<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/roles/common/files/etc/systemd/system, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>Improve Debian 11's fail2ban rules.</title>
<updated>2022-12-18T12:29:34+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2022-12-14T11:01:33+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=7ea3baad594b889f6f7f4e7e4ccc4dc7c0099bc6'/>
<id>7ea3baad594b889f6f7f4e7e4ccc4dc7c0099bc6</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Port baseline to Debian 11 (codename Bullseye).</title>
<updated>2022-10-13T20:12:05+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2022-10-11T23:43:23+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=85347041a04d17f6803100dd2cec9b489c9db47d'/>
<id>85347041a04d17f6803100dd2cec9b489c9db47d</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Bacula: refactor systemd service files.</title>
<updated>2020-11-03T02:37:11+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-11-03T02:15:10+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=ead9aaa3dd7ca48012b2b21cc930ee73c8eaa9d3'/>
<id>ead9aaa3dd7ca48012b2b21cc930ee73c8eaa9d3</id>
<content type='text'>
Use unit overrides on top of upstream's service files instead of
overriding entire service files.  In particular, upstream uses flag `-P`
so we don't need to use RuntimeDirectory= anymore.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Use unit overrides on top of upstream's service files instead of
overriding entire service files.  In particular, upstream uses flag `-P`
so we don't need to use RuntimeDirectory= anymore.
</pre>
</div>
</content>
</entry>
<entry>
<title>stunnel4: Harden and socket-activate.</title>
<updated>2020-05-18T13:51:54+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-18T13:51:54+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=42df93debccbcb1a18cd377b6de0b5b20527312f'/>
<id>42df93debccbcb1a18cd377b6de0b5b20527312f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade baseline to Debian 10.</title>
<updated>2020-05-16T03:45:59+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-16T00:52:55+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=bac7811d2b35252b7a83a45d75bb344b4b1776a9'/>
<id>bac7811d2b35252b7a83a45d75bb344b4b1776a9</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Improve/harden fail2ban configuration.</title>
<updated>2020-01-25T00:57:05+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-01-23T04:33:17+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=ee4e9e9836ad05279647b04eb1e8a3a4b0e16568'/>
<id>ee4e9e9836ad05279647b04eb1e8a3a4b0e16568</id>
<content type='text'>
 * Use nftables sets with a timeout
 * Start daemon with a hardened unit file and restricted Capability
   Bounding Set.  (This requires to change the log path to
   /var/log/fail2ban/*.)
 * Skip database as we don't care about persistence.
 * Refactor jail.local
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
 * Use nftables sets with a timeout
 * Start daemon with a hardened unit file and restricted Capability
   Bounding Set.  (This requires to change the log path to
   /var/log/fail2ban/*.)
 * Skip database as we don't care about persistence.
 * Refactor jail.local
</pre>
</div>
</content>
</entry>
<entry>
<title>systemd.service: Tighten hardening options.</title>
<updated>2018-12-09T19:25:40+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-09T17:15:10+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2147ff3bd9091b88960e2243b2d7d76d03cadc89'/>
<id>2147ff3bd9091b88960e2243b2d7d76d03cadc89</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bacula-*.service: Don't fork in the background.</title>
<updated>2018-12-09T19:25:39+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-09T17:12:39+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2845af5f76ad3be9c0a1f69ab478ff5a08346a4c'/>
<id>2845af5f76ad3be9c0a1f69ab478ff5a08346a4c</id>
<content type='text'>
Inspired from /lib/systemd/system/bacula-fd.service.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Inspired from /lib/systemd/system/bacula-fd.service.
</pre>
</div>
</content>
</entry>
<entry>
<title>systemd: Replace ‘ProtectSystem=full’ with ‘ProtectSystem=strict’.</title>
<updated>2018-12-09T19:25:39+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-08T00:06:06+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=6a57ea01fd48992883d6dac1b7746e79202215e4'/>
<id>6a57ea01fd48992883d6dac1b7746e79202215e4</id>
<content type='text'>
And remove ‘ReadOnlyDirectories=/’ as it's implied by ‘ProtectSystem=strict’.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
And remove ‘ReadOnlyDirectories=/’ as it's implied by ‘ProtectSystem=strict’.
</pre>
</div>
</content>
</entry>
<entry>
<title>/lib/systemd/system → /etc/systemd/system</title>
<updated>2017-05-31T15:39:57+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2017-05-31T15:39:57+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=e136d3edbdb6749d4559939dc9fcbc11d166e34c'/>
<id>e136d3edbdb6749d4559939dc9fcbc11d166e34c</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
