diff options
| author | Luke Smith <luke@lukesmith.xyz> | 2024-07-16 08:33:25 -0400 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2024-07-16 08:33:25 -0400 |
| commit | 613b27642fa4c5315ae925ec6701a224eec08c39 (patch) | |
| tree | 137b4202e7a362401ed66b9cd85482a4a9a1e642 /content | |
| parent | ed8eda775c17b707576744e81f0738724aa64978 (diff) | |
| parent | b5d7e4b977208d89b4615a8ded2525c97e3ba517 (diff) | |
Merge branch 'master' into m-chrzan/spf
Diffstat (limited to 'content')
| -rw-r--r-- | content/auth.md | 2 | ||||
| -rw-r--r-- | content/basic/nginx.md | 4 | ||||
| -rw-r--r-- | content/calibre.md | 2 | ||||
| -rw-r--r-- | content/cgit.md | 8 | ||||
| -rw-r--r-- | content/dendrite.md | 2 | ||||
| -rw-r--r-- | content/i2p.md | 56 | ||||
| -rw-r--r-- | content/irc.md | 2 | ||||
| -rw-r--r-- | content/mail/inbox.md | 4 | ||||
| -rw-r--r-- | content/mail/rdns.md | 3 | ||||
| -rw-r--r-- | content/mail/smtp.md | 2 | ||||
| -rw-r--r-- | content/mail/validate.md | 2 | ||||
| -rw-r--r-- | content/monerod.md | 25 | ||||
| -rw-r--r-- | content/prosody.md | 14 | ||||
| -rw-r--r-- | content/sshkeys.md | 16 | ||||
| -rw-r--r-- | content/tor.md | 4 | ||||
| -rw-r--r-- | content/wireguard.md | 2 |
16 files changed, 84 insertions, 64 deletions
diff --git a/content/auth.md b/content/auth.md index 88a5fee..b38cb88 100644 --- a/content/auth.md +++ b/content/auth.md @@ -132,5 +132,3 @@ http { Now check your configuration with `nginx -t` Reload nginx and you\'re good to go! - -**Contributor** - [tomfasano.net](https://tomfasano.net) diff --git a/content/basic/nginx.md b/content/basic/nginx.md index db41937..d76fb54 100644 --- a/content/basic/nginx.md +++ b/content/basic/nginx.md @@ -33,7 +33,7 @@ for your password, and you can just copy or type in the password from Vultr\'s site. If you get an error here, you might not have done your [DNS -settings](dns.html) right. Double check those. Note you can also replace +settings](/basic/dns) right. Double check those. Note you can also replace the `example.org` with your IP address, but you\'ll want to fix your DNS settings soon. @@ -199,7 +199,7 @@ someone could exploit it. Open the main Nginx config file Uncomment it, and reload Nginx. Remember to [keep your server software up to -date](maintenance.html#update) to get the latest security fixes! +date](/../maintenance#update) to get the latest security fixes! ## We now have a running website! diff --git a/content/calibre.md b/content/calibre.md index 9768acf..e1e9faa 100644 --- a/content/calibre.md +++ b/content/calibre.md @@ -94,7 +94,7 @@ server { } ``` -Issue a Let\'s Encrypt certificate. [Detailed instructions and additional information](/certbot). +Issue a Let\'s Encrypt certificate. [Detailed instructions and additional information](/basic/certbot). ```sh certbot --nginx diff --git a/content/cgit.md b/content/cgit.md index ce6214c..13d4b2b 100644 --- a/content/cgit.md +++ b/content/cgit.md @@ -53,8 +53,8 @@ server { fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend; fastcgi_param PATH_INFO $uri; fastcgi_param GIT_HTTP_EXPORT_ALL 1; - fastcgi_param GIT_PROJECT_ROOT /srv/git; - fastcgi_param HOME /srv/git; + fastcgi_param GIT_PROJECT_ROOT /var/git; + fastcgi_param HOME /var/git; fastcgi_pass unix:/run/fcgiwrap.socket; } @@ -90,11 +90,11 @@ root-title={{<hl>}}Chad's git server{{</hl>}} root-desc={{<hl>}}A web interface to LandChad's git repositories, powered by Cgit{{</hl>}} # The location where git repos are stored on the server -scan-path=/srv/git/ +scan-path=/var/git/ ``` This configuration assumes you followed the [git hosting guide](/git) -and store your repositories on the `/srv/git/` directory. +and store your repositories on the `/var/git/` directory. Cgit\'s configuration allows changing many settings, as documented on the cgitrc(5) manpage installed with Cgit. diff --git a/content/dendrite.md b/content/dendrite.md index 9a7a291..c949a9d 100644 --- a/content/dendrite.md +++ b/content/dendrite.md @@ -18,7 +18,7 @@ Because Matrix uses **HTTP** for transport over the SSL ports (443 and 8448), yo Depending on your setup, there are 2 different configurations to achieve this: -1. Your *desired* domain (**example.org**) has an [A DNS record](http://localhost:1313/basic/dns/) that already poinst to your desired Matrix server, so you can configure this or add to your existing NGINX static site configuration to setup Matrix. +1. Your *desired* domain (**example.org**) has an [A DNS record](/basic/dns/) that already poinst to your desired Matrix server, so you can configure this or add to your existing NGINX static site configuration to setup Matrix. 2. You wish to use Matrix with your *desired* domain (**example.org**) but this domain's A record points to a different server, accessible through another domain (like **matrix.example.org**). In this case, look into [delegation.](https://matrix-org.github.io/synapse/latest/delegate.html) diff --git a/content/i2p.md b/content/i2p.md index 88b05b4..8dcb7cb 100644 --- a/content/i2p.md +++ b/content/i2p.md @@ -11,28 +11,36 @@ Now you have a website, why not offer it in a private alternative such as the In ## Setting up I2P -There are 2 main I2P implementations, I2P and i2pd, we are using i2pd in this guide because it\'s easier to use in servers. +There are 2 main I2P implementations, I2P and i2pd, we are using i2pd in this guide because it's easier to use on servers. ### Installing I2P -i2pd is in most repos, in debian/ubuntu you can install it simply with +We need to [add the i2pd repos to our system](https://repo.i2pd.xyz/) to get the latest version of i2pd: + +Install apt-transport-https and gpg package: ```sh -apt install i2pd +apt install apt-transport-https gpg ``` -### Enabling I2P +Automatically add the repository with a script: + +```sh +wget -q -O - https://repo.i2pd.xyz/.help/add_repo | bash -s - +``` -We are going to create a user for i2pd, because i2pd finds the configuration files in its home directory. And it\'s easier (and more tidy) to have it in a separate user: +After that you can install i2pd as any other software package: ```sh -useradd -m i2p -s /bin/bash -su -l i2p -mkdir ~/.i2pd -cd ~/.i2pd +apt update +apt install i2pd ``` -Now that you\'re in \~/.i2pd, you have to create a file named \"tunnels.conf\". Which is the config file for every hidden service you\'re offering over I2P, the content should be like this: +### Enabling I2P + +Next we have to configure the i2pd daemon, the configuration is located at `/etc/i2pd/`. + +Edit the `tunnels.conf` file and add the following configuration to the file: ```systemd [example] @@ -42,11 +50,13 @@ port = 8080 keys = example.dat ``` +You can comment or remove the tunnels that are added by default in the configuration file. + #### Optional: Generating a Vanity Address -If you run `i2pd` with the configuration above, it will generate a random private key (`example.dat`) for your website in `example.dat` with a matching address made up of 52 random characters, derived from this same key. +If you run `i2pd` with the configuration above, it will generate a random private key (`example.dat`) for your website at `/var/lib/i2pd/` with a matching address made up of 52 random characters, derived from this same key. -If you instead pre-generate a private key for your website, you can use brute-force computation to make a "vanity" address, such as the following: +If you instead pre-generate a private key for your website, you can use brute-force computation to make a "vanity" address, such as the following: ``` {{<hl>}}chad{{</hl>}}aor3jc08ht340c30mg5cf340j395gj095kuazj5tokipr34f.32.i2p ``` @@ -66,7 +76,7 @@ sh dependencies.sh Then compile using the `make` command: ```sh -make -j$(nproc) +make ``` This will build a variety of useful tools for i2p, with `vain` being the command of interest to generate an address: @@ -76,7 +86,7 @@ This will build a variety of useful tools for i2p, with `vain` being the command This command will begin running and output a new set of private keys named `private.dat` to the same directory it's ran from. Copy this file to your i2p configuration and you'll have your vanity address: ```sh -cp private.dat /home/i2p/.i2pd/example.dat +cp private.dat /var/lib/i2pd/example.dat ``` #### Optional: Authentication Strings for Registrars @@ -91,7 +101,7 @@ The command above will save the string to a file named `auth_string.txt`. You wi ### Getting your I2P Hostname -Then, run `/usr/sbin/i2pd --daemon` to start i2pd and we can retreive our I2P hostname. +Then, run the command `systemctl start i2pd` to start i2pd and `systemctl enable i2pd` to enable i2pd at startup, this will automatically generate our I2P hostname which we will now see. This can be done in lynx or a command-line browser by going to `http://127.0.0.1:7070/?page=i2p_tunnels` to get your I2P hostname. @@ -99,14 +109,14 @@ You can also run these commands to find your hostname: ```sh printf "%s.b32.i2p -" $(head -c 391 /home/i2p/.i2pd/example.dat |sha256sum|xxd -r -p | base32 |sed s/=//g | tr A-Z a-z) +" $(head -c 391 /var/lib/i2pd/example.dat | sha256sum | xxd -r -p | base32 | sed s/=//g | tr A-Z a-z) ``` *(If you've generated your own keys to obtain a vanity address, now's a good time to make sure i2pd is properly reading those keys by verifying the address is the same as the one generated with the `vain` command.)* ## Adding the Nginx Config -From here, the steps are almost identical to setting up a normal websitenconfiguration file. Follow the steps as if you were making a new website on the webserver [tutorial](/basic/nginx) up until the server block of code. Instead, paste this: +From here, the steps are almost identical to setting up a normal website configuration file. Follow the steps as if you were making a new website on the webserver [tutorial](/basic/nginx) up until the server block of code. Instead, paste this: ```nginx server { @@ -118,18 +128,18 @@ server { #### Clarifications -#### - -Nginx will listen in port 8080, but i2pd will forward your port 8080 to the i2p site port 80. This way you don\'t have to deal with server names or anything like that. +Nginx will listen on port 8080, but i2pd will forward your port 8080 to the i2p site port 80. This way you don't have to deal with server names or anything like that. -From here we are almost done, all we have to do is enable the site and reload nginx which is also covered in [the webserver tutorial](nginx.html#enable). +From here we are almost done, all we have to do is enable the site and reload nginx which is also covered in [the webserver tutorial](/basic/nginx#enable). ### Update regularly! Make sure to update I2P on a regular basis by running: ```sh -apt update && apt install i2pd +apt update && apt upgrade ``` -**Contributor** - [qorg11](https://qorg11.net) +**Contributors** +- [qorg11](https://qorg11.net) +- [David Uhden](https://github.com/daviduhden) diff --git a/content/irc.md b/content/irc.md index ccf16e8..71abd09 100644 --- a/content/irc.md +++ b/content/irc.md @@ -534,7 +534,7 @@ persistent: # connection information for MySQL (currently only used for persistent history): mysql: - enabled: false + enabled: true host: "localhost" port: 3306 # if socket-path is set, it will be used instead of host:port diff --git a/content/mail/inbox.md b/content/mail/inbox.md index a975bd0..3f70b9c 100644 --- a/content/mail/inbox.md +++ b/content/mail/inbox.md @@ -114,10 +114,10 @@ service auth { } protocol lda { - mail_plugins = \$mail_plugins sieve + mail_plugins = $mail_plugins sieve } protocol lmtp { - mail_plugins = \$mail_plugins sieve + mail_plugins = $mail_plugins sieve } plugin { sieve = ~/.dovecot.sieve diff --git a/content/mail/rdns.md b/content/mail/rdns.md index 9ef700c..85cce0f 100644 --- a/content/mail/rdns.md +++ b/content/mail/rdns.md @@ -3,7 +3,8 @@ title: "Setup rDNS" tags: ['mail'] date: 2022-12-02 --- -While [DNS records](../../basic/dns) refer a domain name to the IP address + +While [DNS records](/basic/dns) refer a domain name to the IP address where the the website is hosted, there is also rDNS (reverse DNS) and specifically PTR (pointer) records which do the reverse: link a server\'s IP to a domain name. diff --git a/content/mail/smtp.md b/content/mail/smtp.md index dee5640..3def765 100644 --- a/content/mail/smtp.md +++ b/content/mail/smtp.md @@ -25,7 +25,7 @@ If you want to start an email server, therefore, go to your VPS\'s site and open a ticket or make a request to open up email ports, notably port `25`. This is a simple process that requires nothing too special. One of the wagies at your VPS will kindly do the needful and open your ports for you. Note -that this is not the same as unblocking a port with [ufw](ufw.html), +that this is not the same as unblocking a port with [ufw](/../ufw), which still needs to be done for SMTP to work. ufw allow 25,587 proto tcp diff --git a/content/mail/validate.md b/content/mail/validate.md index 833ae13..8447409 100644 --- a/content/mail/validate.md +++ b/content/mail/validate.md @@ -170,7 +170,7 @@ You can permanently change your hostname by changing it in `/etc/hostname` and rebooting, or you can just run `hostname example.org` to change it temporarily for testing. Either way, this will allow us to run the `mail` command as in [the SMTP -article](smtp.html). +article](../smtp). ```sh echo "Hi there. diff --git a/content/monerod.md b/content/monerod.md index 5e00645..19afba0 100644 --- a/content/monerod.md +++ b/content/monerod.md @@ -31,6 +31,8 @@ tar -xvjf linux64 mv linux64/monero* /usr/bin/ ``` +If the hardware you are using is not based on the amd64 architecture (like a Raspberry Pi), the monero project also [offers binaries](https://www.getmonero.org/downloads/) for other architectures on Linux, to download and install them simply change the last part of the link (linux64) and the archive name, e.g. for arm64 (linuxarm8). The fastest way to find out which one to use in Debian is with the `dpkg --print-architecture` command. + ## Configuration By default, Monero comes with no sample configuration files. Create one in `/etc/monerod.conf` using a text editor, and enter the following details: @@ -45,6 +47,9 @@ data-dir={{<hl>}}/var/lib/monero{{</hl>}} log-file={{<hl>}}/var/log/monero/monero.log{{</hl>}} log-level=0 +# Slow but reliable db writes +db-sync-mode=safe + # 1048576 kB/s == 1GB/s; a raise from default 2048 kB/s; contribute more to p2p network limit-rate-up=1048576 limit-rate-down=1048576 @@ -122,9 +127,9 @@ Edit `/etc/tor/torrc` and add the following: HiddenServiceDir /var/lib/tor/monerod # For wallets connecting over RPC: -HiddenServicePort 18081 127.0.0.1:18081 +HiddenServicePort 18081 127.0.0.1:18181 # For other nodes: -HiddenServicePort 18083 127.0.0.1:18083 +HiddenServicePort 18083 127.0.0.1:18183 ``` Now restart Tor: @@ -139,19 +144,19 @@ cat /var/lib/tor/monerod/hostname ### I2P -Edit `tunnels.conf` (Which may be located in `/home/i2p/.i2pd/` if you followed [this](/i2p) guide) and add the following tunnels: +Edit `tunnels.conf` (Which may be located in `/etc/i2pd/` if you followed [this](/i2p) guide) and add the following tunnels: ```systemd [monerod] type = http host = 127.0.0.1 -port = 18083 +port = 18283 keys = monerod.dat [monerod-rpc] type = http host = 127.0.0.1 -port = 18081 +port = 18281 keys = monerod-rpc.dat ``` @@ -171,13 +176,13 @@ printf "%s.b32.i2p Then, in `/etc/monerod.conf`, add the following: ```sh -# I2P config -tx-proxy=i2p,127.0.0.1:4447 -anonymous-inbound={{<hl>}}your-i2p-address-here.b32.i2p{{</hl>}}:80,127.0.0.1:18083,16 # Maximum 16 simultaneous connections - # Tor config tx-proxy=tor,127.0.0.1:9050,10 -anonymous-inbound={{<hl>}}your-tor-address-here.onion{{</hl>}}:18083,127.0.0.1:18083,16 +anonymous-inbound={{<hl>}}your-tor-address-here.onion{{</hl>}}:18083,127.0.0.1:18183,16 + +# I2P config +tx-proxy=i2p,127.0.0.1:4447 +anonymous-inbound={{<hl>}}your-i2p-address-here.b32.i2p{{</hl>}}:80,127.0.0.1:18283,16 # Maximum 16 simultaneous connections ``` ## Running the Node diff --git a/content/prosody.md b/content/prosody.md index 94fb548..df18ad3 100644 --- a/content/prosody.md +++ b/content/prosody.md @@ -87,13 +87,7 @@ With this we can bring XMPP to the level of other popular instant messaging appl It is extremely easy to setup. This part is optional, but it can make XMPP more normie-friendly if you plan on moving family members and friends over to XMPP. -First we need to install extra prosody modules. Run the following command: - -```sh -apt install prosody-modules -``` - -Then we can add the following line to you prosody config file to enable file uploads: +Add the following line to your prosody config file to enable file uploads: ```cfg Component "{{<hl>}}uploads.example.org{{</hl>}}" "http_file_share" @@ -107,7 +101,7 @@ This helps with file transfers for devices behind a NAT, and unless you are usin Enable the proxy by adding the following line to the config: ```cfg -Component " {{<hl>}}proxy.example.org{{</hl>}}" "proxy65" +Component "{{<hl>}}proxy.example.org{{</hl>}}" "proxy65" ``` As you can see, another subdomain is needed. We will add ssl certificates for this later. @@ -117,7 +111,7 @@ At this point, file sharing is now setup and ready to be used. Although there ar A big concern with file sharing is large files, seeing as all files shared over XMPP will be stored on your server. This can become a problem when many (and large) files are being shared. We can put a cap on large files by adding the following line to our config: ```cfg -http_file_share_file_size_limit = 20971520 +http_file_share_size_limit = 20971520 ``` This puts a 20MB cap on all files being shared. The value is specified in bytes. You can also specify after how long files should be deleted by adding the following line: @@ -134,7 +128,7 @@ Prosody includes the `internal` and `sql` storage backends by default. If you wish to run Prosody with PostgreSQL, begin by installing the PostgreSQL: ```sh -apt install postgresql +apt install postgresql lua-dbi-postgresql ``` Then start the daemon: diff --git a/content/sshkeys.md b/content/sshkeys.md index f1c8c0d..7c39413 100644 --- a/content/sshkeys.md +++ b/content/sshkeys.md @@ -123,6 +123,22 @@ Once we\'ve done that, we will reload our SSH daemon: systemctl reload sshd ``` +### **Warning:** + +It is possible that your ssh configuration +will be overridden by the default configuration added when creating +the VPS, which will leave you vulnerable to brute force attacks. To +prevent this, remove the configuration file using the following +command: + +```sh +rm /etc/ssh/sshd_config/50-cloud-init.conf +``` + +Also verify that the `/etc/ssh/ssh_config.d/` path is empty. If not, +make sure that the configuration files in that folder are not +overriding yours. + ### We\'re done! Now you can log in quickly and password-less-ly to your server, despite diff --git a/content/tor.md b/content/tor.md index a0acdf8..b1c827d 100644 --- a/content/tor.md +++ b/content/tor.md @@ -87,7 +87,7 @@ mirror. Now we are almost done, all we have to do is enable the site and reload nginx which, is also covered in [the webserver -tutorial](nginx.html#enable). +tutorial](/basic/nginx#enable). ### Advertise your onion service @@ -115,5 +115,3 @@ Make sure to update Tor on a regular basis by running: You do **<u>not</u>** need to run certbot for an ssl certificate. HTTP over tor is plenty secure! - -**Contributor** - [tomfasano.net](https://tomfasano.net) diff --git a/content/wireguard.md b/content/wireguard.md index 3e7d571..c0d1879 100644 --- a/content/wireguard.md +++ b/content/wireguard.md @@ -171,5 +171,3 @@ Start WireGuard again: sudo wg-quick up myvpn To disconnect, type `down` instead of `up`. And just like that, you now host a WireGuard VPN server! - -**Contributor** - [tomfasano.net](https://tomfasano.net) |
