Re: TLS1.0 and 1.1 with Cyrus (Debian Buster)

2020-05-08 Thread Alberto Gonzalez Iniesta
gh > I think this setting is only for client programs like Curl. But seeing > that config I tend to think that Buster may have other tweaks against > older protocols like TLSv1.{0,1} and one of them may be impacting my setup. > > Cheers, > > -r > -- Alberto Gonzalez Iniesta

Re: ModSecurity Debian 8

2017-03-20 Thread Alberto Gonzalez Iniesta
enable modsecurity on my website > 4) Do you have sample config file to share? > Hi there, Debian's modsecurity packages will only work with Apache. In order to get modsecurity to work with nginx you'll have to re-compile nginx and modsecurity. This may help you: https://www.howtof

Re: OpenVPN DDoS Fix

2014-12-01 Thread Alberto Gonzalez Iniesta
ks. Since the test certs used to test the package build expired last week (...), new certs have to be generated, which makes the upgrade a bit more messy. Regards, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico mailto/sip: a...@inittab.org | en GNU/Linu

Re: about bash and Debian Lenny

2014-10-01 Thread Alberto Gonzalez Iniesta
us Lenny > package. Not "official", but from know source: http://ftp.linux.it/pub/People/md/bash/ -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico mailto/sip: a...@inittab.org | en GNU/Linux y software libre Encrypted mail preferred| http://inittab.com

Re: integrity checks and inodes

2011-01-22 Thread Alberto Gonzalez Iniesta
gt; At least with aide you can specify attributes which shall be ignored > from the final report (see ignore_list in aide.conf(5)). So can you with tripwire, and probably any other integrity checker. Otherwise they would be quite useless (warning you about any normal file activity).

Re: Mod-security status in Lenny / New bug...

2009-03-20 Thread Alberto Gonzalez Iniesta
on... ?) I don't think so. Lenny won't have official Debian packages apart from those on my site. Cheers, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred| ht

Re: mod_security (was: Apache "DDOS" with random number request)

2008-09-22 Thread Alberto Gonzalez Iniesta
g issue[1] is supposed to be over[2]? > > There is already an ITP bug, but I don't know the current status. > > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487431 > > Coming soon (tm) -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico a

Re: Find installed contrib and non-free packages

2008-06-12 Thread Alberto Gonzalez Iniesta
ard M. Stallman The vrms program will analyze the set of currently-installed packages on a Debian-based system, and report all of the packages from the non-free and contrib trees which are currently installed. Regards, Alberto -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte té

Re: [Pkg-openssl-devel] [SECURITY] [DSA 1571-1] New openssl packages fix predictable random number generator

2008-05-20 Thread Alberto Gonzalez Iniesta
On Tue, May 20, 2008 at 04:48:43PM +0200, Christoph Martin wrote: > Hi Alberto, > > Alberto Gonzalez Iniesta schrieb: > > On Mon, May 19, 2008 at 01:13:46PM +0200, Christoph Martin wrote: > >> The Ubuntu openssl maintainers released a openssl-blacklist equivalent >

Re: Plans to deploy openssl-blacklist in Debian? (was: Re: ssh-vulnkey and authorized_keys)

2008-05-16 Thread Alberto Gonzalez Iniesta
e f -name \*.key -exec openssl-vulnkey {} \; > > Speaking about that, are there plans to deploy > openssl-blacklist in Debian as an official package? Yes, I'll do that as part of the changes required in OpenVPN due to the OpenSSL bug. Coming shortly. -- Alberto Gonzal

Re: password managers

2004-06-15 Thread Alberto Gonzalez Iniesta
leWritePre*.asc \ '[,']!sh -c 'gpg --default-recipient-self -e -a 2>/dev/null' " Undo the encryption so we are back in the normal text, directly " after the file has been written. autocmd BufWritePost,FileWritePost *.gpg,*.as

Re: password managers

2004-06-15 Thread Alberto Gonzalez Iniesta
leWritePre*.asc \ '[,']!sh -c 'gpg --default-recipient-self -e -a 2>/dev/null' " Undo the encryption so we are back in the normal text, directly " after the file has been written. autocmd BufWritePost,FileWritePost *.gpg,*.asc

Re: restricting process limit

2004-04-28 Thread Alberto Gonzalez Iniesta
that spamassassin, but requires some training. What I don't really know is how effective it'll be on technical mailing lists (which receive mails with dumps, kernel confs, and other 'strange' content that may appear like anything but a 'normal' mail). -- Alberto Gonz

Re: restricting process limit

2004-04-28 Thread Alberto Gonzalez Iniesta
that spamassassin, but requires some training. What I don't really know is how effective it'll be on technical mailing lists (which receive mails with dumps, kernel confs, and other 'strange' content that may appear like anything but a 'normal' mail). -- Alberto Gonz

Re: Mailserver HDD organization

2002-01-17 Thread Alberto Gonzalez Iniesta
On Sun, Nov 25, 2001 at 11:04:45PM +0100, [EMAIL PROTECTED] wrote: > > please use qmail, its really the securest MTA you can get. > please use postfix, since it's as secure as qmail and has a better license -- Alberto Gonzalez Iniesta | They that give up essential liberty [E

Re: Mailserver HDD organization

2002-01-17 Thread Alberto Gonzalez Iniesta
On Sun, Nov 25, 2001 at 11:04:45PM +0100, [EMAIL PROTECTED] wrote: > > please use qmail, its really the securest MTA you can get. > please use postfix, since it's as secure as qmail and has a better license -- Alberto Gonzalez Iniesta | They that give up essential

Re: your mail

2001-09-15 Thread Alberto Gonzalez Iniesta
d & upgraded Also, if you think your machine was compromised, check for backdoors, modified binaries, etc... Changing passwords may not be enough -- Alberto Gonzalez Iniesta [EMAIL PROTECTED] Give Me Liberty or Give Me Death (Patrick Henry)

Re: your mail

2001-09-15 Thread Alberto Gonzalez Iniesta
d & upgraded Also, if you think your machine was compromised, check for backdoors, modified binaries, etc... Changing passwords may not be enough -- Alberto Gonzalez Iniesta [EMAIL PROTECTED] Give Me Liberty or Give Me Death (Patrick Henry) -- To UNSUBSCRIBE, email to [EMAIL PRO

Re: Virtual Networking between Debian and Microsoft Windows systems

2001-09-10 Thread Alberto Gonzalez Iniesta
I'll go for IPSec too (freeswan), but maybe PPTP is easier to configure. Have a look at: pptp-linux - PPTP Microsoft Compatible Tunneling Protocol pptpd - PoPToP Point to Point Tunneling Server Client and server for PPTP VPNs. Regards, Alberto -- Alberto Gonzalez Iniesta [EMAIL PROT

Re: Virtual Networking between Debian and Microsoft Windows systems

2001-09-10 Thread Alberto Gonzalez Iniesta
I'll go for IPSec too (freeswan), but maybe PPTP is easier to configure. Have a look at: pptp-linux - PPTP Microsoft Compatible Tunneling Protocol pptpd - PoPToP Point to Point Tunneling Server Client and server for PPTP VPNs. Regards, Alberto -- Alberto Gonzalez Iniesta [EMAIL PROT