diff options
| author | Guilhem Moulin <guilhem@fripost.org> | 2020-01-23 05:33:17 +0100 | 
|---|---|---|
| committer | Guilhem Moulin <guilhem@fripost.org> | 2020-01-25 01:57:05 +0100 | 
| commit | ee4e9e9836ad05279647b04eb1e8a3a4b0e16568 (patch) | |
| tree | d4e566a7b535f7d62e4fd6fd1a521ea6d7563d21 /roles/common-web/files/etc/nginx/sites-available | |
| parent | 7641a5d5d152db349082b1d0ec93a40888b2ef8e (diff) | |
Improve/harden fail2ban configuration.
 * Use nftables sets with a timeout
 * Start daemon with a hardened unit file and restricted Capability
   Bounding Set.  (This requires to change the log path to
   /var/log/fail2ban/*.)
 * Skip database as we don't care about persistence.
 * Refactor jail.local
Diffstat (limited to 'roles/common-web/files/etc/nginx/sites-available')
0 files changed, 0 insertions, 0 deletions
