summaryrefslogtreecommitdiffstats
path: root/roles/common/tasks/main.yml
Commit message (Expand)AuthorAgeFiles
* Disable resume device.Guilhem Moulin2018-12-091
* Don't install the haveged entropy daemon.Guilhem Moulin2018-12-091
* Install unbound on metal hosts.Guilhem Moulin2018-12-031
* Upgrade syntax to Ansible 2.7 (apt module).Guilhem Moulin2018-12-031
* Skip samhain installation.Guilhem Moulin2018-12-031
* Upgrade syntax to Ansible 2.5.Guilhem Moulin2018-04-041
* Upgrade syntax to Ansible 2.4.Guilhem Moulin2017-11-231
* Fix detection of KVM guests.Guilhem Moulin2017-07-291
* Change group of executables in /usr/local/{bin,sbin} from root to staff.Guilhem Moulin2017-05-141
* Route SMTP traffic from the webmail through IPsec.Guilhem Moulin2016-07-101
* Use stunnel to secure the connection from the webmail to ldap.fripost.org.Guilhem Moulin2016-06-051
* Tunnel munin-update traffic through IPSec.Guilhem Moulin2016-05-221
* Set up IPSec tunnels between each pair of hosts.Guilhem Moulin2016-05-221
* Move /etc/ssl/private/dhparams.pem to /etc/ssl/dhparams.pem and make it public.Guilhem Moulin2016-05-181
* Use systemd unit files for stunnel4.Guilhem Moulin2016-05-121
* Upgrade playbooks to Ansible 2.0.Guilhem Moulin2016-02-121
* Only install letsencrypt-tiny to the relevant hosts.Guilhem Moulin2015-12-281
* Use the Let's Encrypt CA for our public certs.Guilhem Moulin2015-12-201
* Change match to "^(Genuine)?Intel.*" for Intel processors.Guilhem Moulin2015-07-121
* Configure munin nodes & master.Guilhem Moulin2015-06-101
* Configure Bacula File Daemon / Storage Daemon / Director.Guilhem Moulin2015-06-071
* Install CAcert.org root certificates.Guilhem Moulin2015-06-071
* logjam mitigation.Guilhem Moulin2015-06-071
* Don't instal smartd on KVM guests.Guilhem Moulin2015-06-071
* Upgrade the common package list.Guilhem Moulin2015-06-071
* Don't install intel-microcode on Xen guests.Guilhem Moulin2015-06-071
* Don't install smartd on Xen guests.Guilhem Moulin2015-06-071
* Install auditd.Guilhem Moulin2015-06-071
* Don't install daemontools.Guilhem Moulin2015-06-071
* Replace IPSec tunnels by app-level ephemeral TLS sessions.Guilhem Moulin2015-06-071
* Make genkeypair.sh able to display TXT record for DKIM signatures.Guilhem Moulin2015-06-071
* Don't require a PKI for IPSec.Guilhem Moulin2015-06-071
* Install haveged.Guilhem Moulin2015-06-071
* Install ClamAV.Guilhem Moulin2015-06-071
* Install common packages.Guilhem Moulin2015-06-071
* Configure S.M.A.R.T.Guilhem Moulin2015-06-071
* Configure NTP.Guilhem Moulin2015-06-071
* Reorganization.Guilhem Moulin2015-06-071
* Common LDAP (slapd) configuration.Guilhem Moulin2015-06-071
* Common MySQL configuration.Guilhem Moulin2015-06-071
* Postfix master (nullmailer) configurationGuilhem Moulin2015-06-071
* Configure the (basic) logging policy.Guilhem Moulin2015-06-071
* Configure IPSec.Guilhem Moulin2015-06-071
* Configure fail2ban.Guilhem Moulin2015-06-071
* Configure rkhunter.Guilhem Moulin2015-06-071
* Configure samhain.Guilhem Moulin2015-06-071
* Configure v4 and v6 iptable rulesets.Guilhem Moulin2015-06-071
* Configure APT.Guilhem Moulin2015-06-071
* Configure /etc/{hosts,hostname,mailname}.Guilhem Moulin2015-06-071
* Basic ansible setup.Guilhem Moulin2015-06-071