<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/roles/common-web/files/etc/nginx/snippets, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>Nginx: Drop OCSP stapling directives.</title>
<updated>2025-08-06T11:51:50+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2025-08-06T11:51:50+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=983981b8546d9ef847cfef7711c35c6e06549f43'/>
<id>983981b8546d9ef847cfef7711c35c6e06549f43</id>
<content type='text'>
Let's Encrypt removed OCSP URLs from certificates on 2025-05-07, see
https://letsencrypt.org/2024/12/05/ending-ocsp .
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Let's Encrypt removed OCSP URLs from certificates on 2025-05-07, see
https://letsencrypt.org/2024/12/05/ending-ocsp .
</pre>
</div>
</content>
</entry>
<entry>
<title>nginx: Update trusted certificate used for OCSP stapling.</title>
<updated>2020-12-05T14:52:10+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-12-05T14:50:33+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=07218fc1e6caf4299dd453744d6e9e53854f75ab'/>
<id>07218fc1e6caf4299dd453744d6e9e53854f75ab</id>
<content type='text'>
See https://bugs.debian.org/975862 .
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
See https://bugs.debian.org/975862 .
</pre>
</div>
</content>
</entry>
<entry>
<title>common-web: Remove snippets/acme-challenge.conf.</title>
<updated>2020-05-16T21:53:35+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-16T21:49:20+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2d30ef24b25d145b0fa827b7b458583996a04760'/>
<id>2d30ef24b25d145b0fa827b7b458583996a04760</id>
<content type='text'>
lacme now ships that file as /etc/lacme/nginx.conf.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
lacme now ships that file as /etc/lacme/nginx.conf.
</pre>
</div>
</content>
</entry>
<entry>
<title>Nextcloud: use dedicated user and PHP FPM pool.</title>
<updated>2020-05-15T23:30:44+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-15T22:52:10+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=e43ef0c7b9490ece68af38f8a658ad8a710e4e37'/>
<id>e43ef0c7b9490ece68af38f8a658ad8a710e4e37</id>
<content type='text'>
There is a real security gain in not using the 'www-data' user: nginx
workers can't read Nextcloud config files and data directory, so should
our nginx configuration be insecure a leak is much less likely.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
There is a real security gain in not using the 'www-data' user: nginx
workers can't read Nextcloud config files and data directory, so should
our nginx configuration be insecure a leak is much less likely.
</pre>
</div>
</content>
</entry>
<entry>
<title>role/common-web: Upgrade baseline to Debian 10.</title>
<updated>2020-05-15T22:51:30+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-15T22:51:30+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=e250173c23a9c192dc18ba34115f94816846ccf3'/>
<id>e250173c23a9c192dc18ba34115f94816846ccf3</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade baseline to Debian Stretch.</title>
<updated>2018-12-03T02:43:36+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-03T02:04:22+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2495327985da791891b579bd05b3cda1f41dfda7'/>
<id>2495327985da791891b579bd05b3cda1f41dfda7</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>nginx: set Referrer-Policy HTTP header to "no-referrer".</title>
<updated>2016-12-13T19:36:38+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-12-13T19:36:38+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=63b76b4deee43d586ee741415d03f5962e5fafc8'/>
<id>63b76b4deee43d586ee741415d03f5962e5fafc8</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>HSTS: use the standard capitalization of includeSubDomains.</title>
<updated>2016-07-12T15:27:24+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-07-12T15:27:24+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=e8cdae5ccc1aba3dc1e9991cce2942fdf93cabcb'/>
<id>e8cdae5ccc1aba3dc1e9991cce2942fdf93cabcb</id>
<content type='text'>
Cf. RFC 6797 sec. 6.1.2.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Cf. RFC 6797 sec. 6.1.2.
</pre>
</div>
</content>
</entry>
<entry>
<title>Rename letsencrypt-tiny to lacme.</title>
<updated>2016-06-15T16:00:57+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-06-15T16:00:57+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=97e78349145156ca6565ee5b2af54983a6fdd3a6'/>
<id>97e78349145156ca6565ee5b2af54983a6fdd3a6</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Move /etc/ssl/private/dhparams.pem to /etc/ssl/dhparams.pem and make it public.</title>
<updated>2016-05-18T15:55:44+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-18T15:55:40+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=cda53ea254de51eb46cb0f53f7d33b9a0f794bfc'/>
<id>cda53ea254de51eb46cb0f53f7d33b9a0f794bfc</id>
<content type='text'>
Ideally we we should also increase the Diffie-Hellman group size from
2048-bit to 3072-bit, as per ENISA 2014 report.

    https://www.enisa.europa.eu/publications/algorithms-key-size-and-parameters-report-2014

But we postpone that for now until we are reasonably certain that older
client won't be left out.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Ideally we we should also increase the Diffie-Hellman group size from
2048-bit to 3072-bit, as per ENISA 2014 report.

    https://www.enisa.europa.eu/publications/algorithms-key-size-and-parameters-report-2014

But we postpone that for now until we are reasonably certain that older
client won't be left out.
</pre>
</div>
</content>
</entry>
</feed>
