104 Révisions (bfe6fe84792721fe7c8eda9ba96c3204094e2caa)

Auteur SHA1 Message Date
  fengor b368984641 Added "UseRoaming no" to ssh.config to fix OpenSSH: client bugs CVE-2016-0777 and CVE-2016-0778 il y a 9 ans
  Sebastian Kriems 968abba197 ufw tasks shall have the ufw tag il y a 9 ans
  Sven Neuhaus 20bd80c599 Generate 2048 DH group and add it to Postfix il y a 9 ans
  Dan Milon 34f3a483aa Add SSL stapling cache for apache il y a 9 ans
  Dan Milon a419d9403b restart apache on SSL changes il y a 9 ans
  Dan Milon e063abaa51 properly install changed SSL certificate il y a 9 ans
  Laurent Arnoud dfb1b764d7
Use common_timezone and fix idempotence il y a 9 ans
  Laurent Arnoud a09e2e71c1 tar used in place of unarchive module il y a 10 ans
  Laurent Arnoud 311fae7e11 Trailing whitespace il y a 10 ans
  Laurent Arnoud 3b8f15b745 Added whois for fail2ban report il y a 10 ans
  Will McCutchen 1be1afe1ff Disable SSL stapling on wheezy il y a 10 ans
  Will McCutchen 16b66cc849 Define apache SSL config in one place il y a 10 ans
  Manfred Touron 16c93ea486
Using more verbose 'dependencies' tag (#393) il y a 10 ans
  Manfred Touron b49f3a6586 Tagged 'deps' aptitude tasks il y a 10 ans
  Laurent Arnoud 353e69d299 Remove duplication with items unattended upgrades il y a 10 ans
  Laurent Arnoud 89d47731ff Add molly-guard and unattended-upgrades as common pkgs il y a 10 ans
  Alex Payne b11fb68559 Automatically set up passwordless sudo for deploy user. il y a 10 ans
  Aleksandr Bogdanov a849948e8d Choosing the closest ubuntu mirror before anything else il y a 10 ans
  Sven Neuhaus ae58053653 Create /decrypted directory even if encfs is not used. il y a 10 ans
  Sven Neuhaus d5217ea1cd Create main user without "fuse" group, instead add it later as part il y a 10 ans
  Marius Voila b13ab39f11 cleaning security.yml il y a 10 ans
  fengor 7ed46f590c renamed templates to be consistent with coding standard. il y a 10 ans
  Marius Voila ec69fef60c removed old template il y a 10 ans
  Marius Voila 2ae2c3683c removed template and implemented logic il y a 10 ans
  fengor 2fd1e1b722 readded google authenticator lines il y a 10 ans
  fengor 224e8cb339 Setting timezone to UTC il y a 10 ans
  fengor 39566abb6c More secure defaults for ssh. il y a 10 ans
  Marius Voila 67e1bf0fc3 fail2ban support for Trusty il y a 10 ans
  Marius Voila e62bd7c71a fail2ban support for Trusty il y a 10 ans
  Anthony Perez-sanz cdf9ed07bb Enable UFW after setting firewall rules il y a 10 ans
  Lorenzo Villani 5d1090d488 Make sure fail2ban is started il y a 11 ans
  Lorenzo Villani d5ecf673d3 Calm OCD by sorting almost every with_items block in alphabetical order il y a 11 ans
  Lorenzo Villani e7703d0d9c Add support for Apache 2.4 on Ubuntu 14.04 il y a 11 ans
  Lorenzo Villani e2e61a2f76 Install 'fuse' instead of 'fuse-utils' il y a 11 ans
  Sven Neuhaus 63ba754eb7 libpam-google-authenticator uses distribution package on Ubuntu 14.04 il y a 11 ans
  Gelnior 7995bac36c put back enc.fs (removed by mistake) il y a 11 ans
  Gelnior bd57edd5a5 newebe config: fix Newebe config file task il y a 11 ans
  Justin Plock 1d7986fd96 Enable UFW and deny everything by default il y a 11 ans
  Justin Plock ea0b288818
Moved ufw firewall rules into individual roles il y a 11 ans
  Justin Plock ed75c9469b
libpam-dev didn't exist for some people so switching to libpam0g-dev instead il y a 11 ans
  Justin Plock e88fb57cba
Skip the google authenticator generation if we're running as vagrant. Vagrant can't sudo to the sovereign test user so this won't work. il y a 11 ans
  Justin Plock 2d751ab680
The .google_authenticator file has to be generated by the user that is going to attempt to use it. Also, -W doesn't seem to work (results an in INVALID_WINDOW error in /var/log/auth.log), so use -w 1 to allow for a single concurrent token il y a 11 ans
  Justin Plock c037dce07a
Clarified parameters are bit in a comment il y a 11 ans
  Justin Plock 22a8717f6d
Automatically generate the Google authenticator file for the default user il y a 11 ans
  Justin Plock 84c9febec7
Added Google Authenticator 2FA logins il y a 11 ans
  Justin Plock 89f018bd23
In preparation for using any 2FA solution, it will most likely need to modify sshd_config, so let's change the file in place instead of overwriting it completely. il y a 11 ans
  Justin Plock 9f918363b9
Set a ServerName for apache (fixes #187) il y a 11 ans
  Benjamin Reitzammer d957760697 Making main user's shell configurable il y a 11 ans
  Justin Plock 3b0308d69e Allow both TCP and UDP port 53 for DNS lookups through OpenVPN il y a 11 ans
  Joost Baaij ae2e74bb79 make NTP pool configurable il y a 11 ans