linux:serveur_msp
Différences
Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
| linux:serveur_msp [2023/11/11 08:16] – ptitfrap | linux:serveur_msp [2023/11/12 07:44] (Version actuelle) – ptitfrap | ||
|---|---|---|---|
| Ligne 1: | Ligne 1: | ||
| - | ==== Securiser ==== | + | ====== Ports ====== |
| + | * 8001 mailu 80 | ||
| + | * 8002 mailu 443 | ||
| + | |||
| + | |||
| + | ==== Securiser | ||
| sshd_config | sshd_config | ||
| Ligne 10: | Ligne 15: | ||
| ssh-keygen -b 8192 | ssh-keygen -b 8192 | ||
| | | ||
| + | ==== Firewall UFW ==== | ||
| + | |||
| + | | ||
| + | apt install ufw | ||
| + | | ||
| + | ufw default deny incoming | ||
| + | ufw default allow outgoing | ||
| + | | ||
| + | ufw allow SSH | ||
| + | ufw allow "WWW Full" | ||
| + | | ||
| + | ufw enable | ||
| + | | ||
| + | ufw reload | ||
| + | | ||
| + | Outils: | ||
| + | ufw status verbose | ||
| + | ufw app list | ||
| + | | ||
| + | # ufw < | ||
| + | ufw allow from 100.100.100.100 to any port 5789 | ||
| + | | ||
| + | ==== Snapd ==== | ||
| + | install | ||
| + | sudo apt update | ||
| + | sudo apt install snapd | ||
| + | sudo snap install core | ||
| + | | ||
| + | check | ||
| + | snap list | ||
| + | snap remove [snap_name] | ||
| + | |||
| + | ==== NGINX ==== | ||
| + | apt install nginx | ||
| + | |||
| + | LetxEncrypt | ||
| + | sudo snap install --classic certbot | ||
| + | sudo ln -s / | ||
| + | sudo snap set certbot trust-plugin-with-root=ok | ||
| + | sudo snap install certbot-dns-ovh | ||
| + | |||
| + | get ovh credential | ||
| + | |||
| + | sudo certbot certonly --dns-ovh --dns-ovh-credentials / | ||
| + | | ||
| + | | ||
| + | outils: | ||
| + | sudo certbot renew --dry-run | ||
| + | sudo certbot certificates | ||
| + | |||
| + | ==== Docker ==== | ||
| + | |||
| + | install: [[https:// | ||
| + | | ||
| + | ==== Mailu ==== | ||
| + | |||
| + | domaine principal mail.msp-roanne.fr | ||
| + | |||
| + | attention a la copie du cert dans opt mailu. | ||
| + | |||
| + | |||
| + | |||
linux/serveur_msp.1699687019.txt.gz · Dernière modification : 2023/11/11 08:16 de ptitfrap
