Commit Graph

355 Commits

Author SHA1 Message Date
Jack Ivanov
00e4bcc1ec security role and SSH fixes #77 2016-08-26 00:35:07 +03:00
Jack Ivanov
8c5f80bf8f linting 2016-08-25 23:59:16 +03:00
Jack Ivanov
57b6c96ba8 SSH fingerprints #77 2016-08-25 23:48:35 +03:00
Jack Ivanov
0945f54366 SSH user-management #77 2016-08-25 23:30:27 +03:00
Jack Ivanov
c19908c9b1 ssh fixes 2016-08-25 23:03:20 +03:00
Jack Ivanov
cf08c5ff61 fix 2016-08-25 22:20:53 +03:00
Dan Guido
27421070b9 linting 2016-08-24 09:22:04 +02:00
Dan Guido
809b62cd33 daemon_reload is an option for systemd, not service 2016-08-24 09:03:29 +02:00
Jack Ivanov
b29f1ab226 service fixed #78 2016-08-24 10:03:19 +03:00
Dan Guido
2fcc3600fd Disable features in the Match block vs main config 2016-08-23 17:03:27 -04:00
Jack Ivanov
1dcfe18055 SSH tunneling role #77 2016-08-23 16:51:06 +03:00
Jack Ivanov
19797bc020 CPU and memory limitations of the services #63 2016-08-23 16:10:42 +03:00
Evgeniy Ivanov
5ecd23c59c type 2016-08-23 09:01:07 +03:00
Evgeniy Ivanov
468d5af23d service fixes 2016-08-23 09:00:32 +03:00
Defunct
50f43dc601 revert systemd changes (2.2 only), identation normalization; 2016-08-23 02:02:57 +00:00
Evgeniy Ivanov
09c39627d9 Memory limits #63 2016-08-22 23:01:43 +03:00
Evgeniy Ivanov
c51fe5dac0 run charon as non-root user #66 2016-08-21 20:32:31 +03:00
Evgeniy Ivanov
71ad2f570e proxy prompts enabled #70 2016-08-21 19:57:52 +03:00
Evgeniy Ivanov
ba50abce8a make local ip changeable #67 2016-08-21 13:29:53 +03:00
Evgeniy Ivanov
e6090b8245 forwarding #61 2016-08-21 12:51:58 +03:00
Colin Mahns
1fbe1b63f8 HTTPS for domains that support it
hosts-file.net and malwaredomainlist.com has optional TLS, adaway.org forces it server side
2016-08-20 14:48:31 -04:00
Colin Mahns
6c81b86c92 Link to MVPS Hosts file directly
http://www.mvps.org/winhelp2002/hosts.txt redirects to http://winhelp2002.mvps.org/hosts.txt automatically, saves a step
2016-08-20 14:40:33 -04:00
Evgeniy Ivanov
53f60e33d8 random tmp names #64 2016-08-20 17:45:35 +03:00
Evgeniy Ivanov
3864f8104d adblock.sh as an unprivileged user; Store the whitelists in /var/; #64 2016-08-20 17:25:06 +03:00
Evgeniy Ivanov
4b2ae71ffe Tighten the dnsmasq AppArmor policy #62 2016-08-20 16:49:34 +03:00
Evgeniy Ivanov
de06b4fd9e security remarks 2016-08-20 16:24:00 +03:00
Evgeniy Ivanov
b593986b0c SFTP fixed 2016-08-20 16:22:54 +03:00
Evgeniy Ivanov
3fa75a081d new iptabes deployment #61 2016-08-20 16:22:14 +03:00
Evgeniy Ivanov
cfc38e3df1 Drop SMB traffic ##61 2016-08-20 15:19:46 +03:00
Evgeniy Ivanov
4a6602e877 RSAAuthentication no; Turn off SFTP; Turn off X11 forwarding; #51 2016-08-20 14:14:09 +03:00
Evgeniy Ivanov
16627783f5 Minor updates to the sshd_config #51 2016-08-18 21:35:47 +03:00
Evgeniy Ivanov
f3eb06cfe0 server_name fixes 2016-08-18 12:44:34 +03:00
Evgeniy Ivanov
9eaaf63fa0 server_name fixes 2016-08-18 12:36:54 +03:00
Evgeniy Ivanov
f20d375dc9 IP_subject fixes 2016-08-18 12:32:28 +03:00
Evgeniy Ivanov
a9b10baf1d Some fixes 2016-08-18 12:17:46 +03:00
Evgeniy Ivanov
a1bf2ad5ef flush handlers after loopback configured 2016-08-18 11:22:06 +03:00
Evgeniy Ivanov
7085a594fc p12 moved into playbooks 2016-08-18 11:16:22 +03:00
Evgeniy Ivanov
4f46cc221a Split the features role in two #49 2016-08-17 23:26:21 +03:00
Evgeniy Ivanov
95c43e2211 Split the features role in two #49 2016-08-17 23:26:17 +03:00
Dan Guido
2a8c1adb76 Update main.yml 2016-08-16 23:31:20 -04:00
Dan Guido
52855c9e3f Use the right language for GCE 2016-08-16 00:03:26 -04:00
Dan Guido
0fd0de17d4 rename the cloud roles 2016-08-16 00:00:26 -04:00
Dan Guido
f538ffe4e8 linting 2016-08-15 23:32:44 -04:00
jack
7a8d58783f Roles and Google cloud 2016-08-14 20:03:33 +03:00
jack
e729f0d303 Roles and Google cloud 2016-08-14 20:03:23 +03:00
jack
42e6067e4d Firewall | Google Cloud Engine #27 2016-08-14 16:51:24 +03:00
jack
89758aaec9 Google Cloud Engine #27 2016-08-14 16:36:50 +03:00
jack
3870956f0a google and azure 2016-08-14 14:13:23 +03:00
jack
917b7d6138 Modify user-management function 2016-08-11 23:54:29 +03:00
jack
f6c1309aac non-cloud servers #34 2016-08-11 23:40:07 +03:00
jack
2f66b03880 EC2 Role; Loggin Role 2016-08-11 22:36:36 +03:00
jack
fff70293f1 Roles enabled 2016-08-11 11:54:34 +03:00
Dan Guido
e10b1b669f no reason to have roles yet 2016-05-15 11:06:03 -04:00
Dan Guido
041c6da9b0 fix what was here, script runs now 2016-05-15 11:02:13 -04:00
Dan Guido
e8993b06dd initial commit 2016-05-14 23:43:37 -04:00