summaryrefslogtreecommitdiffstats
path: root/roles
Commit message (Expand)AuthorAgeFiles
* firewall: gracefully close invalid connections.Guilhem Moulin2018-12-221
* fail2ban: Only install the roundcube/dovecot filters if needed.Guilhem Moulin2018-12-151
* submission: Prospective SPF checking.Guilhem Moulin2018-12-125
* Outgoing SMTP: masquerade internal hostnames.Guilhem Moulin2018-12-123
* IMAP: raise per user maximum number of inotify instances from 128 to 512.Guilhem Moulin2018-12-121
* IPsec: use Suite-B-GCM-256 algorithms for IKEv2 & ESP.Guilhem Moulin2018-12-091
* MSA verification probes: enable opportunistic encryption.Guilhem Moulin2018-12-092
* Use mariadb.service not mysql.service.Guilhem Moulin2018-12-092
* Update 'IMAP', 'MSA' and 'LDAP-provider' roles to Debian Stretch.Guilhem Moulin2018-12-0924
* Disable resume device.Guilhem Moulin2018-12-093
* IMAP: Ensure /home/mail is mounted before creating sub-directories.Guilhem Moulin2018-12-091
* bacula-sd: Ensure /mnt/backup is mounted before creating sub-directories.Guilhem Moulin2018-12-091
* bacula: Backup MySQL database for the nextcloud host.Guilhem Moulin2018-12-092
* systemd.service: Tighten hardening options.Guilhem Moulin2018-12-099
* bacula-*.service: Don't fork in the background.Guilhem Moulin2018-12-093
* Upgrade 'lists' role to Debian Stretch.Guilhem Moulin2018-12-098
* Firewall: disable outgoing access to git:// remote servers.Guilhem Moulin2018-12-091
* systemd: Replace ‘ProtectSystem=full’ with ‘ProtectSystem=strict’.Guilhem Moulin2018-12-099
* Firewall: REJECT outgoing connections instead of DROPing them.Guilhem Moulin2018-12-091
* Upgrade 'out' role to Debian Stretch.Guilhem Moulin2018-12-091
* Don't install the haveged entropy daemon.Guilhem Moulin2018-12-092
* ntp.conf: reduce delta with the packaged version.Guilhem Moulin2018-12-091
* MX: chroot postscreen(8), smtpd(8) and cleanup(8) daemons.Guilhem Moulin2018-12-098
* MX: don't override 5XY reject codes to 554.Guilhem Moulin2018-12-091
* postfix: remove explicit default 'mail_owner = postfix'.Guilhem Moulin2018-12-066
* postfix ≥3.0: don't advertise SMTPUTF8 support.Guilhem Moulin2018-12-061
* Upgrade 'ikiwiki-pandoc' to v0.5.1.Guilhem Moulin2018-12-061
* Roundcube: improve serving of static resources.Guilhem Moulin2018-12-061
* DKIM: also include the "d=" tag in key filenames, not only the "s=" tag.Guilhem Moulin2018-12-053
* Upgrade DKIM keys to rsa2048, and allow for multiple keys.Guilhem Moulin2018-12-043
* Install unbound on metal hosts.Guilhem Moulin2018-12-034
* Define new host "calima" serving Nextcloud.Guilhem Moulin2018-12-039
* Upgrade wiki baseline to Debian Stretch.Guilhem Moulin2018-12-034
* Upgrade MX baseline to Debian Stretch.Guilhem Moulin2018-12-031
* Upgrade webmail baseline to Debian Stretch.Guilhem Moulin2018-12-036
* Upgrade syntax to Ansible 2.7 (apt module).Guilhem Moulin2018-12-0325
* Postfix: replace cdb & btree tables with lmdb ones.Guilhem Moulin2018-12-0314
* IPsec: allow ISAKMP over IPv6.Guilhem Moulin2018-12-032
* Upgrade baseline to Debian Stretch.Guilhem Moulin2018-12-0323
* Skip samhain installation.Guilhem Moulin2018-12-034
* Harden anti spam on the MX:es.Guilhem Moulin2018-06-095
* More logcheck-database tweaks.Guilhem Moulin2018-04-043
* lacme: explicitely bind to [::]:80.Guilhem Moulin2018-04-041
* Postfix: replace 'fifo' types with 'unix', as it's the new default.Guilhem Moulin2018-04-041
* sympa: wibbleGuilhem Moulin2018-04-042
* Firewall: Allow DNS queries over TCP.Guilhem Moulin2018-04-041
* APT: use deb.debian.org as archive source.Guilhem Moulin2018-04-041
* Postscreen: improve DNSBL sites and scores.Guilhem Moulin2018-04-041
* Amavis: bind server to INADDR_LOOPBACKGuilhem Moulin2018-04-041
* Perform recipient address verification on the MSA itself.Guilhem Moulin2018-04-044