This is a guide to set up a modern XMPP server focused on security and mobile messaging. The whole guide assumes Debian stable running on the server, the fact that you will end up hosting a few of your friends and that you have some basic skills working on a linux command line. Please note that if you’ve followed this guide in the past you might need to have a look at the update considerations
Wir haben eine Reihe von ASAs im Einsatz, die auf Kundenwunsch gepflegt werden. Wie immer betreffen Änderungswünsche nur die Einrichtung von Freischaltungen, aber nie das Wegräumen von Altlasten. Für diesen Fall gibt es zwei Tools, die ich vorstellen möchte.
- mkacl-from-asaconfig.pl
- clean-asa-config.pl
RANCID monitors a router's (or more generally a device's) configuration, including software and hardware (cards, serial numbers, etc) and uses CVS (Concurrent Version System) or Subversion to maintain history of changes.
RANCID does this by the very simple process summarized as:
- login to each device in the router table (router.db),
- run various commands to get the information that will be saved,
- cook the output; re-format, remove oscillating or incrementing data,
- email any differences (sample) from the previous collection to a mail list,
- and finally commit those changes to the revision control system
This site lets you create a muttrc configuration file for the Mutt email program. You specify your preferences in the boxes on the next few pages, and you get a muttrc you can use.
None of the data you enter is stored permanently, but as the Internet is not secure, you should not enter any sensitive information such as passwords. Enter a placeholder instead (such as "password goes here" and replace it in the file you download.
The idea is based on netliberte's sadly-defunct muttrc builder.
etcd is a distributed, consistent key value store for shared configuration and service discovery with a focus on being:
Simple: curl'able user facing API (HTTP+JSON)
Secure: optional SSL client cert authentication
Fast: benchmarked 1000s of writes/s per instance
Reliable: properly distributed using Raft
etcd is written in Go and uses the Raft consensus algorithm to manage a highly-available replicated log.
See etcdctl for a simple command line client. Or feel free to just use curl, as in the examples below.
If you're considering etcd for production use, please see: production-ready.md
The following configuration reads the Windows EventLog and sends it to the Graylog2 server in GELF format.
duraconf - A collection of hardened configuration files for SSL/TLS services
http://www.appelbaum.net/
Hier gibt es ein paar Hinweise, wie man seine openssh-Konfiguration zunagelt. Ich persönlich habe ja für meine Server jeweils in ~/.ssh/config sowas stehen wie:...
You may have heard that the NSA can decrypt SSH at least some of the time. If you have not, then read the latest batch of Snowden documents now. All of it. This post will still be here when you finish. My goal with this post here is to make NSA analysts sad.
TL;DR: Scan this post for fixed width fonts, these will be the config file snippets and commands you have to use.
This article does not contain a complete list of all preferences. If you don't find an entry below for a given preference, check the Category:Preferences (multiple-page) listing, which includes many new preferences that have not been added here, as well as those preferences that have been migrated from sections of this article. Also check Mail and news settings for a listing of Thunderbird and Mozilla Suite/SeaMonkey mail and news preferences.