63 Commits

Author SHA1 Message Date
Tommy
11189cffe7
Proper permission policies for WebAuthn
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 07:30:24 -07:00
Tommy
85ce409081
Remove publickey-credentials-get=()
FIDO2 is used almost everywhere now

Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 07:27:04 -07:00
Tommy
59f31c32c6
Add server_token.conf to setup script 2024-10-13 05:52:20 -07:00
Tommy
9d671fb07e
Disable server_tokens 2024-10-13 05:49:48 -07:00
Tommy
1678b0861d
Hide X-Powered-By 2024-10-13 05:15:14 -07:00
Tommy
89b35004f2
Remove unmaintained sample 2024-10-13 05:12:17 -07:00
Tommy
fd996d1a02
Remove unnecessary comment 2024-10-13 03:41:17 -07:00
Tommy
c374b5ef86
Fix listen directives 2024-10-13 03:32:03 -07:00
Tommy
d938584c21
Add vaultwarden 2024-10-13 03:30:33 -07:00
Tommy
2db0611650
Add Nextcloud 2024-10-13 03:27:54 -07:00
Tommy
95881525c4
Avoid confusion with proxy_pass 2024-10-13 02:59:28 -07:00
Tommy
3bbe3ea3a3
Use http_host for Host
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 01:26:11 -07:00
Tommy
673f533643
Add extra headers
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 01:25:32 -07:00
Tommy
7036022071
Use http_host
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-12 23:54:54 -07:00
Tommy
3833fd16eb
Remove unnecessary OCSP stapling config
Signed-off-by: Tommy <contact@tommytran.io>
2024-09-26 07:26:02 -07:00
Tommy
d2ea15b130
Add permission control for workflow
Signed-off-by: Tommy <contact@tommytran.io>
2024-09-10 16:16:01 -07:00
Tommy
d8addd4d0c
Update README.md
Signed-off-by: Tommy <contact@tommytran.io>
2024-09-04 15:00:07 -07:00
Tommy
2a014e53ba
Remove no longer accurate comment
Signed-off-by: Tommy <contact@tommytran.io>
2024-08-30 10:53:32 -07:00
Tommy
d1a5f7766d
Fix restorecon not being on new line
Signed-off-by: Tommy <contact@tommytran.io>
2024-08-30 10:49:29 -07:00
Tommy
37d8caf409
Typo Fix
Signed-off-by: Tommy <contact@tommytran.io>
2024-08-27 09:00:51 -07:00
Tommy
6b49097447
Typo Fix 2024-08-01 18:59:24 -07:00
Tommy
4874077871
Update comments
Signed-off-by: Tommy <contact@tommytran.io>
2024-08-01 13:56:09 -07:00
Tommy
8689195fdb
Add missing sudo
Signed-off-by: Tommy <contact@tommytran.io>
2024-08-01 13:22:24 -07:00
Tommy
b6482df91f
Support non ip pinning setups
Signed-off-by: Tommy <contact@tommytran.io>
2024-07-27 15:05:37 -07:00
Tommy
c4014dc57e
Suppress curl output 2024-07-26 07:43:35 -07:00
Tommy
239bc633c1
Upload nginx-create-session-ticket-keys-ramfs script for RHEL 2024-07-26 07:40:00 -07:00
Tommy
7e75518a8b
Clean up setup.sh 2024-07-26 07:26:15 -07:00
Tommy
470bb0ea04
RHEL is supported 2024-07-26 07:25:58 -07:00
Tommy
4e61156e94
Fix certbot-renew override 2024-07-26 07:16:18 -07:00
Tommy
b5494ec13b
Remove certbot OCSP fetcher service 2024-07-26 07:15:11 -07:00
Tommy
93f2f91f96
Fix SC2046
Signed-off-by: Tommy <contact@tommytran.io>
2024-07-26 07:07:43 -07:00
Tommy
eb39ad2f39
Use realpath for interoperability 2024-07-26 07:04:05 -07:00
Tommy
faa35bf11b
Remove OCSP stapling
https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html
2024-07-26 06:52:58 -07:00
Tommy
6e6b7c3c16
Typo Fix
Signed-off-by: Tommy <contact@tommytran.io>
2024-07-26 06:41:36 -07:00
Tommy
95357339af
Add set -u
Signed-off-by: Tommy <contact@tommytran.io>
2024-07-20 18:19:34 -07:00
Tommy
c2e70d17ee
Add set -e
Signed-off-by: Tommy <contact@tommytran.io>
2024-07-05 08:38:51 -07:00
Tommy
b6e13fadb8
Remove restorecon on certbot certonly 2024-07-03 19:09:34 -07:00
Tommy
07f2cb7a02
Certbot OCSP fetcher changes have been upstreamed
Signed-off-by: Tommy <contact@tommytran.io>
2024-06-30 12:46:02 -07:00
Tommy
5a3ac8cbd7
Miniflux needs form-action 'self'
Signed-off-by: Tommy <contact@tommytran.io>
2024-06-30 12:37:44 -07:00
Tommy
ab5fb14232
SELinux support for certbot-ocsp-fetcher
Signed-off-by: Tommy <contact@tommytran.io>
2024-06-29 17:53:27 -07:00
Tommy
b5a6386526
Reorganize Miniflux CSP
Signed-off-by: Tommy <contact@tommytran.io>
2024-06-29 16:54:37 -07:00
Tommy
e48e0a1096
Add Miniflux 2024-06-29 14:59:18 -07:00
Tommy
616669f832
Put reuseport into the default site config 2024-06-29 14:56:28 -07:00
Tommy
dcd36c9051
Add sample configuration 2024-06-26 20:58:06 -07:00
Tommy
c09190f5be
Typo Fix 2024-06-26 14:41:06 -07:00
Tommy
7cfbc5abb8
Ensure correct permissions 2024-06-26 14:25:56 -07:00
Tommy
183e414e91
Add cross-origin-security to setup.sh
Signed-off-by: Tommy <contact@tommytran.io>
2024-06-26 12:26:22 -07:00
Tommy
08ce46c69e
Fix package name
Signed-off-by: Tommy <contact@tommytran.io>
2024-06-26 11:19:13 -07:00
Tommy
40089938a5
Use nginx-core instead of nginx
Signed-off-by: Tommy <contact@tommytran.io>
2024-06-26 11:18:15 -07:00
Tommy
1add9de088
Add missing execute permission 2024-06-26 11:17:23 -07:00