 from your admin IP only.
- Connect: ssh -i your-key.pem ec2-user@<instance-public-ip>
- Verify: systemctl is-active auditd chronyd rsyslog firewalld sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication' Expected: permitrootlogin no; passwordauthentication no.
Support
Vendor support
Email: CoreNovaLabs@aipalnet.cn Web: https://aipalnet.cn Refund: 30-day software-fee refunds per AWS Marketplace Standard Contract (SCMP) Support hours: Email, business days (5x8). Include instance ID, AWS region, AMI ID, product version, and steps to reproduce.
Support scope: Documentation and guidance for launching and verifying this AMI (SSH access, baseline services, firewall). We do not provide 24/7 managed operations or application-level support unless separately agreed.
When contacting support, include: AWS region, AMI ID, instance ID, and a description of the issue with relevant logs.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products




