summaryrefslogtreecommitdiffstats
path: root/roles
Commit message (Expand)AuthorAgeFiles
...
* wwsympa: allow write access to /var/spool/sympa.Guilhem Moulin2017-05-141
* MSA: reject null sender address.Guilhem Moulin2017-05-144
* IMAP: new script list-users.Guilhem Moulin2017-05-142
* Fix Ansible 2.2.0 compatibility of a Jinja2 template.Guilhem Moulin2017-01-141
* Allow SMTP client from whitelisted IPs to bypass postscreen checks.Guilhem Moulin2017-01-141
* nginx: set Referrer-Policy HTTP header to "no-referrer".Guilhem Moulin2016-12-131
* nginx: add support for HTTP/2.Guilhem Moulin2016-12-135
* dovecot: Deduplicate attachments hourly, just before automatic backup.Guilhem Moulin2016-12-111
* dovecot: use Single-Instance Storage for mail attachments.Guilhem Moulin2016-12-104
* More logcheck-database tweaks.Guilhem Moulin2016-12-081
* wiki: Add instruction for how to add the post-update hook.Guilhem Moulin2016-12-081
* Dovecot: Explicitly disable LDAP.Guilhem Moulin2016-12-081
* gitolite: allow hook.* git config keys.Guilhem Moulin2016-12-081
* Upgrade to lacme 0.2-1.Guilhem Moulin2016-12-082
* Webmail: Install XCache (PHP opcode cacher).Guilhem Moulin2016-12-081
* Dovecot: use fallocate(2) to preallocate new mdbox files.Guilhem Moulin2016-12-081
* Postscreen: Give temporary whitelist status to primary MX addresses only.Guilhem Moulin2016-09-201
* systemd: Ensure sympa service is enabled.Guilhem Moulin2016-09-181
* lacme-certs.conf: don't restart but reload dovecot after renewing IMAPS cert.Guilhem Moulin2016-09-181
* Postfix: ensure common aliases are present.Guilhem Moulin2016-09-183
* FreshClam: change ownership of /etc/clamav/freshclam.conf.Guilhem Moulin2016-09-181
* Firewall: allow duplicates rules.Guilhem Moulin2016-09-181
* More logcheck-database tweaks.Guilhem Moulin2016-08-222
* HSTS: use the standard capitalization of includeSubDomains.Guilhem Moulin2016-07-121
* postfix: Remove obsolete templates tls_policy/relay_clientcerts.Guilhem Moulin2016-07-124
* postfix: commit the master.cf symlinks.Guilhem Moulin2016-07-125
* nginx: Don't hard-code the HPKP headers.Guilhem Moulin2016-07-1213
* Postfix lists/MDA instances: only include the MX:es' IPs in $mynetworks.Guilhem Moulin2016-07-102
* Route all internal SMTP traffic through IPsec.Guilhem Moulin2016-07-1013
* Postfix MX/MSA instances: put certs in the the instance's $config_directory.Guilhem Moulin2016-07-105
* Postfix MX/MSA instances: don't ask the remote SMTP client for a client certi...Guilhem Moulin2016-07-102
* Postfix: avoid hardcoding the instance names.Guilhem Moulin2016-07-102
* Postfix: don't share the master.cf between the instances.Guilhem Moulin2016-07-1012
* postfix: Don't explicitly set inet_interfaces=all as it's the default.Guilhem Moulin2016-07-105
* Change the pubkey extension from .pem to .pub.Guilhem Moulin2016-07-107
* Route SMTP traffic from the webmail through IPsec.Guilhem Moulin2016-07-108
* More logcheck-database tweaks.Guilhem Moulin2016-07-092
* Localize the NTP pool hostnames.Guilhem Moulin2016-07-091
* Localize the debian archive hostnames.Guilhem Moulin2016-07-091
* ClamAV (FreshClam): use a localized Database Mirror.Guilhem Moulin2016-07-092
* IMAP: don't include mailbox under the virtual namespace in LIST responses.Guilhem Moulin2016-07-062
* dovecot: use the MSA postfix instance for sieve redirection.Guilhem Moulin2016-07-012
* IPSec → IPsecGuilhem Moulin2016-06-295
* More logcheck-database tweaks.Guilhem Moulin2016-06-293
* update-firewall.sh: COMMIT empty iptables rule files.Guilhem Moulin2016-06-291
* Postfix MSA: don't allow unauthenticated clients from $mynetworks.Guilhem Moulin2016-06-291
* certs/public: fetch each cert's pubkey (SPKI), not the cert itself.Guilhem Moulin2016-06-157
* Rename letsencrypt-tiny to lacme.Guilhem Moulin2016-06-157
* wwsympa systemd service file: Set PrivateTmp=yes.Guilhem Moulin2016-06-071
* clamav: Don't set obsolete option 'AllowSupplementaryGroups'.Guilhem Moulin2016-06-051