<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/roles/common/files/usr, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>Send internal system mails to root@f.o.</title>
<updated>2025-09-10T13:14:45+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2025-09-10T13:14:45+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=4b48f1b6dd799d1a69f0c9e2a157a007fcdcbe25'/>
<id>4b48f1b6dd799d1a69f0c9e2a157a007fcdcbe25</id>
<content type='text'>
Instead of admin@f.o. Per msgid=&lt;ad724342-b3bb-48d9-9984-6d277714910d@fripost.org&gt;.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Instead of admin@f.o. Per msgid=&lt;ad724342-b3bb-48d9-9984-6d277714910d@fripost.org&gt;.
</pre>
</div>
</content>
</entry>
<entry>
<title>LDAP: Rotate soon-to-be expired key material.</title>
<updated>2024-09-08T18:54:00+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2024-09-08T18:30:20+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=6b7ad809bbefc32216bac22547241ed402a570c8'/>
<id>6b7ad809bbefc32216bac22547241ed402a570c8</id>
<content type='text'>
Also, switch from rsa4096 to ed25519 and use a separate key for each
syncrepl.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Also, switch from rsa4096 to ed25519 and use a separate key for each
syncrepl.
</pre>
</div>
</content>
</entry>
<entry>
<title>Port baseline to Debian 11 (codename Bullseye).</title>
<updated>2022-10-13T20:12:05+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2022-10-11T23:43:23+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=85347041a04d17f6803100dd2cec9b489c9db47d'/>
<id>85347041a04d17f6803100dd2cec9b489c9db47d</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade baseline to Debian 10.</title>
<updated>2020-05-16T03:45:59+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-05-16T00:52:55+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=bac7811d2b35252b7a83a45d75bb344b4b1776a9'/>
<id>bac7811d2b35252b7a83a45d75bb344b4b1776a9</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Convert firewall to nftables.</title>
<updated>2020-01-23T04:57:01+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-01-23T03:29:12+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=7641a5d5d152db349082b1d0ec93a40888b2ef8e'/>
<id>7641a5d5d152db349082b1d0ec93a40888b2ef8e</id>
<content type='text'>
Debian Buster uses the nftables framework by default.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Debian Buster uses the nftables framework by default.
</pre>
</div>
</content>
</entry>
<entry>
<title>firewall: gracefully close invalid connections.</title>
<updated>2018-12-22T12:22:43+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-20T01:04:25+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=fc337924c7e66258319c6b6d538660240cfeda5e'/>
<id>fc337924c7e66258319c6b6d538660240cfeda5e</id>
<content type='text'>
This is useful when an ESTABLISHED connection is seen as NEW because the
client was offline for some time.  For instance, clients now gracefully
close existing SSH connections immediately after resuming from a suspend
state, rather that waiting for the TCP timeout.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This is useful when an ESTABLISHED connection is seen as NEW because the
client was offline for some time.  For instance, clients now gracefully
close existing SSH connections immediately after resuming from a suspend
state, rather that waiting for the TCP timeout.
</pre>
</div>
</content>
</entry>
<entry>
<title>Firewall: REJECT outgoing connections instead of DROPing them.</title>
<updated>2018-12-09T19:25:39+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-08T00:05:28+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=bccbd0d4c0faf46e911284e599cc22da2c9b04d9'/>
<id>bccbd0d4c0faf46e911284e599cc22da2c9b04d9</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>DKIM: also include the "d=" tag in key filenames, not only the "s=" tag.</title>
<updated>2018-12-05T15:24:12+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-05T14:47:34+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=9722d50b9b6c5ccd81892a00bdd3023399b004fb'/>
<id>9722d50b9b6c5ccd81892a00bdd3023399b004fb</id>
<content type='text'>
While the combination of "s=" tag (selector) &amp; "d=" tag signing domain
maps to a unique key, the selector alone doesn't necessarily.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
While the combination of "s=" tag (selector) &amp; "d=" tag signing domain
maps to a unique key, the selector alone doesn't necessarily.
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade baseline to Debian Stretch.</title>
<updated>2018-12-03T02:43:36+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-03T02:04:22+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2495327985da791891b579bd05b3cda1f41dfda7'/>
<id>2495327985da791891b579bd05b3cda1f41dfda7</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Firewall: allow duplicates rules.</title>
<updated>2016-09-18T15:51:28+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-09-18T15:51:28+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=e0274134445a99c2fab01928b180e2a3d4f9be69'/>
<id>e0274134445a99c2fab01928b180e2a3d4f9be69</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
