Commit Graph

5346 Commits

Author SHA1 Message Date
Bob Mottram 6c904ee967 We don't really need to backup mailpile 2017-08-09 23:30:36 +01:00
Bob Mottram 364b57a3d9 Turn off magic sysrq 2017-08-09 17:46:09 +01:00
Bob Mottram 850d5628a8 Don't panic! 2017-08-09 17:34:44 +01:00
Bob Mottram 46b37c96c1 Manual hash check after verify 2017-08-09 11:29:56 +01:00
Bob Mottram 659e49c477 Check a given hash against the tripwire database 2017-08-09 11:27:13 +01:00
Bob Mottram adef1bb88f Turn off ssl in dovecot when using mailpile 2017-08-08 21:18:52 +01:00
Bob Mottram acebf591bc Mailpile user permissions 2017-08-08 21:16:07 +01:00
Bob Mottram d93167fa60 Bump mailpile commit 2017-08-08 20:21:34 +01:00
Bob Mottram 2325be1f58 Nextcloud upgrade command 2017-08-08 19:24:47 +01:00
Bob Mottram 963d382d22 bump nextcloud commit 2017-08-08 18:59:28 +01:00
Bob Mottram 4efb04dce5 Additional tripwire rules 2017-08-08 13:26:39 +01:00
Bob Mottram 32d89e951f Fix nextcloud leak of version information
This could be of obvious use to adversaries
2017-08-08 11:05:25 +01:00
Bob Mottram 70813b5a65 Setting prosody group 2017-08-07 21:40:19 +01:00
Bob Mottram 5096ba9cc1 Tidying 2017-08-07 21:29:31 +01:00
Bob Mottram 68bbd5e693 Updating gpg keys 2017-08-07 19:04:16 +01:00
Bob Mottram 99d88d8792 Don't update certs on upgrade 2017-08-07 18:45:39 +01:00
Bob Mottram d3b3bd1d9b Try without the pep dance 2017-08-07 18:15:36 +01:00
Bob Mottram c80feb6768 Only update logindefs when needed 2017-08-07 17:31:37 +01:00
Bob Mottram 51de0ff9b3 grep string 2017-08-07 15:17:41 +01:00
Bob Mottram ee6925eeb6 Test for predictable device names 2017-08-07 14:46:08 +01:00
Bob Mottram 90dc589eb9 Removing of bluetooth kernel module 2017-08-07 14:18:59 +01:00
Bob Mottram 8c5aaeddc0 fail2ban isn't useful when logging is turned off most of the time 2017-08-07 13:56:25 +01:00
Bob Mottram fb811406e9 Include utils in logging command
So that functions can be called by logging app routines
2017-08-07 13:42:05 +01:00
Bob Mottram a59a84a0a3 kanboard logging functions 2017-08-07 13:32:16 +01:00
Bob Mottram 22557c6359 Don't repeatedly try to install amd64 kernel 2017-08-07 13:16:47 +01:00
Bob Mottram 0ee00f775c Ownership of ghost binary 2017-08-07 10:51:21 +01:00
Bob Mottram b654846c86 Fix typo 2017-08-06 21:21:51 +01:00
Bob Mottram db322c02d3 keyserver database gets cleaned up anyway via the daily sks script 2017-08-06 21:07:02 +01:00
Bob Mottram bb64427344 Reverse logic 2017-08-06 17:12:03 +01:00
Bob Mottram 66f784ed55 Only change xmpp config if needed 2017-08-06 14:34:48 +01:00
Bob Mottram 5950438ced Fix account required 2017-08-06 13:50:52 +01:00
Bob Mottram 267851bd89 Only alter fstab if needed 2017-08-06 12:50:31 +01:00
Bob Mottram 42754613df xmpp logging conditions 2017-08-05 23:30:38 +01:00
Bob Mottram c8de324376 Only change login umask when needed 2017-08-05 23:16:37 +01:00
Bob Mottram f7f323b763 Only change pam values when needed 2017-08-05 23:13:28 +01:00
Bob Mottram c1650ae415 Only update limits when needed 2017-08-05 23:07:31 +01:00
Bob Mottram 7e24becb9c Only disable ctrl-alt-del once 2017-08-05 23:00:46 +01:00
Bob Mottram 259e061dcf Turing rsyslog on or off 2017-08-05 22:23:52 +01:00
Bob Mottram bd86c4b19a Only remove motd instructions once 2017-08-05 22:15:32 +01:00
Bob Mottram c713c613c9 Don't repeatedly config congestion control 2017-08-05 22:11:02 +01:00
Bob Mottram bbcc17f2d1 Only copy files which have changed 2017-08-05 21:16:37 +01:00
Bob Mottram f703a95971 Only copy stig tests script if it changes 2017-08-05 20:41:21 +01:00
Bob Mottram 9cf9388131 Indicate permissions lockdown 2017-08-05 20:24:46 +01:00
Bob Mottram 50867e7770 Clear before lockdown 2017-08-05 20:22:45 +01:00
Bob Mottram 1b6782f12a Remove clears 2017-08-05 20:21:14 +01:00
Bob Mottram a15759e394 Lockdown before tripwire reset 2017-08-05 20:13:11 +01:00
Bob Mottram db091e1d72 Only update files when they change 2017-08-05 20:08:57 +01:00
Bob Mottram 7586c716d4 Only copy cleanup script if it has changed 2017-08-05 18:01:56 +01:00
Bob Mottram 6122296b59 Only copy email archiving script if it has changed 2017-08-05 17:55:02 +01:00
Bob Mottram 5914a8c190 Check inadyn commit 2017-08-05 17:48:08 +01:00
Bob Mottram 8aec3e3da3 Tripwire ignores global node modules 2017-08-05 17:25:27 +01:00
Bob Mottram 6e57b1b33b Don't lockdown on upgrade 2017-08-05 16:59:13 +01:00
Bob Mottram b432410716 Fixing tripwire policy 2017-08-05 16:13:43 +01:00
Bob Mottram b7f63f6ff1 Directory name 2017-08-05 14:27:41 +01:00
Bob Mottram cd96dc6fd7 No routing 2017-08-05 14:21:35 +01:00
Bob Mottram 8f1df8243d tripwire exclusions to avoid triggering on routine updates 2017-08-05 14:10:44 +01:00
Bob Mottram 61d555737e Don't show tripwire code if database file doesn't exist 2017-08-05 13:32:34 +01:00
Bob Mottram d9adff3a9e Option to verify the tripwire code 2017-08-05 13:30:58 +01:00
Bob Mottram 99479d6448 Stray tld 2017-08-05 13:19:16 +01:00
Bob Mottram 31e7b8d619 tripwire qr code verification 2017-08-05 13:15:35 +01:00
Bob Mottram f2c17eddd5 Message at the end of tripwire reset 2017-08-05 11:33:13 +01:00
Bob Mottram 0485e73a7d More comprehensive tripwire reset 2017-08-05 11:26:24 +01:00
Bob Mottram 07942a701b End of fixes message 2017-08-05 10:07:33 +01:00
Bob Mottram 75d6de301b Menu option to fix stig test failures 2017-08-05 10:00:34 +01:00
Bob Mottram 80be052424 Don't try to fix stig failures because this triggers the tripwire 2017-08-05 09:56:13 +01:00
Bob Mottram 26b80c868f Don't need this if email is configured properly 2017-08-04 23:50:58 +01:00
Bob Mottram 1d3e165d2d Don't need daily sks script because an equivalent one is already installed by the debian package 2017-08-04 23:34:42 +01:00
Bob Mottram cc922b3b56 Support different languages for mutt spell checking 2017-08-04 21:41:40 +01:00
Bob Mottram 19c99e8d5a Emacs spell checking 2017-08-04 21:04:19 +01:00
Bob Mottram 144fae7bae tripwire check 2017-08-04 18:28:43 +01:00
Bob Mottram 23f541964e Add tripwire check as a cron job 2017-08-04 18:12:01 +01:00
Bob Mottram 4bf48b5801 Reset tripwire 2017-08-03 21:32:18 +01:00
Bob Mottram da30734ba9 Stop ghost before updating 2017-08-01 09:49:42 +01:00
Bob Mottram 14afd04473 cryptpad 1.12.0 2017-08-01 09:38:27 +01:00
Bob Mottram ac22ebb9b8 Remove links to feedly from ghost blog 2017-07-31 14:50:32 +01:00
Bob Mottram 9dd54f5c32 facepalm 2017-07-31 12:50:50 +01:00
Bob Mottram 6897652c86 keyserver buffer size limit 2017-07-31 12:39:20 +01:00
Bob Mottram 9b6be8dce3 Data limits on keyserver web interface 2017-07-31 12:34:11 +01:00
Bob Mottram a361727da6 Clear out keyserver logs more frequently and make sure that sks daemon is stopped when clearing 2017-07-31 11:53:03 +01:00
Bob Mottram 4398c8b976 Don't need sks repo 2017-07-31 10:23:00 +01:00
Bob Mottram f396203257 Fix ghost 2017-07-30 22:08:47 +01:00
Bob Mottram 11b01bfe25 Also upgrade ghost-cli 2017-07-30 18:32:20 +01:00
Bob Mottram 81be48d180 Enable sks after restore 2017-07-30 16:55:53 +01:00
Bob Mottram 43a44a1186 Watchdog to disable keyserver if the database becomes too large 2017-07-30 16:38:49 +01:00
Bob Mottram 4cdef1e0b4 Remove keyserver key 2017-07-30 16:15:17 +01:00
Bob Mottram 0607a26ea8 Remove any keyserver log files during upgrades 2017-07-30 14:29:10 +01:00
Bob Mottram 9ce7e29174 Remove keyserver log files before backup 2017-07-30 14:27:15 +01:00
Bob Mottram a03db43778 keyserver debug level 2017-07-30 14:10:05 +01:00
Bob Mottram efa7548513 log diffs setting 2017-07-30 14:01:58 +01:00
Bob Mottram 6a85df523b More keyserver checks 2017-07-30 13:15:33 +01:00
Bob Mottram 496667d47d Complain about malformed email addresses 2017-07-30 12:52:43 +01:00
Bob Mottram 006d355377 Extra email check 2017-07-30 12:48:41 +01:00
Bob Mottram d81cea2fe9 Include optional mailsync address when adding other keyserver 2017-07-30 12:45:51 +01:00
Bob Mottram efe6c6f315 Backup and restore sks config files 2017-07-30 12:19:52 +01:00
Bob Mottram 972e9b463b Extra keyserver settings 2017-07-30 12:02:27 +01:00
Bob Mottram 0bbfd412b5 Don't backup infeasibly large keyserver databases 2017-07-30 11:08:30 +01:00
Bob Mottram fe024046ec Backup and restore for keyserver 2017-07-30 10:34:44 +01:00
Bob Mottram 5122bdbc48 keyserver active on port 80
Without this commandline interaction doesn't work
2017-07-29 22:44:45 +01:00
Bob Mottram 342b1fc328 Fixing keyserver 2017-07-29 21:28:24 +01:00
Bob Mottram 8c12c0f195 Edit keyserver sync servers 2017-07-29 15:37:42 +01:00
Bob Mottram 8b39a6d211 Add sync keyservers 2017-07-29 15:19:29 +01:00
Bob Mottram 4b9cf813cd Duplicate port 2017-07-28 23:34:40 +01:00
Bob Mottram 8f280c82e0 keyserver listening ports 2017-07-28 23:14:12 +01:00
Bob Mottram 3a75c54d24 Show sks keyserver onion address on about screen 2017-07-28 23:03:31 +01:00
Bob Mottram dfe18fb802 Keep track of sks onion domain 2017-07-28 22:57:40 +01:00
Bob Mottram 73397491f5 Onion servive for keyserver 2017-07-28 22:52:38 +01:00
Bob Mottram 3714095c0d Firewall for keyserver 2017-07-28 22:46:36 +01:00
Bob Mottram 62da06d236 typo 2017-07-28 22:03:12 +01:00
Bob Mottram d2af928664 Change name on keyserver 2017-07-28 22:01:35 +01:00
Bob Mottram 79cfba462d Download keyserver dump using date
Because downloading the full data will likely take longer than a day
2017-07-28 21:39:29 +01:00
Bob Mottram 79b5bd818e Simplify keyserver install 2017-07-28 21:06:46 +01:00
Bob Mottram ad4b4c61fd Check directories 2017-07-28 20:16:20 +01:00
Bob Mottram e7e69d4877 Add dialog asking to continue with download 2017-07-28 20:02:25 +01:00
Bob Mottram 18ad18de7d Move database import to interactive 2017-07-28 19:57:21 +01:00
Bob Mottram 19f431b7b5 No mariadb restart needed 2017-07-28 15:27:14 +01:00
Bob Mottram 810e346f69 Set directories for search 2017-07-28 15:17:49 +01:00
Bob Mottram 3609e4c952 Upgrade ghost install to 1.x type 2017-07-28 14:51:24 +01:00
Bob Mottram 74cb0c0493 Some extra packages for ghost 2017-07-28 11:42:21 +01:00
Bob Mottram 01e5748db7 Bump ghost version 2017-07-28 11:28:08 +01:00
Bob Mottram 388a4c8885 Backup the database and content subdirectory for ghost 2017-07-28 11:17:47 +01:00
Bob Mottram 14efdb6a2f keyserver 2017-07-27 21:54:08 +01:00
Bob Mottram d9d93b18a7 sks keyserver app 2017-07-27 21:51:12 +01:00
Bob Mottram 29bae785aa Upgrade sequence 2017-07-27 14:57:26 +01:00
Bob Mottram b7720972cd Needs bower install 2017-07-27 14:50:12 +01:00
Bob Mottram 7a496ecb40 Install after cryptpad upgrade 2017-07-27 14:41:14 +01:00
Bob Mottram 04bc4393f0 Bump cryptpad commit 2017-07-27 14:35:30 +01:00
Bob Mottram dd04199b4a Install composer 2017-07-25 22:11:03 +01:00
Bob Mottram dc4f99a740 Dialog proportions 2017-07-25 21:51:48 +01:00
Bob Mottram 59455534ad No background image 2017-07-25 21:46:13 +01:00
Bob Mottram ae396b0e63 code index 2017-07-25 21:42:08 +01:00
Bob Mottram 21d1f73df6 kanboard app 2017-07-25 21:39:27 +01:00
Bob Mottram f748e4ebcc Don't set profanity gpg key by default so that screen refresh bug doesn't happen 2017-07-25 10:44:21 +01:00
Bob Mottram ed5e451b82 Update profanity commits 2017-07-25 10:16:19 +01:00
Bob Mottram 812f5de7f2 Beginning of wekan 2017-07-25 10:13:58 +01:00
Bob Mottram c63b3abe8b Switch to BBR congestion control 2017-07-22 18:31:11 +01:00
Bob Mottram cbcdc4dd40 Adding users to the blocklist 2017-07-20 22:43:18 +01:00
Bob Mottram df3df89fa8 Riot filename changed 2017-07-20 15:35:24 +01:00
Bob Mottram 47ff7bda86 Update riot version 2017-07-20 15:32:27 +01:00
Bob Mottram 6e535f2eab Upgrading GS/pA 2017-07-18 13:15:24 +01:00
Bob Mottram 2cee73ca8e flash bbb wireless kernel 2017-07-17 15:30:09 +01:00
Bob Mottram 28211221ba Package not needed 2017-07-17 14:51:21 +01:00
Bob Mottram 745ee6019e Hotspot setup for bbb wireless 2017-07-17 14:17:13 +01:00
Bob Mottram a6c6841a13 Permissions on profile 2017-07-15 17:33:02 +01:00
Bob Mottram d551818ff0 Support 256 colours in the terminal 2017-07-15 17:27:52 +01:00
Bob Mottram aa87b5c188 Add next year archive after previous one 2017-07-15 14:54:53 +01:00
Bob Mottram 59f018b336 Set site key filename 2017-07-15 11:37:41 +01:00
Bob Mottram a752130127 Checks when resetting tripwire 2017-07-15 11:25:57 +01:00
Bob Mottram 9741890691 stig test for tripwire database 2017-07-15 11:10:40 +01:00
Bob Mottram 054c452d71 Not using aide
Check for tripwire cron entry instead
2017-07-15 10:30:02 +01:00
Bob Mottram f3d6fc59f2 Braces 2017-07-14 23:42:04 +01:00