<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet title="XSL formatting" type="text/xsl" href="https://uname.pingveno.net/blog/index.php/feed/rss2/xslt" ?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title># uname -a - Mot-clé - jessie</title>
    <link>https://uname.pingveno.net/blog/index.php/</link>
    <atom:link href="https://uname.pingveno.net/blog/index.php/feed/tag/jessie/rss2" rel="self" type="application/rss+xml" />
    <description>Le blog de uname.pingveno.net</description>
    <language>fr</language>
    <pubDate>Tue, 18 Aug 2026 13:46:21 +0200</pubDate>
    <copyright>Mathieu Pellegrin</copyright>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <generator>Dotclear</generator>
          <item>
        <title>Debian 8 : Configure Nginx and Passenger to supercharge your PuppetMaster</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2016/06/22/Debian-8-%3A-Configure-Nginx-and-Passenger-to-supercharge-your-PuppetMaster</link>
        <guid isPermaLink="false">urn:md5:67dac3b40d4c262e3ea9a071eb94d2e6</guid>
        <pubDate>Wed, 22 Jun 2016 21:16:00 +0200</pubDate>
        <dc:creator>Mathieu</dc:creator>
                  <category>Hacks</category>
                          <category>debian</category>
                  <category>jessie</category>
                  <category>mongrel</category>
                  <category>nginx</category>
                  <category>passenger</category>
                  <category>puppet</category>
                  <category>puppetmaster</category>
                  <category>ruby</category>
                <description>&lt;p&gt;The &lt;a href=&quot;http://puppetlabs.com/&quot;&gt;Puppet&lt;/a&gt; master comes by default with a basic WEBrick server. It allow a quick start for those that are not familiar with Puppet, but when the number of Puppet nodes grows, the performances of the default WEBrick server are going down quickly.&lt;/p&gt;

&lt;p&gt;The Puppet documentation show how to configure Apache and Passenger to replace the default WEBrick server, but what if you have a lot of nodes ? What if you want to apply your configuration within minutes, instead of the default half-hour threshold before the agent asks the master if something changed ?&lt;/p&gt;

&lt;p&gt;Or you may just want a fancy Nginx instead of your plain-old-reliable Apache.&lt;/p&gt;

&lt;p&gt;Here is how.&lt;/p&gt;          &lt;h3&gt;Check your hostname&lt;/h3&gt;

&lt;p&gt;Your hostname is the base configuration for your node, you should check that it's correct, otherwise you will run into problems after Puppet installation.&lt;/p&gt;

&lt;pre&gt;
# hostname -f&lt;/pre&gt;

&lt;p&gt;If everything is okay, check your hosts file&lt;/p&gt;

&lt;pre&gt;
# cat /etc/hosts&lt;/pre&gt;

&lt;p&gt;If your hostname is inside your host file, carry on. Otherwise, set it.&lt;/p&gt;

&lt;h3&gt;Install Puppet and Puppetmaster&lt;/h3&gt;

&lt;p&gt;I suppose that you also need the puppet agent installed on the Puppetmaster server.&lt;/p&gt;

&lt;p&gt;Install Puppet and Puppetmaster :&lt;/p&gt;

&lt;pre&gt;
# apt-get install puppet puppetmaster&lt;/pre&gt;

&lt;p&gt;Stop the Puppetmaster :&lt;/p&gt;

&lt;pre&gt;
# service puppetmaster stop&lt;/pre&gt;

&lt;p&gt;Prevent the puppetmaster from starting. Nginx will spawn on the right port instead of the WEBrick server, previously spawn by Puppetmaster service. Edit the file &lt;strong&gt;/etc/defaults/puppetmaster&lt;/strong&gt; :&lt;/p&gt;

&lt;pre&gt;
# Start puppetmaster on boot?
START=no&lt;/pre&gt;

&lt;p&gt;Configure the Puppet agent : edit the file &lt;strong&gt;/etc/puppet/puppet.conf&lt;/strong&gt; to point your agent on the master (for instance puppetmaster.example.com).&lt;/p&gt;

&lt;p&gt;Also, &lt;strong&gt;comment&lt;/strong&gt; the two lines that are &quot;needed for passenger&quot;, our configuration don't need them. Actually, &lt;strong&gt;if you keep it, it will not work&lt;/strong&gt;.&lt;/p&gt;

&lt;pre&gt;
[main]
logdir=/var/log/puppet
vardir=/var/lib/puppet
ssldir=/var/lib/puppet/ssl
rundir=/var/run/puppet
factpath=$vardir/lib/facter
prerun_command=/etc/puppet/etckeeper-commit-pre
postrun_command=/etc/puppet/etckeeper-commit-post
&lt;strong&gt;server=puppetmaster.example.com&lt;/strong&gt;

[master]
# These are needed when the puppetmaster is run by passenger
# and can safely be removed if webrick is used.
&lt;strong&gt;#ssl_client_header = SSL_CLIENT_S_DN
#ssl_client_verify_header = SSL_CLIENT_VERIFY&lt;/strong&gt;

[agent]
report = true&lt;/pre&gt;

&lt;p&gt;Enable your puppet agent :&lt;/p&gt;

&lt;pre&gt;
# puppet agent --enable&lt;/pre&gt;

&lt;h3&gt;Install Nginx and Passenger&lt;/h3&gt;

&lt;p&gt;We will install the bundle Nginx+Passenger shipped by Phusion repositories.&lt;/p&gt;

&lt;p&gt;Add the key to your keyring :&lt;/p&gt;

&lt;pre&gt;
# apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 561F9B9CAC40B2F7&lt;/pre&gt;

&lt;p&gt;The Phusion repository uses HTTPS, add HTTPS transport to APT :&lt;/p&gt;

&lt;pre&gt;
# apt-get install apt-transport-https ca-certificates&lt;/pre&gt;

&lt;p&gt;Finally, install Nginx and Passenger :&lt;/p&gt;

&lt;pre&gt;
# apt-get update
# apt-get install nginx-extras passenger&lt;/pre&gt;

&lt;h3&gt;Configure Nginx and Puppetmaster application&lt;/h3&gt;

&lt;p&gt;Edit &lt;strong&gt;/etc/nginx/nginx.conf&lt;/strong&gt; and uncomment the reference to passenger config :&lt;/p&gt;

&lt;pre&gt;
    ##
    # Phusion Passenger config
    ##
    # Uncomment it if you installed passenger or passenger-enterprise
    ##

    include /etc/nginx/passenger.conf;&lt;/pre&gt;

&lt;p&gt;Create the file &lt;strong&gt;/etc/nginx/nginx/sites-available/puppet.conf&lt;/strong&gt; with the following content :&lt;/p&gt;

&lt;pre&gt;
server {
    listen                     8140 ssl;
    server_name                puppet puppetmaster puppetmaster.example.com;

    passenger_enabled          on;
    passenger_app_env          production;

    passenger_set_header       X-Client-Verify  $ssl_client_verify;
    passenger_set_header       X-Client-DN $ssl_client_s_dn;
    passenger_set_header       X-SSL-Subject    $ssl_client_s_dn;
    passenger_set_header       X-SSL-Issuer     $ssl_client_i_dn;

    access_log                 /var/log/nginx/puppet_access.log;
    error_log                  /var/log/nginx/puppet_error.log;

    root                       /etc/puppet/rack/public;

    ssl_certificate            /var/lib/puppet/ssl/certs/puppetmaster.example.com.pem;
    ssl_certificate_key        /var/lib/puppet/ssl/private_keys/puppetmaster.example.com.pem;
    ssl_crl                    /var/lib/puppet/ssl/ca/ca_crl.pem;
    ssl_client_certificate     /var/lib/puppet/ssl/certs/ca.pem;
    ssl_ciphers                'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
    ssl_prefer_server_ciphers  on;
    ssl_verify_client          optional;
    ssl_verify_depth           1;
    ssl_session_cache          shared:SSL:128m;
    ssl_session_timeout        5m;
}&lt;/pre&gt;

&lt;p&gt;Remove the default virtual host from Nginx as we don't need it :&lt;/p&gt;

&lt;pre&gt;
# rm /etc/nginx/sites-enabled/default&lt;/pre&gt;

&lt;p&gt;And enable your newly created server :&lt;/p&gt;

&lt;pre&gt;
# ln -s /etc/nginx/sites-available/puppet.conf /etc/nginx/sites-enabled/puppet.conf&lt;/pre&gt;

&lt;p&gt;Before restarting Nginx, we will configure the Ruby application for Puppetmaster.&lt;/p&gt;

&lt;p&gt;Create the directory &lt;strong&gt;/etc/puppet/rack&lt;/strong&gt; and its subdirectories &lt;strong&gt;/etc/puppet/rack/public&lt;/strong&gt; and &lt;strong&gt;/etc/puppet/rack/tmp&lt;/strong&gt;&lt;/p&gt;

&lt;pre&gt;
# mkdir -p /etc/puppet/rack/public /etc/puppet/rack/tmp&lt;/pre&gt;

&lt;p&gt;Create the file &lt;strong&gt;/etc/puppet/rack/config.ru&lt;/strong&gt; with the following content :&lt;/p&gt;

&lt;pre&gt;
# a config.ru, for use with every rack-compatible webserver.
# SSL needs to be handled outside this, though.

# if puppet is not in your RUBYLIB:
# $LOAD_PATH.unshift('/opt/puppet/lib')

$0 = &quot;master&quot;

# Set the PATH in environment variable
ENV['PATH'] = &quot;/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin&quot;

# if you want debugging:
# ARGV &amp;lt;&amp;lt; &quot;--debug&quot;

ARGV &amp;lt;&amp;lt; &quot;--rack&quot;

# Rack applications typically don't start as root.  Set --confdir, --vardir,
# --logdir, --rundir to prevent reading configuration from
# ~/ based pathing.
ARGV &amp;lt;&amp;lt; &quot;--confdir&quot; &amp;lt;&amp;lt; &quot;/etc/puppet&quot;
ARGV &amp;lt;&amp;lt; &quot;--vardir&quot;  &amp;lt;&amp;lt; &quot;/var/lib/puppet&quot;
ARGV &amp;lt;&amp;lt; &quot;--logdir&quot;  &amp;lt;&amp;lt; &quot;/var/log/puppet&quot;
ARGV &amp;lt;&amp;lt; &quot;--rundir&quot;  &amp;lt;&amp;lt; &quot;/var/run/puppet&quot;
#ARGV &amp;lt;&amp;lt; &quot;--codedir&quot;  &amp;lt;&amp;lt; &quot;/etc/puppet/code&quot;

# always_cache_features is a performance improvement and safe for a master to
# apply. This is intended to allow agents to recognize new features that may be
# delivered during catalog compilation.
ARGV &amp;lt;&amp;lt; &quot;--always_cache_features&quot;

# NOTE: it's unfortunate that we have to use the &quot;CommandLine&quot; class
#  here to launch the app, but it contains some initialization logic
#  (such as triggering the parsing of the config file) that is very
#  important.  We should do something less nasty here when we've
#  gotten our API and settings initialization logic cleaned up.
#
# Also note that the &quot;$0 = master&quot; line up near the top here is
#  the magic that allows the CommandLine class to know that it's
#  supposed to be running master.
#
# --cprice 2012-05-22

require 'puppet/util/command_line'
# we're usually running inside a Rack::Builder.new {} block,
# therefore we need to call run *here*.
run Puppet::Util::CommandLine.new.execute&lt;/pre&gt;

&lt;p&gt;Chown the file for Puppet user :&lt;/p&gt;

&lt;pre&gt;
# chown puppet:puppet /etc/puppet/rack/config.ru&lt;/pre&gt;

&lt;p&gt;And finally, restart Nginx :&lt;/p&gt;

&lt;pre&gt;
# service nginx restart&lt;/pre&gt;

&lt;p&gt;Then, test you configuration by running the agent :&lt;/p&gt;

&lt;pre&gt;
# puppet agent --test&lt;/pre&gt;

&lt;h3&gt;Troubleshooting and errors&lt;/h3&gt;

&lt;h4&gt;Error 500&lt;/h4&gt;

&lt;pre&gt;
Warning: Error 500 on SERVER: Internal Server Error&lt;/pre&gt;

&lt;p&gt;Read the logs at &lt;strong&gt;/var/log/nginx/error.log&lt;/strong&gt; and &lt;strong&gt;/etc/nginx/puppet_error.log&lt;/strong&gt;&lt;/p&gt;

&lt;h4&gt;Error 403&lt;/h4&gt;

&lt;pre&gt;
Warning: Error 403 on SERVER: Forbidden request: localhost(127.0.0.1) access to /node/puppetmaster.example.com [find] at :119&lt;/pre&gt;

&lt;p&gt;Check that your hostname resolves, and that your host file is clean. In particular, you should have the host name of your server on the same line than localhost :&lt;/p&gt;

&lt;pre&gt;
127.0.0.1    localhost puppetmaster puppetmaster.example.com&lt;/pre&gt;

&lt;p&gt;Also check that your Puppet configuration is correct, in particular check that the two lines &quot;required for Passenger&quot; are commented.&lt;/p&gt;

&lt;h3&gt;Sources&lt;/h3&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;https://docs.puppet.com/puppet/4.5/reference/passenger.html#install-rackpassenger&quot;&gt;[Puppet Doc] Configuring a Puppet Master Server with Passenger and Apache&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://www.linode.com/docs/websites/ror/ruby-on-rails-nginx-debian-8&quot;&gt;[Linode] Ruby on Rails with Nginx on Debian 8&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://www.phusionpassenger.com/library/install/nginx/install/oss/jessie/&quot;&gt;[Phusion Passenger] Installing Passenger + Nginx&lt;/a&gt;
	&lt;ul&gt;
		&lt;li&gt;&lt;a href=&quot;https://www.phusionpassenger.com/library/config/nginx/reference/&quot;&gt;[Phusion Passenger] Configuration reference&lt;/a&gt;&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://ask.puppet.com/question/13176/puppet-master-could-not-retrieve-fact-fqdnipaddress/?answer=13351#post-id-13351&quot;&gt;[Ask Puppet] Puppet Master - Could not retrieve fact fqdn/ipaddress&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a class=&quot;question-hyperlink&quot; href=&quot;http://serverfault.com/questions/456680/puppet-master-rest-api-returns-403-when-running-under-passenger-works-when-maste&quot;&gt;Puppet master REST API returns 403 when running under passenger&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt; &lt;/p&gt;</description>
        
              </item>
          <item>
        <title>Debian 8 : Limit SSH users to SFTP</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2016/01/07/Limit-SSH-users-to-SFTP-only</link>
        <guid isPermaLink="false">urn:md5:d5a47c46eec6232c19a682eae095d7a1</guid>
        <pubDate>Thu, 18 Feb 2016 10:38:00 +0100</pubDate>
        <dc:creator>Mathieu</dc:creator>
                  <category>Hacks</category>
                          <category>debian</category>
                  <category>jessie</category>
                  <category>server</category>
                  <category>sftp</category>
                  <category>ssh</category>
                <description>&lt;p&gt;Let&amp;#8217;s say you want to configure a secure remote file access for you users, but you can&amp;#8217;t use FTPS for some reasons (problems with passive mode and commercial firewalls&amp;#160;? Yes&amp;#160;!). Your only secure solution is either a VPN, or a SFTP access.&lt;/p&gt;&lt;p&gt;SFTP is great, but it may implies giving full command line access to your end users.&amp;nbsp; In order to prevent that, you could set-up a jailed SSH access with &lt;a href=&quot;http://olivier.sessink.nl/jailkit/&quot;&gt;Jailkit&lt;/a&gt; and some &lt;a href=&quot;http://unix.stackexchange.com/questions/198590/what-is-a-bind-mount&quot;&gt;bind mount&lt;/a&gt;, but it&amp;#8217;s not that trivial to configure and to maintain&amp;#160;; and it may not work with software virtualization (Docker, LXCs&amp;#8230;). There is a simpler solution.&lt;/p&gt;&lt;p&gt;The solution is&amp;#160;: use the native chroot and limitations abilities of OpenSSH. Here is how.&lt;/p&gt;          &lt;h3&gt;Warning!&lt;/h3&gt;&lt;p&gt;You should not configure this on your primary SSH access. By doing so, you will simply lock you out of your server.&lt;/p&gt;&lt;p&gt;In this article, we will set up a completely new instance of OpennSSH server, running next to the original, and handling SFTP only.&lt;/p&gt;&lt;h3&gt;1. Setup the secondary SSH access (SFTP-only)&lt;/h3&gt;&lt;p&gt;Create a new configuration file by copying the primary configuration&amp;#160;:&lt;/p&gt;&lt;pre&gt;cp /etc/ssh/sshd_config /etc/ssh/sftp_config&lt;/pre&gt;&lt;p&gt;Now edit the file &lt;strong&gt;/etc/ssh/sftp_config&lt;/strong&gt; and change the listening port (for instance 10022)&amp;#160;:&lt;/p&gt;&lt;pre&gt;Port 10022&lt;/pre&gt;&lt;p&gt;Change the PID file for this new instance, set something meaningful&amp;#160;:&lt;/p&gt;&lt;pre&gt;PidFile /var/run/sftp.pid&lt;/pre&gt;&lt;p&gt;Then add these lines to&amp;nbsp;&lt;strong&gt;/etc/ssh/sftp_config&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;ChrootDirectory %h
ForceCommand internal-sftp
AllowTcpForwarding no&lt;/pre&gt;&lt;p&gt;Here is a sample of a full configuration&amp;#160;:&lt;/p&gt;&lt;pre&gt;# Package generated configuration file
# See the sshd_config(5) manpage for details

# What ports, IPs and protocols we listen for
&lt;strong&gt;Port 10022&lt;/strong&gt;
# Use these options to restrict which interfaces/protocols sshd will bind to
#ListenAddress ::
#ListenAddress 0.0.0.0
Protocol 2
# HostKeys for protocol version 2
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
HostKey /etc/ssh/ssh_host_ecdsa_key
HostKey /etc/ssh/ssh_host_ed25519_key
#Privilege Separation is turned on for security
UsePrivilegeSeparation yes

&lt;strong&gt;PidFile /var/run/sftp.pid&lt;/strong&gt;

# Lifetime and size of ephemeral version 1 server key
KeyRegenerationInterval 3600
ServerKeyBits 1024

# Logging
SyslogFacility AUTH
LogLevel INFO

# Authentication:
LoginGraceTime 120
PermitRootLogin no
StrictModes yes

RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile    %h/.ssh/authorized_keys

# Don't read the user's ~/.rhosts and ~/.shosts files
IgnoreRhosts yes
# For this to work you will also need host keys in /etc/ssh_known_hosts
RhostsRSAAuthentication no
# similar for protocol version 2
HostbasedAuthentication no
# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
#IgnoreUserKnownHosts yes

# To enable empty passwords, change to yes (NOT RECOMMENDED)
PermitEmptyPasswords no

# Change to yes to enable challenge-response passwords (beware issues with
# some PAM modules and threads)
ChallengeResponseAuthentication no

# Change to no to disable tunnelled clear text passwords
#PasswordAuthentication yes

# Kerberos options
#KerberosAuthentication no
#KerberosGetAFSToken no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes

# GSSAPI options
#GSSAPIAuthentication no
#GSSAPICleanupCredentials yes

&lt;strong&gt;X11Forwarding no&lt;/strong&gt;
X11DisplayOffset 10
PrintMotd no
PrintLastLog yes
TCPKeepAlive yes
#UseLogin no

#MaxStartups 10:30:60
#Banner /etc/issue.net

# Allow client to pass locale environment variables
AcceptEnv LANG LC_*

&lt;strong&gt;Subsystem sftp /usr/lib/openssh/sftp-server
ChrootDirectory %h
ForceCommand internal-sftp
AllowTcpForwarding no&lt;/strong&gt;

# Set this to 'yes' to enable PAM authentication, account processing,
# and session processing. If this is enabled, PAM authentication will
# be allowed through the ChallengeResponseAuthentication and
# PasswordAuthentication.  Depending on your PAM configuration,
# PAM authentication via ChallengeResponseAuthentication may bypass
# the setting of &quot;PermitRootLogin without-password&quot;.
# If you just want the PAM account and session checks to run without
# PAM authentication, then enable this but set PasswordAuthentication
# and ChallengeResponseAuthentication to 'no'.
UsePAM yes
&lt;/pre&gt;&lt;p&gt;Now, let&amp;#8217;s configure autostart. Copy &lt;strong&gt;/lib/systemd/system/ssh.service&lt;/strong&gt; to&amp;nbsp;&lt;strong&gt;/lib/systemd/system/sftp.service&lt;/strong&gt; and adjust settings&amp;#160;:&lt;/p&gt;&lt;pre&gt;[Unit]
Description=&lt;strong&gt;OpenBSD Secure Shell server (SFTP only)&lt;/strong&gt;
After=network.target auditd.service
ConditionPathExists=!/etc/ssh/sshd_not_to_be_run

[Service]
EnvironmentFile=-/etc/default/ssh
ExecStart=/usr/sbin/sshd -D $SSHD_OPTS -f &lt;strong&gt;/etc/ssh/sftp.conf&lt;/strong&gt;
ExecReload=/bin/kill -HUP $MAINPID
KillMode=process
Restart=on-failure

[Install]
WantedBy=multi-user.target
Alias=&lt;strong&gt;sftp.service&lt;/strong&gt;
&lt;/pre&gt;&lt;p&gt;And enable your service&amp;#160;:&lt;/p&gt;&lt;pre&gt;systemctl enable sftp.service&lt;/pre&gt;&lt;p&gt;Make sure the symlink&amp;nbsp;&lt;strong&gt;/etc/systemd/system/sftp.service&lt;/strong&gt; is created.&lt;/p&gt;&lt;p&gt;And try to start it&amp;#160;:&lt;/p&gt;&lt;pre&gt;service sftp start&lt;/pre&gt;&lt;h3&gt;2. Reconfigure the primary SSH access&lt;/h3&gt;&lt;p&gt;In order to prevent normal users to log into a full shell, we have to change the primary configuration.&lt;/p&gt;&lt;p&gt;The configuration file should be located in &lt;strong&gt;/etc/ssh/sshd_config&lt;/strong&gt; . Add an AllowUsers or AllowGroups directive to this file&amp;#160;:&lt;/p&gt;&lt;pre&gt;# One or the other but not both!
AllowUsers root admin
#AllowGroups sudo
&lt;/pre&gt;&lt;p&gt;Here is a sample of a full configuration&amp;#160;:&lt;/p&gt;&lt;pre&gt;# Package generated configuration file
# See the sshd_config(5) manpage for details

# What ports, IPs and protocols we listen for
&lt;strong&gt;Port 22&lt;/strong&gt;
# Use these options to restrict which interfaces/protocols sshd will bind to
#ListenAddress ::
#ListenAddress 0.0.0.0
Protocol 2
# HostKeys for protocol version 2
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
HostKey /etc/ssh/ssh_host_ecdsa_key
HostKey /etc/ssh/ssh_host_ed25519_key
#Privilege Separation is turned on for security
UsePrivilegeSeparation yes

# Lifetime and size of ephemeral version 1 server key
KeyRegenerationInterval 3600
ServerKeyBits 1024

# Logging
SyslogFacility AUTH
LogLevel INFO

# Authentication:
LoginGraceTime 120
PermitRootLogin without-password
StrictModes yes
&lt;strong&gt;AllowUsers root admin&lt;/strong&gt;

RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile    %h/.ssh/authorized_keys

# Don't read the user's ~/.rhosts and ~/.shosts files
IgnoreRhosts yes
# For this to work you will also need host keys in /etc/ssh_known_hosts
RhostsRSAAuthentication no
# similar for protocol version 2
HostbasedAuthentication no
# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
#IgnoreUserKnownHosts yes

# To enable empty passwords, change to yes (NOT RECOMMENDED)
PermitEmptyPasswords no

# Change to yes to enable challenge-response passwords (beware issues with
# some PAM modules and threads)
ChallengeResponseAuthentication no

# Change to no to disable tunnelled clear text passwords
#PasswordAuthentication yes

# Kerberos options
#KerberosAuthentication no
#KerberosGetAFSToken no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes

# GSSAPI options
#GSSAPIAuthentication no
#GSSAPICleanupCredentials yes

X11Forwarding no
X11DisplayOffset 10
PrintMotd no
PrintLastLog yes
TCPKeepAlive yes
#UseLogin no

#MaxStartups 10:30:60
Banner /etc/issue.net

# Allow client to pass locale environment variables
AcceptEnv LANG LC_*

Subsystem sftp /usr/lib/openssh/sftp-server

UsePAM yes&lt;/pre&gt;&lt;p&gt;Restart your primary SSH access, but &lt;strong&gt;don&amp;#8217;t close your terminal afterwards&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;service ssh restart&lt;/pre&gt;&lt;p&gt;Now open a new terminal and check that your primary SSH is still working. If not, rollback your configuration.&lt;/p&gt;&lt;h3&gt;3. Conclusion&lt;/h3&gt;&lt;p&gt;Now you should have two SSH sockets listening&amp;#160;: one for everyone using exclusively SFTP, and the other with full SSH access for authorized accounts.&lt;/p&gt;&lt;p&gt;Don&amp;#8217;t hesitate to reply in comments if you encounter problems. &lt;img src=&quot;/blog/themes/mathedit_material3/smilies/smile.png&quot; alt=&quot;:)&quot; class=&quot;smiley&quot;&gt;&lt;/p&gt;&lt;h3&gt;Sources&lt;/h3&gt;&lt;p&gt;&lt;a href=&quot;https://wiki.archlinux.org/index.php/SFTP_chroot&quot;&gt;https://wiki.archlinux.org/index.php/SFTP_chroot&lt;/a&gt;&lt;/p&gt;</description>
        
              </item>
          <item>
        <title>Set-up SQL quarantine with Amavisd-new and ISPConfig</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2015/12/05/Set-up-SQL-quarantine-with-Amavisd-new-and-ISPConfig</link>
        <guid isPermaLink="false">urn:md5:c449e2fbaef8eadc5d8276ac89e472d3</guid>
        <pubDate>Sun, 06 Dec 2015 16:56:00 +0100</pubDate>
        <dc:creator>Mathieu</dc:creator>
                  <category>Hacks</category>
                          <category>amavis</category>
                  <category>debian</category>
                  <category>ISPConfig</category>
                  <category>jessie</category>
                  <category>mail</category>
                  <category>quarantine</category>
                  <category>server</category>
                  <category>spam</category>
                  <category>sql</category>
                <description>&lt;p&gt;It's documented, but it took me two days to do it correctly, so here is how to reconfigure an ISPConfig installation of Amavis to store quarantined mail in SQL database, in order to install a quarantine viewer like Mailzu.&lt;/p&gt;          &lt;h3&gt;1. Prerequisites&lt;/h3&gt;

&lt;ul&gt;
	&lt;li&gt;A working Postfix+Amavis stack with ISPConfig&lt;/li&gt;
	&lt;li&gt;A working SQL (PostgreSQL, MySQL...) database&lt;/li&gt;
	&lt;li&gt;Optional : a working mail server with PHP (for Mailzu)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Jump to &lt;a href=&quot;https://uname.pingveno.net/blog/index.php/post/2015/12/05/Set-up-SQL-quarantine-with-Amavisd-new-and-ISPConfig#installation&quot;&gt;Installation&lt;/a&gt; if you know what you are doing.&lt;/p&gt;

&lt;h3&gt;2. Off-subject generic explanations&lt;/h3&gt;

&lt;h4&gt;2.1 Amavis and ISPConfig policies&lt;/h4&gt;

&lt;figure style=&quot;float: right; margin: 0 0 1em 1em;&quot;&gt;&lt;a class=&quot;media-link&quot; href=&quot;https://uname.pingveno.net/blog/public/captures/ispconfig/ispconfig_mail_spamfilter_policy_tag_levels.png&quot;&gt;&lt;img alt=&quot;ispconfig_mail_spamfilter_policy_tag_levels.png&quot; class=&quot;media&quot; src=&quot;https://uname.pingveno.net/blog/public/captures/ispconfig/.ispconfig_mail_spamfilter_policy_tag_levels_s.png&quot; /&gt;&lt;/a&gt;

&lt;figcaption&gt;ISPConfig policies, Tag-Levels&lt;/figcaption&gt;
&lt;/figure&gt;

&lt;p&gt;In a default ISPConfig installation per-user ISPConfig policies are loaded. The configuration file for Amavis, written by ISPConfig contains :&lt;/p&gt;

&lt;pre&gt;
@lookup_sql_dsn =
   ( ['DBI:mysql:database=dbispconfig;host=127.0.0.1;port=3306', 'ispconfig', 'xxxx'] );
$sql_select_policy =
   'SELECT *,spamfilter_users.id'.
   ' FROM spamfilter_users LEFT JOIN spamfilter_policy ON spamfilter_users.policy_id=spamfilter_policy.id'.
   ' WHERE spamfilter_users.email IN (%k) ORDER BY spamfilter_users.priority DESC';
$sql_select_white_black_list = 'SELECT wb FROM spamfilter_wblist'.
    ' WHERE (spamfilter_wblist.rid=?) AND (spamfilter_wblist.email IN (%k))' .
    ' ORDER BY spamfilter_wblist.priority DESC';&lt;/pre&gt;

&lt;p&gt;It means that whatever you would set as&amp;nbsp;&lt;strong&gt;$sa_spam_subject_tag&lt;/strong&gt;, &lt;strong&gt;$sa_tag_level_deflt&lt;/strong&gt;, &lt;strong&gt;$sa_tag2_level_deflt&lt;/strong&gt;, &lt;strong&gt;$sa_kill_level_deflt&lt;/strong&gt;, &lt;strong&gt;$sa_dsn_cutoff_level&lt;/strong&gt;, it will be overridden by per-user policies.&lt;/p&gt;

&lt;p&gt;The ISPConfig policies can be changed in tab Email =&amp;gt; Spamfilter =&amp;gt; Policy in ISPConfig panel. If you struggle wondering why your message keeps getting smashed at level 4.5, look at the sa_tag_level in policies. We will have to change values in that policies, to make the SQL quarantine working.&lt;/p&gt;

&lt;h4&gt;2.2 Lookup DSN and Storage DSN&lt;/h4&gt;

&lt;p&gt;DSN (Data Source Name) are the connection strings with host, username, and password, used to connect to databases.&lt;/p&gt;

&lt;p&gt;Amavis can set two DSN : one for Policies lookup (used to retrieve ISPConfig policies from Panel), and one for storage of mail meta informations and quarantine. We will use the Storage DSN to set up a secondary database for quarantine storage, to not mess with existing ISPConfig database.&lt;/p&gt;

&lt;h4&gt;2.3 Levels and cutoffs&lt;/h4&gt;

&lt;p&gt;Amavis uses Spamassassin to score the mail, in order to decide what to do with it. The category of test (spam test, antivirus, etc) and the score along with levels determines the actions Amavis will trigger, and the final destiny where the mail belongs.&lt;/p&gt;

&lt;p&gt;Spamassassin levels are :&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;strong&gt;tag_level&lt;/strong&gt; : a message above that score will be tagged with &lt;strong&gt;X-Spam-Status&lt;/strong&gt;, &lt;strong&gt;X-Spam-Score&lt;/strong&gt; and &lt;strong&gt;X-Spam-Level&lt;/strong&gt; headers.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;tag2_level&lt;/strong&gt; : a message above that score will be marked &lt;strong&gt;as X-Spam-Status: Yes&lt;/strong&gt; and the subject is changed if &lt;strong&gt;sa_spam_modifies_subj&lt;/strong&gt; is set to true.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;kill_level&lt;/strong&gt; : a message above that score is taken to the &lt;strong&gt;final_spam_destiny&lt;/strong&gt;, and quarantined, it will not be delivered unless &lt;strong&gt;D_PASS&lt;/strong&gt; is set to &lt;strong&gt;final_spam_destiny&lt;/strong&gt;.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;dsn_cutoff_level&lt;/strong&gt; : a message above that level will never trigger a bounce or a reject, whatever &lt;strong&gt;spam_destiny&lt;/strong&gt; is.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;quarantine_cutoff_level&lt;/strong&gt; : a message above that level will not be quarantined.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;2.4 Final &lt;span class=&quot;gt-baf-back&quot;&gt;destinations&lt;/span&gt;&lt;/h4&gt;

&lt;p&gt;Once the message is categorized by Amavis tests (through SpamAssassin, ClamAV, etc), Amavis decides if it should be delivered to user mailbox or not, and if a bounce will be issued.&lt;/p&gt;

&lt;p&gt;This is the purpose of &lt;strong&gt;$final_virus_destiny&lt;/strong&gt;, &lt;strong&gt;$final_spam_destiny&lt;/strong&gt;, &lt;strong&gt;$final_banned_destiny&lt;/strong&gt;, &lt;strong&gt;$final_bad_header_destiny&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;They can take the following values :&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;strong&gt;D_PASS&lt;/strong&gt; : mail will be delivered to inbox.&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;D_BOUNCE&lt;/strong&gt; : mail will not be delivered, and a &lt;em&gt;delivery status notification&lt;/em&gt; will be returned by Postifx to sender (except if the score exceeds the &lt;strong&gt;dsn_cutoff&lt;/strong&gt; level)&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;D_REJECT&lt;/strong&gt; : Postfix will answer REJECT to the distant mail server, and the distant mail server may produce a &lt;em&gt;delivery status notification&lt;/em&gt; to the user&lt;/li&gt;
	&lt;li&gt;&lt;strong&gt;D_DISCARD&lt;/strong&gt; : forgive and forget : the mail will not be delivered and the sender is not informed. The mail may be quarantined if the &lt;strong&gt;quarantine_cutoff&lt;/strong&gt; level is not exceeded.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a name=&quot;installation&quot;&gt;3. Installation&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
	&lt;li&gt;For Amavis : Nothing ! Amavis comes out-of-the-box with SQL storage.&lt;/li&gt;
	&lt;li&gt;For Mailzu : see &lt;a href=&quot;https://uname.pingveno.net/blog/index.php/post/2015/12/05/Set-up-SQL-quarantine-with-Amavisd-new-and-ISPConfig#mailzu&quot;&gt;Mailzu&lt;/a&gt; section.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;4. Configuration&lt;/h3&gt;

&lt;h4&gt;4.1 Database&lt;/h4&gt;

&lt;p&gt;Create an user and a database for quarantine storage :&lt;/p&gt;

&lt;pre&gt;
# mysql -u root -p
mysql&amp;gt; CREATE DATABASE amavis_storage;
mysql&amp;gt; CREATE USER 'amavis_storage'@'localhost' IDENTIFIED BY 'xxxx';
mysql&amp;gt; GRANT ALL PRIVILEGES ON amavis_storage.* TO 'amavis_storage'@'localhost';
mysql&amp;gt; FLUSH PRIVILEGES;&lt;/pre&gt;

&lt;p&gt;Load the initial schema from Amavis docs (usually located in &lt;strong&gt;/usr/share/doc/amavisd-new&lt;/strong&gt;/ ).&lt;/p&gt;

&lt;p&gt;Delete unnecessary tables, as we will be using this database only for mail storage and not for lookups :&lt;/p&gt;

&lt;pre&gt;
# mysql -u amavis_storage -p amavis_storage
mysql&amp;gt; DROP TABLE users;
mysql&amp;gt; DROP TABLE mailaddr;
mysql&amp;gt; DROP TABLE policy;
mysql&amp;gt; DROP TABLE wblist;
&lt;/pre&gt;

&lt;p&gt;Nota Bene : while executing &lt;strong&gt;DROP TABLE users&lt;/strong&gt;, don't be silly, and do not remove mysql users database.&lt;/p&gt;

&lt;h4&gt;4.2 Amavis&lt;/h4&gt;

&lt;p&gt;Update your Amavis configuration &lt;strong&gt;/etc/amavis/conf.d/50_user&lt;/strong&gt; :&lt;/p&gt;

&lt;pre&gt;
@storage_sql_dsn = ( ['DBI:mysql:database=amavis_storage;host=127.0.0.1;port=3306', 'amavis_storage', 'xxxx'] );  # none, same, or separate database

# Quarantine SPAM into SQL server.
$spam_quarantine_to = 'spam-quarantine';
$spam_quarantine_method = 'sql:';

# Quarantine VIRUS into SQL server.
$virus_quarantine_to = 'virus-quarantine';
$virus_quarantine_method = 'sql:';

# Quarantine BANNED message into SQL server.
$banned_quarantine_to = 'banned-quarantine';
$banned_files_quarantine_method = 'sql:';

# Quarantine Bad Header message into SQL server.
$bad_header_quarantine_method = 'sql:';
$bad_header_quarantine_to = 'badheader-quarantine';

# Do not store non-quarantined messages info
# You can set it to 1 (the default) to test if Amavis is filling correctly the tables maddr, msgs, and msgcrpt
$sql_store_info_for_all_msgs = 0;

#
# SQL Select statements
#

$sql_select_policy =
   'SELECT *,spamfilter_users.id'.
   ' FROM spamfilter_users LEFT JOIN spamfilter_policy ON spamfilter_users.policy_id=spamfilter_policy.id'.
   ' WHERE spamfilter_users.email IN (%k) ORDER BY spamfilter_users.priority DESC';

$sql_select_white_black_list = 'SELECT wb FROM spamfilter_wblist'.
    ' WHERE (spamfilter_wblist.rid=?) AND (spamfilter_wblist.email IN (%k))' .
    ' ORDER BY spamfilter_wblist.priority DESC';

#
# Quarantine settings
#

$final_virus_destiny = D_BOUNCE;
$final_spam_destiny = D_DISCARD;
$final_banned_destiny = D_BOUNCE;
$final_bad_header_destiny = D_PASS;

# Default settings, we st this very high to not filter aut emails accidently
$sa_spam_subject_tag = '[SPAM] ';
$sa_tag_level_deflt  = 20.0;  # add spam info headers if at, or above that level
$sa_tag2_level_deflt = 60.0; # add 'spam detected' headers at that level
$sa_kill_level_deflt = 60.0; # triggers spam evasive actions
$sa_dsn_cutoff_level = 100;   # spam level beyond which a DSN is not sent
#$sa_debug = 1;

#
# Disable spam and virus notifications for the admin user.
# Can be overridden by the policies in mysql
#

$virus_admin = undef;
$spam_admin = undef;

#
# Enable Logging
#

$DO_SYSLOG = 1;
$LOGFILE = &quot;/var/log/amavis.log&quot;;  # (defaults to empty, no log)

# Set the log_level to 5 for debugging
$log_level = 0;                # (defaults to 0)&lt;/pre&gt;

&lt;h4&gt;4.3 ISPConfig policies&lt;/h4&gt;

&lt;p&gt;Remember that ISPconfig policies are overriding a lot of our configuration in &lt;strong&gt;50_user&lt;/strong&gt;. In order to majke the quarantine work, you have to reconfigure all the available policies in ISPConfig Panel.&lt;/p&gt;

&lt;p&gt;Look at your policies list, you have to change the quarantine settings for every policies :&lt;/p&gt;

&lt;figure style=&quot;{figureStyle}&quot;&gt;&lt;a class=&quot;media-link&quot; href=&quot;https://uname.pingveno.net/blog/public/captures/ispconfig/ispconfig_mail_spamfilter_policy.png&quot;&gt;&lt;img alt=&quot;ispconfig_mail_spamfilter_policy.png&quot; class=&quot;media&quot; src=&quot;https://uname.pingveno.net/blog/public/captures/ispconfig/ispconfig_mail_spamfilter_policy.png&quot; /&gt;&lt;/a&gt;

&lt;figcaption&gt;ISPConfig Mail Spamfilter Policy&lt;/figcaption&gt;
&lt;/figure&gt;

&lt;h4&gt;When editing a policy, on the Quarantine tab, set the destinations :&lt;/h4&gt;

&lt;figure style=&quot;{figureStyle}&quot;&gt;&lt;a class=&quot;media-link&quot; href=&quot;https://uname.pingveno.net/blog/public/captures/ispconfig/ispconfig_mail_spamfilter_policy_quarantine.png&quot;&gt;&lt;img alt=&quot;ispconfig_mail_spamfilter_policy_quarantine.png&quot; class=&quot;media&quot; src=&quot;https://uname.pingveno.net/blog/public/captures/ispconfig/ispconfig_mail_spamfilter_policy_quarantine.png&quot; /&gt;&lt;/a&gt;

&lt;figcaption&gt;ISPConfig Mail Spamfilter Policy Quarantine destinations&lt;/figcaption&gt;
&lt;/figure&gt;

&lt;p&gt;&lt;strong&gt;If you do not fill something in these fields, Amavis will not store quarantined mails in SQL database, and will just discard it !&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;These fields correspond to the &lt;strong&gt;virus_quarantine_to&lt;/strong&gt;, &lt;strong&gt;spam_quarantine_to&lt;/strong&gt;, &lt;strong&gt;banned_quarantine_to&lt;/strong&gt;, &lt;strong&gt;bad_header_quarantine_to&lt;/strong&gt; variables in Amavis configuration, and an empty value is overriding those we set in Amavis configuration.&lt;/p&gt;

&lt;h4&gt;4.4 Test&lt;/h4&gt;

&lt;p&gt;Send some spam to your server, check if the tables are populated :&lt;/p&gt;

&lt;pre&gt;
mysql&amp;gt; SELECT * FROM maddr;&lt;/pre&gt;

&lt;p&gt;Check if meta informations are populated :&lt;/p&gt;

&lt;pre&gt;
mysql&amp;gt; SELECT * FROM msgs;
mysql&amp;gt; SELECT * FROM msgrcpt;&lt;/pre&gt;

&lt;p&gt;And if quarantine is filling :&lt;/p&gt;

&lt;pre&gt;
mysql&amp;gt; SELECT * FROM quarantine;&lt;/pre&gt;

&lt;h3&gt;5. Cleanup !&lt;/h3&gt;

&lt;p&gt;You should not &quot;setup and forget&quot; your quarantine SQL storage. Messages has to be deleted periodically, otherwise your database will grow forever. Look at the documentaion in &lt;strong&gt;/usr/share/docs/amavisd-new&lt;/strong&gt; to make a cronjob like this :&lt;/p&gt;

&lt;pre&gt;
#!/bin/bash

SQL_HOST=&quot;localhost&quot;;
SQL_LOGIN=&quot;amavis_storage&quot;
SQL_PASSWORD=&quot;xxxx&quot;
SQL_DB=&quot;amavis_storage&quot;

mysql --user=&quot;$SQL_LOGIN&quot; --password=&quot;$SQL_PASSWORD&quot; --host=&quot;$SQL_HOST&quot; $SQL_DB -e &quot; \
  DELETE FROM msgs WHERE time_num &amp;lt; UNIX_TIMESTAMP() - 30*24*3600; \
  DELETE FROM msgrcpt WHERE NOT EXISTS (SELECT 1 FROM msgs WHERE mail_id=msgrcpt.mail_id); \
  DELETE FROM quarantine WHERE NOT EXISTS (SELECT 1 FROM msgs WHERE mail_id=quarantine.mail_id); \
  DELETE FROM maddr WHERE NOT EXISTS (SELECT 1 FROM msgs WHERE sid=id) AND NOT EXISTS (SELECT 1 FROM msgrcpt WHERE rid=id); \
&quot;
&lt;/pre&gt;

&lt;h3&gt;&lt;a name=&quot;mailzu&quot;&gt;6. Mailzu&lt;/a&gt;&lt;/h3&gt;

&lt;p&gt;I have to admit, Mailzu seems a bit obsolete as I had to patch to make it working with Amavis 3.3 tables. But it still works pretty well for a simple task like reading and releasing quarantine mails.&lt;/p&gt;

&lt;h4&gt;6.1 Installation&lt;/h4&gt;

&lt;p&gt;Download the source files at &lt;a href=&quot;http://sourceforge.net/projects/mailzu/&quot;&gt;http://sourceforge.net/projects/mailzu/&lt;/a&gt;.&lt;/p&gt;

&lt;h4&gt;62. Patch&lt;/h4&gt;

&lt;p&gt;The existing Mailzu source code is quite old, and the schema of Amavis SQL tables changed. Download and apply &lt;a href=&quot;http://sourceforge.net/p/mailzu/patches/10/&quot;&gt;this patch&lt;/a&gt; in to make Mailzu work.&lt;/p&gt;

&lt;h4&gt;6.3 Configuration&lt;/h4&gt;

&lt;p&gt;I suppose that you know how to spawn PHP with CGI to serve the Mailzu files.&lt;/p&gt;

&lt;p&gt;Configure your database login and password in &lt;strong&gt;config/config.php&lt;/strong&gt; :&lt;/p&gt;

&lt;pre&gt;
$conf['db']['dbType'] = 'mysql';
$conf['db']['dbUser'] = 'amavis_storage';
$conf['db']['dbPass'] = 'xxxx';
$conf['db']['dbName'] = 'amavis_storage';
$conf['db']['hostSpec'] = 'localhost:3306';&lt;/pre&gt;

&lt;p&gt;I am using IMAP login to authenticate in Mailzu. Unfortunately, I had to turn off SSL authentication, as it wasn't working. Here is my configuration :&lt;/p&gt;

&lt;pre&gt;
$conf['auth']['serverType'] = 'imap';
$conf['auth']['imap_hosts'] = array( 'localhost:143' );
$conf['auth']['imap_type'] = 'imaptls';
$conf['auth']['imap_domain_name'] = 'example.com';&lt;/pre&gt;

&lt;p&gt;Don't forget to set yourself &quot;super&quot; :&lt;/p&gt;

&lt;pre&gt;
$conf['auth']['s_admins'] = array ('me@example.com');&lt;/pre&gt;

&lt;p&gt;And to set your web uri :&lt;/p&gt;

&lt;pre&gt;
$conf['app']['weburi'] = 'https://example.com/mailzu';&lt;/pre&gt;

&lt;h4&gt;6.4 Configure in-app release&lt;/h4&gt;

&lt;p&gt;Mailzu can also release quarantined mail. I did not implement this function, but you have to set up the amavisd-release internface on an inet socket on port 9998, instead of the existing unix socket located at &lt;strong&gt;/var/lib/amavis/amavisd.sock&lt;/strong&gt; . &lt;a href=&quot;https://www.ijs.si/software/amavisd/amavisd-new-docs.html#quar-release&quot;&gt;Read more&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;References&lt;/h3&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;http://www.iredmail.org/docs/amavisd.sql.db.html&quot;&gt;Explanation of Amavisd SQL database&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://blog.bravi.org/?p=683&quot;&gt;AMaViS: deal with SPAM, Viruses, Banned attachments, and Bad headers&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://www.ijs.si/software/amavisd/amavisd-new-docs.html#quarantine&quot;&gt;amavisd-new documentation bits and pieces&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://www.raygibson.net/kb/amavis/amavisd.conf&quot;&gt;amavis.conf&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://sourceforge.net/projects/mailzu/&quot;&gt;Mailzu&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://sourceforge.net/p/mailzu/patches/10/&quot;&gt;Mailzu patch for Amavis 2.7.0&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
        
          <enclosure url="/blog/public/code/sql/amavis_storage_partial_schema.sql" length="4518" type="application/octet-stream" />
        
              </item>
          <item>
        <title>Configurer dibbler-client pour IPv6 sur une Dedibox (Online.net) avec Debian 8 (Jessie)</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2015/10/21/Configurer-dibbler-client-pour-IPv6-sur-une-Dedibox-%28Online.net%29-avec-Debian-8-%28Jessie%29</link>
        <guid isPermaLink="false">urn:md5:68ab8bab67fba7928f19774250094c5e</guid>
        <pubDate>Wed, 21 Oct 2015 14:24:00 +0200</pubDate>
        <dc:creator>Mathieu</dc:creator>
                  <category>Hacks</category>
                          <category>debian</category>
                  <category>dedibox</category>
                  <category>dibbler</category>
                  <category>jessie</category>
                  <category>online</category>
                  <category>proxmox</category>
                  <category>server</category>
                <description>          &lt;p&gt;La documentation d&amp;#8217;Online pour IPv6 ne traite pas le cas de Debian, Ubuntu, ou toute distribution utilisant systemd (CentOS6, etc). La documention doit être étendue pour ajouter le service sysetmd au démarrage, en lieu et place de l&amp;#8217;init script.&lt;/p&gt;&lt;h3&gt;Vérifiez que l&amp;#8217;IPv6 est activé&lt;/h3&gt;&lt;p&gt;Cela devrait normalement être le cas, puisque le noyau par défaut de Debian 8 inclut nativement IPv6 et ne peut pas être désactivé. Mais au cas où vous ne verriez pas le link-local sur vos interfaces&amp;#160;:&lt;/p&gt;&lt;p&gt;Changer dans &lt;code&gt;/etc/modprobe.d/local.conf :&lt;/code&gt;&lt;/p&gt;&lt;pre&gt;options ipv6 disable=0&lt;/pre&gt;&lt;p&gt;Ajouter dans &lt;code&gt;/etc/modules :&lt;/code&gt;&lt;/p&gt;&lt;pre&gt;ipv6&lt;/pre&gt;&lt;p&gt;Il faudra sans doute redémarrer pour appliquer les changments.&lt;/p&gt;&lt;h3&gt;Récupérez votre préfixe et votre DUID depuis la console d&amp;#8217;Online&lt;/h3&gt;&lt;p&gt;Vous devez &lt;a href=&quot;https://console.online.net/fr/assistance/ticket/list&quot;&gt;demander l&amp;#8217;activation de IPv6 au support&lt;/a&gt; et créer votre /64&amp;#160;&lt;a href=&quot;https://console.online.net/fr/network/&quot;&gt;dans la console d&amp;#8217;Online&lt;/a&gt; pour obtenir votre DUID.&lt;/p&gt;&lt;p&gt;Créez un /64 et n&amp;#8217;utilisez pas le /48 ou le 56 directement, vous pourriez le regretter si vous souhaitez redécouper le réseau. Vous n&amp;#8217;avez qu&amp;#8217;un seul /48 par compte, un /56 pour chaque serveur, et un /64 pour chaque failover souscrit.&lt;/p&gt;&lt;h3&gt;Configurez l&amp;#8217;interface réseau&lt;/h3&gt;&lt;p&gt;Encore une fois, c&amp;#8217;est sans doute facultatif puisque Dibbler reconfigure l&amp;#8217;interface lorsqu&amp;#8217;il se lance, donc explicitons ça dans le fichier &lt;strong&gt;/etc/network/interfaces&lt;/strong&gt;, juste au cas où&amp;#160;:&lt;/p&gt;&lt;pre&gt;iface eth0 inet6 static
    address your_ipv6_address
    netmask 64
&amp;nbsp;&amp;nbsp; &amp;nbsp;accept_ra 2
&lt;/pre&gt;&lt;h3&gt;Notes sur Proxmox et le forwarding&lt;/h3&gt;&lt;p&gt;Sous Proxmox on travaille sur l&amp;#8217;interface bridge, c&amp;#8217;est &lt;strong&gt;vmbr0&lt;/strong&gt; et non pas eth0.&lt;/p&gt;&lt;p&gt;Si le forwarding est activé, vous devez forcer le &lt;strong&gt;accept_ra&lt;/strong&gt; à &lt;strong&gt;2&lt;/strong&gt;, une valeur de 1 fera ignorer les router advertisements lorsque le forwarding est activé. &lt;a href=&quot;http://www.mattb.net.nz/blog/2011/05/12/linux-ignores-ipv6-router-advertisements-when-forwarding-is-enabled/&quot;&gt;Explications&lt;/a&gt;. Ajoutez dans sysctl.conf&amp;#160;:&lt;/p&gt;&lt;pre&gt;net.ipv6.conf.vmbr0.accept_ra = 2&lt;/pre&gt;&lt;p&gt;Notez bien que dans le cas où vous adressez vos machines virtuelles en IPv6 vous ne &lt;strong&gt;devez pas brancher l&amp;#8217;interface IPv6 de vos VM directement sur l&amp;#8217;interface vmbr0&lt;/strong&gt;. &lt;a href=&quot;https://forum.online.net/index.php?/topic/5380-configuring-ipv6-in-proxmox-on-dedibox-from-onlinenet/&quot;&gt;Voilà pourquoi&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Compilez et installez Dibbler&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Téléchargez &lt;a href=&quot;http://klub.com.pl/dhcpv6/dibbler/dibbler-1.0.1.tar.gz&quot;&gt;Dibbler 1.0.1&lt;/a&gt; à partir du &lt;a href=&quot;http://klub.com.pl/dhcpv6/#DOWNLOAD&quot;&gt;site officiel&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Installez build-essential&amp;#160;: &lt;code&gt;apt-get install build-essential&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Décompressez Dibbler&amp;#160;: &lt;code&gt;tar -xzf dibbler-1.0.1.tar.gz &amp;amp;&amp;amp; cd dibbler-1.0.1&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Compilez et installez Dibbler&amp;#160;: &lt;code&gt;./configure &amp;amp;&amp;amp; ./make&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Configurez Dibbler&lt;/h3&gt;&lt;p&gt;Créez les dossiers et fichiers de configuration comme le précise la documentation&amp;#160;:&lt;/p&gt;&lt;p&gt;Configurez le DUID dans &lt;strong&gt;/var/lib/dibbler/client-duid&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;mkdir /var/lib/dibbler/
touch /var/lib/dibbler/client-duid
chmod 640 /var/lib/client-duid
# Set up you duid in client-duid
vim /var/lib/client-duid
&lt;/pre&gt;&lt;p&gt;Configurez &lt;strong&gt;/etc/dibbler/client.conf&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;mkdir /etc/dibbler
vim /etc/dibbler/client.conf&lt;/pre&gt;&lt;p&gt;Voici le contenu de mon &lt;strong&gt;client.conf&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;auth-protocol reconfigure-key
auth-replay monotonic
auth-methods digest-hmac-md5
duid-type duid-ll
inactive-mode
log-level 8
iface eth0 {
    pd
    ia
}
&lt;/pre&gt;&lt;p&gt;Encore une fois, c&amp;#8217;est à adapter en fonction du nom de votre interface.&lt;/p&gt;&lt;p&gt;Démarrez le client pour tester la connectivité&amp;#160;:&lt;/p&gt;&lt;pre&gt;dibbler-client run&lt;/pre&gt;&lt;p&gt;Pour vérifier que Dibbler a configuré l&amp;#8217;interface, pressez CTRL+Z pour suspendre le processus et vérifiez que l&amp;#8217;IP et les routes sont bien configurées. Tapez la commande &amp;#8220;fg&amp;#8221; pour retourner au processus en cours d&amp;#8217;exécution, et tapez CTRL+C pour stopper Dibbler.&lt;/p&gt;&lt;p&gt;Si pendant l&amp;#8217;opération les routes et les IPs sont incorrectes, vérifiez que votre pare feu accepte les connexions entrantes par le port 546 UDP.&lt;/p&gt;&lt;h3&gt;Configurez Dibbler au démarrage&lt;/h3&gt;&lt;p&gt;Cette section est différente de la documentation d&amp;#8217;Online.&lt;/p&gt;&lt;p&gt;Avant systemd, le système d&amp;#8217;init par dépendances se contentait d&amp;#8217;un script dans /etc/init.d/. Avec systemd, il faut créer un fichier &lt;strong&gt;service&lt;/strong&gt; dans &lt;strong&gt;/etc/systemd/system/&lt;/strong&gt; .&lt;/p&gt;&lt;p&gt;Créez le fichier suivant&amp;#160;: &lt;strong&gt;/etc/systemd/system/dibbler.service&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;[Unit]
Description=Dibbler
After=network.target

[Service]
Type=simple
ExecStart=/usr/local/sbin/dibbler-client start
ExecStop=/usr/local/sbin/dibbler-client stop
PrivateTmp=true
NonBlocking=yes

[Install]
WantedBy=multi-user.target&lt;/pre&gt;&lt;p&gt;Lancez la commande suivante pour que systemd lise le fichier&amp;nbsp;&amp;#160;:&lt;/p&gt;&lt;pre&gt;systemctl daemon-reload&lt;/pre&gt;&lt;p&gt;Et activez le service&amp;#160;:&lt;/p&gt;&lt;pre&gt;systemctl enable dibbler.service&lt;/pre&gt;&lt;p&gt;Et essayez de le lancer pour la première fois&amp;#160;:&lt;/p&gt;&lt;pre&gt;systemctl start dibbler.service&lt;/pre&gt;&lt;p&gt;Vérifions que tout est correct&amp;#160;:&lt;/p&gt;&lt;pre&gt;service dibbler status
ifconfig
route -6
ping6 whatever-you-want.com&lt;/pre&gt;&lt;p&gt;Si tout va bien, redémarrez et l&amp;#8217;IPv6 fonctionnera dès le démarrage&amp;#160;! &lt;img src=&quot;/blog/themes/mathedit_material3/smilies/smile.png&quot; alt=&quot;:)&quot; class=&quot;smiley&quot;&gt;&lt;/p&gt;&lt;p&gt;Addendum&amp;#160;: juste au cas où, n&amp;#8217;utilisez pas resolvconf pour pousser les DNS IPv6 automatiquement, conservez autant que possible vos DNS IPv4. Ça serait tellement dommage que votre connectivité IPv6 saute et que vous vous retrouviez sans DNS (oui ça m&amp;#8217;est arrivé&amp;#8230;).&lt;/p&gt;&lt;h3&gt;Sources&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://documentation.online.net/en/serveur-dedie/reseau/ipv6-prefix&quot;&gt;http://documentation.online.net/en/serveur-dedie/reseau/ipv6-prefix&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.lowendtalk.com/discussion/48591/configuring-ipv6-for-proxmox-kvm-on-dedibox-online-net&quot;&gt;http://www.lowendtalk.com/discussion/48591/configuring-ipv6-for-proxmox-kvm-on-dedibox-online-net&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://unix.stackexchange.com/questions/47695/how-to-write-startup-script-for-systemd&quot;&gt;http://unix.stackexchange.com/questions/47695/how-to-write-startup-script-for-systemd&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://sulek.fr/index.php?article60/configuration-ipv6-pour-une-dedibox-sous-centos-7&quot;&gt;https://sulek.fr/index.php?article60/configuration-ipv6-pour-une-dedibox-sous-centos-7&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.mattb.net.nz/blog/2011/05/12/linux-ignores-ipv6-router-advertisements-when-forwarding-is-enabled/&quot;&gt;http://www.mattb.net.nz/blog/2011/05/12/linux-ignores-ipv6-router-advertisements-when-forwarding-is-enabled/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://forum.online.net/index.php?/topic/5380-configuring-ipv6-in-proxmox-on-dedibox-from-onlinenet/&quot;&gt;https://forum.online.net/index.php?/topic/5380-configuring-ipv6-in-proxmox-on-dedibox-from-onlinenet/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
        
              </item>
          <item>
        <title>Configure dibbler-client for IPV6 networking on Dedibox (or any Online.net) servers with Debian 8 (Jessie)</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2015/10/21/Configure-dibbler-for-IPV6-networking-on-Dedibox-%28or-any-Online.net%29-servers-with-Debian-8-%28Jessie%29</link>
        <guid isPermaLink="false">urn:md5:cf27b5e56650bb4963d6a1f71966a199</guid>
        <pubDate>Wed, 21 Oct 2015 12:50:00 +0200</pubDate>
        <dc:creator>Mathieu</dc:creator>
                  <category>Hacks</category>
                          <category>debian</category>
                  <category>dedibox</category>
                  <category>dibbler</category>
                  <category>jessie</category>
                  <category>online</category>
                  <category>proxmox</category>
                  <category>server</category>
                <description>          &lt;p&gt;The &lt;a href=&quot;http://documentation.online.net/en/serveur-dedie/reseau/ipv6-prefix&quot;&gt;Online documentation for IPv6&lt;/a&gt; is not dealing with the case of Debian 8, Ubuntu, or any distribution using systemd. Systemd replaces upstart, so the procedure has to be extended to add systemd service for startup, replacing the previoux behavior that was using init scripts.&lt;/p&gt;&lt;h3&gt;Ensure that you are IPv6-proof&lt;/h3&gt;&lt;p&gt;It should be the case as Debian 8 is shipping a kernel with native IPv6, but just to be sure&amp;#160;:&lt;/p&gt;&lt;p&gt;In &lt;code&gt;/etc/modprobe.d/local.conf :&lt;/code&gt;&lt;/p&gt;&lt;pre&gt;options ipv6 disable=0&lt;/pre&gt;&lt;p&gt;In &lt;code&gt;/etc/modules :&lt;/code&gt;&lt;/p&gt;&lt;pre&gt;ipv6&lt;/pre&gt;&lt;p&gt;You may have to reboot in order to apply the changes.&lt;/p&gt;&lt;h3&gt;Set up your IPv6 prefix and get your DUID on Online console&lt;/h3&gt;&lt;p&gt;You have to &lt;a href=&quot;https://console.online.net/fr/assistance/ticket/list&quot;&gt;request IPv6 activation to support&lt;/a&gt; and create your /64&amp;#160;&lt;a href=&quot;https://console.online.net/fr/network/&quot;&gt;on Online console&lt;/a&gt; before getting your DUID working.&lt;/p&gt;&lt;p&gt;Make a /64 and do not use your /48 or your /56 directly, as you may regret it. You can have only one /48 by account, one /56 by server, and one /64 by IP failover (the /48 is divided to make the /56 and so on).&lt;/p&gt;&lt;h3&gt;Configure your network interface&lt;/h3&gt;&lt;p&gt;It may not be mandatory as Dibbler will reconfigure your interface, but you have to ensure that you accept router advertisements. Add to &lt;strong&gt;/etc/network/interfaces&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;iface eth0 inet6 static
    address your_ipv6_address
    netmask 64
&amp;nbsp;&amp;nbsp; &amp;nbsp;accept_ra 2
&lt;/pre&gt;&lt;h3&gt;Notes about Proxmox and forwarding&lt;/h3&gt;&lt;p&gt;On Proxmox, you are working on the bridge interface, it should be &lt;strong&gt;vmbr0&lt;/strong&gt; instead of eth0.&lt;/p&gt;&lt;p&gt;If you enabled forwarding on this interface (to give your VM an access to IPv6 network), you have to force the &lt;strong&gt;accept_ra&lt;/strong&gt; to &lt;strong&gt;2&lt;/strong&gt;, while the default value of 1 wil make your Debian to ignore router advertisements when forwarding is enabled&amp;#160;! &lt;a href=&quot;http://www.mattb.net.nz/blog/2011/05/12/linux-ignores-ipv6-router-advertisements-when-forwarding-is-enabled/&quot;&gt;Read more&lt;/a&gt;. Add to sysctl.conf&amp;#160;:&lt;/p&gt;&lt;pre&gt;net.ipv6.conf.vmbr0.accept_ra = 2&lt;/pre&gt;&lt;p&gt;Also &lt;strong&gt;do not set the IPv6 interface of your VM to vmbr0&lt;/strong&gt;, as you can break your network access. &lt;a href=&quot;https://forum.online.net/index.php?/topic/5380-configuring-ipv6-in-proxmox-on-dedibox-from-onlinenet/&quot;&gt;Read more&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Compile and install Dibbler&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Download &lt;a href=&quot;http://klub.com.pl/dhcpv6/dibbler/dibbler-1.0.1.tar.gz&quot;&gt;Dibbler 1.0.1&lt;/a&gt; from the &lt;a href=&quot;http://klub.com.pl/dhcpv6/#DOWNLOAD&quot;&gt;offical website&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Install build-essential&amp;#160;: &lt;code&gt;apt-get install build-essential&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Extract Dibbler&amp;#160;: &lt;code&gt;tar -xzf dibbler-1.0.1.tar.gz &amp;amp;&amp;amp; cd dibbler-1.0.1&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Compile and install Dibbler&amp;#160;: &lt;code&gt;./configure &amp;amp;&amp;amp; ./make&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Configure Dibbler&lt;/h3&gt;&lt;p&gt;Make the directories and set up according to the documentation&amp;#160;:&lt;/p&gt;&lt;p&gt;Set up duid&amp;#160;:&lt;/p&gt;&lt;pre&gt;mkdir /var/lib/dibbler/
touch /var/lib/dibbler/client-duid
chmod 640 /var/lib/client-duid
# Set up you duid in client-duid
vim /var/lib/client-duid
&lt;/pre&gt;&lt;p&gt;Set up client.conf&amp;#160;:&lt;/p&gt;&lt;pre&gt;mkdir /etc/dibbler
vim /etc/dibbler/client.conf&lt;/pre&gt;&lt;p&gt;The content of my client.conf&amp;#160;:&lt;/p&gt;&lt;pre&gt;auth-protocol reconfigure-key
auth-replay monotonic
auth-methods digest-hmac-md5
duid-type duid-ll
inactive-mode
log-level 8
iface eth0 {
    pd
    ia
}
&lt;/pre&gt;&lt;p&gt;Note that if your interface name is different you have to change it accordingly. For instance, on a Proxmox host server, it should be &lt;strong&gt;vmbr0&lt;/strong&gt; instead of eth0.&lt;/p&gt;&lt;p&gt;Start dibbler to try the connectivity&amp;#160;:&lt;/p&gt;&lt;pre&gt;dibbler-client run&lt;/pre&gt;&lt;p&gt;Hit CTRL+Z to suspend the process and check that the IP and routes are configured. Type the command &amp;#8220;fg&amp;#8221; to get back to the running process and hit CTRL+C to stop it.&lt;/p&gt;&lt;p&gt;If it doesn&amp;#8217;t work, check your firewall, dibbler needs to listen port 546 UDP.&lt;/p&gt;&lt;h3&gt;Set Dibbler at startup&lt;/h3&gt;&lt;p&gt;This section differs from Online documentation.&lt;/p&gt;&lt;p&gt;Before systemd, the dependency-based boot sequence only needed an init script, for instance /etc/init.d/dibbler . With systemd, you have to make a &lt;strong&gt;service&lt;/strong&gt; file in &lt;strong&gt;/etc/systemd/system/&lt;/strong&gt; .&lt;/p&gt;&lt;p&gt;Make the following file&amp;#160;: &lt;strong&gt;/etc/systemd/system/dibbler.service&lt;/strong&gt;&amp;#160;:&lt;/p&gt;&lt;pre&gt;[Unit]
Description=Dibbler
After=network.target

[Service]
Type=simple
ExecStart=/usr/local/sbin/dibbler-client start
ExecStop=/usr/local/sbin/dibbler-client stop
PrivateTmp=true
NonBlocking=yes

[Install]
WantedBy=multi-user.target&lt;/pre&gt;&lt;p&gt;Run the following command to make systemd read file&amp;#160;:&lt;/p&gt;&lt;pre&gt;systemctl daemon-reload&lt;/pre&gt;&lt;p&gt;Enable the service&amp;#160;:&lt;/p&gt;&lt;pre&gt;systemctl enable dibbler.service&lt;/pre&gt;&lt;p&gt;And then, try to start it&amp;#160;:&lt;/p&gt;&lt;pre&gt;systemctl start dibbler.service&lt;/pre&gt;&lt;p&gt;Check everything is fine&amp;#160;:&lt;/p&gt;&lt;pre&gt;service dibbler status
ifconfig
route -6
ping6 whatever-you-want.com&lt;/pre&gt;&lt;p&gt;Reboot and the IPv6 networking should work at startup&amp;#160;! &lt;img src=&quot;/blog/themes/mathedit_material3/smilies/smile.png&quot; alt=&quot;:)&quot; class=&quot;smiley&quot;&gt;&lt;/p&gt;&lt;p&gt;Addendum&amp;#160;: just in case, don&amp;#8217;t use resolvconf with IPv6 DNS pushing and if possible keep IPv4 DNS, it would be such a pity if the IPv6 networking crashes while your DNS servers are set to IPv6 addresses (yeah, it happened to to me)&amp;#8230;&lt;/p&gt;&lt;h3&gt;Sources&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://documentation.online.net/en/serveur-dedie/reseau/ipv6-prefix&quot;&gt;http://documentation.online.net/en/serveur-dedie/reseau/ipv6-prefix&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.lowendtalk.com/discussion/48591/configuring-ipv6-for-proxmox-kvm-on-dedibox-online-net&quot;&gt;http://www.lowendtalk.com/discussion/48591/configuring-ipv6-for-proxmox-kvm-on-dedibox-online-net&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://unix.stackexchange.com/questions/47695/how-to-write-startup-script-for-systemd&quot;&gt;http://unix.stackexchange.com/questions/47695/how-to-write-startup-script-for-systemd&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://sulek.fr/index.php?article60/configuration-ipv6-pour-une-dedibox-sous-centos-7&quot;&gt;https://sulek.fr/index.php?article60/configuration-ipv6-pour-une-dedibox-sous-centos-7&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.mattb.net.nz/blog/2011/05/12/linux-ignores-ipv6-router-advertisements-when-forwarding-is-enabled/&quot;&gt;http://www.mattb.net.nz/blog/2011/05/12/linux-ignores-ipv6-router-advertisements-when-forwarding-is-enabled/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://forum.online.net/index.php?/topic/5380-configuring-ipv6-in-proxmox-on-dedibox-from-onlinenet/&quot;&gt;https://forum.online.net/index.php?/topic/5380-configuring-ipv6-in-proxmox-on-dedibox-from-onlinenet/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
        
              </item>
          <item>
        <title>Migrate an OpenVPN configuration to Debian 8 (Jessie) with systemd</title>
        <link>https://uname.pingveno.net/blog/index.php/post/2015/05/23/Migrate-an-OpenVPN-configuration-to-Debian-8-%28Jessie%29-with-systemd</link>
        <guid isPermaLink="false">urn:md5:a60d9b9041f53247753bbe51ac24a8c0</guid>
        <pubDate>Sat, 23 May 2015 10:32:00 +0200</pubDate>
        <dc:creator>Mathieu</dc:creator>
                  <category>Hacks</category>
                          <category>debian</category>
                  <category>jessie</category>
                  <category>openvpn</category>
                  <category>systemd</category>
                <description>          &lt;p&gt;This article could have been avoided if the Debian documentation was up-to-date. Actually it is not, and the solution came from Fedora documentation for OpenVPN.&lt;/p&gt;

&lt;p&gt;Debian 8 uses systemd by default, and it implies several changes, in&amp;nbsp; particular the way you start/stop your services.&lt;/p&gt;

&lt;h3&gt;The main topic : systemd&lt;/h3&gt;

&lt;h4&gt;What changes&lt;/h4&gt;

&lt;ul&gt;
	&lt;li&gt;
	&lt;p&gt;A new fancy command now manage the startup : &lt;strong&gt;systemctl&lt;/strong&gt; (don't mess with the &lt;strong&gt;sysctl&lt;/strong&gt; command used for network configuration !)&lt;/p&gt;
	&lt;/li&gt;
	&lt;li&gt;
	&lt;p&gt;The startup dependencies are no longer in the LSB headers in startup scripts (way too simple, boy), the dependencies are stored as symlinks in subdirectories located in &lt;strong&gt;/etc/systemd/*&lt;/strong&gt; . Note that &lt;strong&gt;/etc/systemd/&lt;/strong&gt; contains some static configuration files, and that the real services configuration files are stored in &lt;strong&gt;/lib/systemd/*&lt;/strong&gt; (this is where the symlinks from &lt;strong&gt;/etc/systemd/*&lt;/strong&gt; points to).&lt;/p&gt;
	&lt;/li&gt;
	&lt;li&gt;
	&lt;p&gt;&lt;strong&gt;Some services have been split from monolithic startup to dynamic&lt;/strong&gt;. It means that you potentially have to enable and run multiple &quot;services&quot; in order to actually start the full &quot;service&quot;. For instance, &lt;strong&gt;OpenVPN no longer runs every available configuration in /etc/openvpn/*.conf , you have to explicitely activate each *.conf file as a service in systemd !&lt;/strong&gt;&lt;/p&gt;
	&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;What doesn't change&lt;/h4&gt;

&lt;ul&gt;
	&lt;li&gt;
	&lt;p&gt;You can still start your services with &lt;strong&gt;service &lt;em&gt;servicename&lt;/em&gt; start&lt;/strong&gt;.&lt;/p&gt;
	&lt;/li&gt;
	&lt;li&gt;
	&lt;p&gt;The init scripts in &lt;strong&gt;/etc/init.d/*&lt;/strong&gt; still exists, and some are still usable (monolithics services).&lt;/p&gt;
	&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Run your OpenVPN configuration&lt;/h3&gt;

&lt;p&gt;While you can still use the command &lt;strong&gt;openvpn --config /etc/openvpn/yourconfigfile.conf&lt;/strong&gt;, you should do it with systemd. If your configuration file is /etc/openvpn/sample.conf, you should start your VPN connexion with &lt;strong&gt;systemctl start openvpn@sample.service&lt;/strong&gt; .&lt;/p&gt;

&lt;p&gt;Note that &lt;strong&gt;service openvpn@sample start&lt;/strong&gt; also works.&lt;/p&gt;

&lt;h3&gt;Start your VPN at boot&lt;/h3&gt;

&lt;p&gt;Again, the auto startup was too simple. You now have to enable every *.conf file at boot. Enable you newly sample.conf at startup with the command &lt;strong&gt;systemctl enable openvpn@sample.service&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This actually creates a symlink in &lt;strong&gt;/etc/systemd/system/multi-user.target.wants/openvpn@sample.service&lt;/strong&gt; pointing to &lt;strong&gt;/lib/systemd/system/openvpn@.service&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Ok, it's simpler for dynamic loads, but who needs to dynamically enable and disable configuration at boot ? If I want a different configuration, I simply write different files in the right folder...&lt;/p&gt;

&lt;h3&gt;Meanwhile, in Debian Apache package&lt;/h3&gt;

&lt;p&gt;You can enable and disable VirtualHosts by using the /etc/apache2/sites-available/ and /etc/apache2/sites-enabled/ folders. No hidden features, no boot startup configuration, all configuration files in /etc/programname/ . Way too simple ?&lt;/p&gt;

&lt;p&gt;Hey, what if we had to configure a startup script for every VirtualHost ? Should be fun, don't you think ?&lt;/p&gt;

&lt;h3&gt;Sources&lt;/h3&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;https://fedoraproject.org/wiki/Openvpn#Working_with_systemd&quot; hreflang=&quot;en&quot;&gt;OpenVPN : working with systemd [Fedora wiki]&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://fedoraproject.org/wiki/Systemd#How_do_I_start.2Fstop_or_enable.2Fdisable_services.3F&quot; hreflang=&quot;en&quot;&gt;Systemd : how to enable and start services [Fedora wiki]&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
        
              </item>
      </channel>
</rss>
