<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/roles/MSA/files/etc, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>postfix: Adjust anonymize_sender.pcre.</title>
<updated>2022-10-11T12:02:34+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2022-10-11T12:02:31+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=bcff69a1a65808d705a3abc4a730adca8a58a6b1'/>
<id>bcff69a1a65808d705a3abc4a730adca8a58a6b1</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>postfix-sender-login: Better hardening.</title>
<updated>2020-05-21T01:40:53+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-20T13:46:27+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=6d1daa0424c168eae4bfa9f6772add3f77ec506f'/>
<id>6d1daa0424c168eae4bfa9f6772add3f77ec506f</id>
<content type='text'>
Run as a dedicated user, not ‘postfix’.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Run as a dedicated user, not ‘postfix’.
</pre>
</div>
</content>
</entry>
<entry>
<title>MSA: Update role to Debian Buster.</title>
<updated>2020-05-19T04:36:36+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-19T04:06:17+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=82e6b29ad39bfaee2d4036f98d1362ab8e689006'/>
<id>82e6b29ad39bfaee2d4036f98d1362ab8e689006</id>
<content type='text'>
For `ssl_cipher_list` we pick the suggested value from
https://ssl-config.mozilla.org/#server=postfix&amp;version=3.4.10&amp;config=intermediate&amp;openssl=1.1.1d

At the moment it's equivalent (modulo order) to adding ‘EDH+AESGCM+aRSA’
to ‘EECDH+AESGCM:EECDH+CHACHA20!MEDIUM!LOW!EXP!aNULL!eNULL’.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
For `ssl_cipher_list` we pick the suggested value from
https://ssl-config.mozilla.org/#server=postfix&amp;version=3.4.10&amp;config=intermediate&amp;openssl=1.1.1d

At the moment it's equivalent (modulo order) to adding ‘EDH+AESGCM+aRSA’
to ‘EECDH+AESGCM:EECDH+CHACHA20!MEDIUM!LOW!EXP!aNULL!eNULL’.
</pre>
</div>
</content>
</entry>
<entry>
<title>systemd.service: Tighten hardening options.</title>
<updated>2018-12-09T19:25:40+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-09T17:15:10+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2147ff3bd9091b88960e2243b2d7d76d03cadc89'/>
<id>2147ff3bd9091b88960e2243b2d7d76d03cadc89</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>systemd: Replace ‘ProtectSystem=full’ with ‘ProtectSystem=strict’.</title>
<updated>2018-12-09T19:25:39+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-08T00:06:06+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=6a57ea01fd48992883d6dac1b7746e79202215e4'/>
<id>6a57ea01fd48992883d6dac1b7746e79202215e4</id>
<content type='text'>
And remove ‘ReadOnlyDirectories=/’ as it's implied by ‘ProtectSystem=strict’.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
And remove ‘ReadOnlyDirectories=/’ as it's implied by ‘ProtectSystem=strict’.
</pre>
</div>
</content>
</entry>
<entry>
<title>postfix-msa: anonymize SASL-authenticated senders using IPv6.</title>
<updated>2017-06-06T11:32:45+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2017-06-06T11:32:45+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=4c60cd07f1c5295d3611601db3c658f0eadfad87'/>
<id>4c60cd07f1c5295d3611601db3c658f0eadfad87</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>move postfix-sender-login.{service,socket} to files/.</title>
<updated>2017-06-02T12:12:32+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2017-06-02T12:12:26+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=1395cc86969823d9972517833c614becba8660a0'/>
<id>1395cc86969823d9972517833c614becba8660a0</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>MSA: reject null sender address.</title>
<updated>2017-05-14T13:02:46+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2017-05-14T13:02:21+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=c55ae1e2a93b1debd8df3ef944c2ddc91055c423'/>
<id>c55ae1e2a93b1debd8df3ef944c2ddc91055c423</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Configure the Mail Submission Agent.</title>
<updated>2015-06-07T00:51:10+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2013-12-02T22:39:26+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=1a50ad8f85ae7b42d7749b43d8f01adb663114ff'/>
<id>1a50ad8f85ae7b42d7749b43d8f01adb663114ff</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
