From b12633fa2680743d28a78c05beed686b5ca45047 Mon Sep 17 00:00:00 2001 From: Denshi Date: Fri, 19 May 2023 20:21:42 +0400 Subject: Added http_file_share in Prosody and added vanity address and auth string tutorial in I2P article --- content/ejabberd.md | 5 ++++ content/i2p.md | 82 +++++++++++++++++++++++++++++++++++++---------------- content/prosody.md | 52 ++++++++++++++++++++------------- 3 files changed, 96 insertions(+), 43 deletions(-) (limited to 'content') diff --git a/content/ejabberd.md b/content/ejabberd.md index c725465..eff3b36 100644 --- a/content/ejabberd.md +++ b/content/ejabberd.md @@ -191,6 +191,11 @@ PostgreSQL is available in the Debian repositories: apt install postgresql ``` +In addition, you will have to install the **appropriate headers for Erlang,** the language ejabberd is written in, so it can actually interact with the PostgreSQL server: +```sh +apt install erlang-p1-pgsql +``` + Start the PostgreSQL daemon to begin using it: ```sh diff --git a/content/i2p.md b/content/i2p.md index d0b2edb..88b05b4 100644 --- a/content/i2p.md +++ b/content/i2p.md @@ -7,13 +7,11 @@ tags: ['service'] short_desc: "A private and uncensorable web-layer similar to Tor." --- -Now you have a website, why not offer it in a private alternative such -as the Invisible Internet? +Now you have a website, why not offer it in a private alternative such as the Invisible Internet? ## Setting up I2P -There are 2 main I2P implementations, I2P and i2pd, we are using i2pd in -this guide because it\'s easier to use in servers. +There are 2 main I2P implementations, I2P and i2pd, we are using i2pd in this guide because it\'s easier to use in servers. ### Installing I2P @@ -25,9 +23,7 @@ apt install i2pd ### Enabling I2P -We are going to create a user for i2pd, because i2pd finds the -configuration files in its home directory. And it\'s easier (and more -tidy) to have it in a separate user: +We are going to create a user for i2pd, because i2pd finds the configuration files in its home directory. And it\'s easier (and more tidy) to have it in a separate user: ```sh useradd -m i2p -s /bin/bash @@ -36,9 +32,7 @@ mkdir ~/.i2pd cd ~/.i2pd ``` -Now that you\'re in \~/.i2pd, you have to create a file named -\"tunnels.conf\". Which is the config file for every hidden service -you\'re offering over I2P, the content should be like this: +Now that you\'re in \~/.i2pd, you have to create a file named \"tunnels.conf\". Which is the config file for every hidden service you\'re offering over I2P, the content should be like this: ```systemd [example] @@ -48,13 +42,58 @@ port = 8080 keys = example.dat ``` +#### Optional: Generating a Vanity Address + +If you run `i2pd` with the configuration above, it will generate a random private key (`example.dat`) for your website in `example.dat` with a matching address made up of 52 random characters, derived from this same key. + +If you instead pre-generate a private key for your website, you can use brute-force computation to make a "vanity" address, such as the following: +``` +{{}}chad{{}}aor3jc08ht340c30mg5cf340j395gj095kuazj5tokipr34f.32.i2p +``` + +To accomplish this, a set of tools named `i2pd-tools` can be installed. + +Begin by cloning their repository: +```sh +git clone --recursive https://github.com/purplei2p/i2pd-tools +``` + +The repository comes with a dependency installation script included. Run this to list the compilation dependencies you'll need, and install them: +```sh +cd i2pd-tools +sh dependencies.sh +``` + +Then compile using the `make` command: +```sh +make -j$(nproc) +``` + +This will build a variety of useful tools for i2p, with `vain` being the command of interest to generate an address: +```sh +./vain {{}}chad{{}} +``` +This command will begin running and output a new set of private keys named `private.dat` to the same directory it's ran from. Copy this file to your i2p configuration and you'll have your vanity address: + +```sh +cp private.dat /home/i2p/.i2pd/example.dat +``` + +#### Optional: Authentication Strings for Registrars + +I2P has various **registrars** that let users link their long I2P addresses to shorter, more memorable ones, like `example.i2p`. To actually register your site on one of these registrars, you will need an **authentication string.** Luckily, `i2pd-tools` includes such a tool in their repository: + +```sh +./regaddr private.dat {{}}example.2ip{{}} > {{}}auth_string.txt{{}} +``` + +The command above will save the string to a file named `auth_string.txt`. You will have to place the text contained in that file on a registration page like [http://reg.i2p/add](http://reg.i2p/add) or [http://stats.i2p/i2p/addkey.html](http://stats.i2p/i2p/addkey.html). + ### Getting your I2P Hostname -Then, run `/usr/sbin/i2pd --daemon` to start i2pd and we can retreive -our I2P hostname. +Then, run `/usr/sbin/i2pd --daemon` to start i2pd and we can retreive our I2P hostname. -This can be done in lynx or a command-line browser by going to -`http://127.0.0.1:7070/?page=i2p_tunnels` to get your I2P hostname. +This can be done in lynx or a command-line browser by going to `http://127.0.0.1:7070/?page=i2p_tunnels` to get your I2P hostname. You can also run these commands to find your hostname: @@ -63,12 +102,11 @@ printf "%s.b32.i2p " $(head -c 391 /home/i2p/.i2pd/example.dat |sha256sum|xxd -r -p | base32 |sed s/=//g | tr A-Z a-z) ``` +*(If you've generated your own keys to obtain a vanity address, now's a good time to make sure i2pd is properly reading those keys by verifying the address is the same as the one generated with the `vain` command.)* + ## Adding the Nginx Config -From here, the steps are almost identical to setting up a normal website -configuration file. Follow the steps as if you were making a new website -on the webserver [tutorial](/basic/nginx) up until the server block of -code. Instead, paste this: +From here, the steps are almost identical to setting up a normal websitenconfiguration file. Follow the steps as if you were making a new website on the webserver [tutorial](/basic/nginx) up until the server block of code. Instead, paste this: ```nginx server { @@ -82,13 +120,9 @@ server { #### -Nginx will listen in port 8080, but i2pd will forward your port 8080 to -the i2p site port 80. This way you don\'t have to deal with server names -or anything like that +Nginx will listen in port 8080, but i2pd will forward your port 8080 to the i2p site port 80. This way you don\'t have to deal with server names or anything like that. -From here we are almost done, all we have to do is enable the site and -reload nginx which is also covered in [the webserver -tutorial](nginx.html#enable). +From here we are almost done, all we have to do is enable the site and reload nginx which is also covered in [the webserver tutorial](nginx.html#enable). ### Update regularly! diff --git a/content/prosody.md b/content/prosody.md index 2797a8e..08262ab 100644 --- a/content/prosody.md +++ b/content/prosody.md @@ -96,21 +96,18 @@ apt install prosody-modules Then we can add the following line to you prosody config file to enable file uploads: ```cfg -Component "uploads.example.org" "http_upload" +Component "{{}}uploads.example.org{{}}" "http_file_share" ``` As you will notice, you need another subdomain for this. We will add an ssl certficate for this later. -You will also need to go back to `modules_enabled` and uncomment the `http_files` module. -This is used to actually serve the files to users. - ### Proxy Support This helps with file transfers for devices behind a NAT, and unless you are using XMPP in a LAN, you **probably need this.** Enable the proxy by adding the following line to the config: ```cfg -Component "proxy.example.org" "proxy65" +Component " {{}}proxy.example.org{{}}" "proxy65" ``` As you can see, another subdomain is needed. We will add ssl certificates for this later. @@ -120,26 +117,45 @@ At this point, file sharing is now setup and ready to be used. Although there ar A big concern with file sharing is large files, seeing as all files shared over XMPP will be stored on your server. This can become a problem when many (and large) files are being shared. We can put a cap on large files by adding the following line to our config: ```cfg -http_upload_file_size_limit = 20971520 +http_file_share_file_size_limit = 20971520 ``` This puts a 20MB cap on all files being shared. The value is specified in bytes. You can also specify after how long files should be deleted by adding the following line: ```cfg -http_upload_expire_after = 60 * 60 * 24 * 7 +http_file_share_expire_after = 60 * 60 * 24 * 7 ``` The value is specified in seconds. The above line will make prosody delete files after a week. -If it is for some reason neccessary, you can also manually invoke expiry with the following command: +### Database Setup -```cfg -prosodyctl mod_http_upload expire +Prosody includes the `internal` and `sql` storage backends by default. +If you wish to run Prosody with PostgreSQL, begin by installing the PostgreSQL: + +```sh +apt install postgresql ``` -### Database Setup +Then start the daemon: + +```sh +systemctl restart postgresql +``` -Prosody includes the `internal` and `sql` storage backends by default. If you wish to run Prosody with PostgreSQL, edit the following lines: +Now create a user named `prosody` to manage your database: + +```sh +su -c "createuser --pwprompt prosody" postgres +``` + +And finally, create the actual database: + +```sh +su -c "psql -c 'CREATE DATABASE prosody OWNER prosody;'" postgres +``` + +Finally, in `/etc/prosody/prosody.cfg.lua`, edit the following lines: ```cfg storage = "sql" @@ -153,8 +169,6 @@ sql = { } ``` -(This is assuming you've installed the `postgresql` package, and setup a database named `prosody` with a user named `prosody` as the owner.) - ### Voice and Video Calling Prosody supports XMPP voice and video calls through an external TURN and STUN server. @@ -194,14 +208,14 @@ Obviously, we want to have client-to-server and server-to-server encryption. Now **If you have multi-user chat enabled, be sure to get a certificate for that subdomain as well.** Include the `--nginx` option assuming you have an Nginx server running. ```sh -certbot -d chat.example.org --nginx +certbot -d {{}}chat.example.org{{}} --nginx ``` **If you have file sharing enabled, be sure to get a certificate for those subdomains as well.** ```sh -certbot -d uploads.example.org --nginx -certbot -d proxy.example.org --nginx +certbot -d {{}}uploads.example.org{{}} --nginx +certbot -d {{}}proxy.example.org{{}} --nginx ``` Once you have the certificates for encryption, run the following to import them into Prosody. @@ -219,7 +233,7 @@ Note that you might get an error that a certificate has not been found if your ` Let's manually create the admin user we prepared for above. Note that you can indeed do this in your XMPP client if you have not disabled registration, but this is how it is done on the command line: ```sh -prosodyctl adduser chad@example.org +prosodyctl adduser {{}}chad@example.org{{}} ``` This will prompt you to create a password as well. @@ -259,6 +273,6 @@ Remember that MUCs are kept on a separate subdomain that we created and should'v ### Note on firewalls and opening ports -If you use a firewall, you should open ports 5222 and 5281. The first one is needed for clients to be able to connect to your server. The second is only necessary if you are using the `http_upload` module for file sharing. +If you use a firewall, you should open ports 5222 and 5281. The first one is needed for clients to be able to connect to your server. The second is only necessary if you are using the `http_file_share` module for file sharing, as 5281 is the port for serving content over HTTPS. A complete list of ports used by Prosody can be found [here](https://prosody.im/doc/ports). -- cgit v1.2.3