User Tools

Site Tools


This is an old revision of the document!

Bock 2018

Base system information

  • VPS @Omnitec, 2CPU, 2GB, 100GB
  • Base IP:

Operating system installation

Source media or media image

Installation method

Installation options selected

Critical Services

  • Telnet client for testing
  • Web - php, php-mysql, mb, php-imap; split vhost logs
  • DNS
  • Lists


master DNS zone but Bud will be in public zone transfer service to Bind from ?



Completed 180627

* Finished mysql configuration of postfix * Connected smtp & smtpd to wildcard cert * Disabled postgrey * All other filters already disabled


* Setup and enable postgrey * Setup and enable SpamAssassin or rspamd * Setup and enable clamav * Setup and enable Amavisd?

* Change PLAIN login method to TLS??

  (require TLS connection before sending password)


Apache configuration

a2enmod ssl.load a2enmod info

Let's Encrypt

  • certbot from github is curreent, required for wildcard certs
  • Install requires dev libraries for headers:
    • aptitude install python2.7-dev
    • aptitude install libffi-dev
    • aptitude install libssl-dev
  • Setup:

python install

  • Generate:

certbot certonly –manual -d * –agree-tos –no-bootstrap –manual-public-ip-logging-ok –preferred-challenges dns-01 –server

  • Result: (If someone can figure out how to force plain text, please fix!!)

Please deploy a DNS TXT record under the name with the following value: EGAoTq2e_Cf8TwYV4EN7zBLNfdgHodgoy9yX_WaLrGY IMPORTANT NOTES: - Congratulations! Your certificate and chain have been saved at: /etc/letsencrypt/live/ Your key file has been saved at: /etc/letsencrypt/live/ Your cert will expire on 2018-09-18. To obtain a new or tweaked version of this certificate in the future, simply run certbot again. To non-interactively renew *all* of your certificates, run "certbot renew" - Your account credentials have been saved in your Certbot configuration directory at /etc/letsencrypt. You should make a secure backup of this folder now. This configuration directory will also contain certificates and private keys obtained by Certbot so making regular backups of this folder is ideal. - If you like Certbot, please consider supporting our work by: Donating to ISRG / Let's Encrypt: Donating to EFF: </nowiki>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please deploy a DNS TXT record under the name with the following value: EGAoTq2e_Cf8TwYV4EN7zBLNfdgHodgoy9yX_WaLrGY Before continuing, verify the record is deployed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Press Enter to Continue Waiting for verification… Cleaning up challenges IMPORTANT NOTES: - Congratulations! Your certificate and chain have been saved at: /etc/letsencrypt/live/ Your key file has been saved at: /etc/letsencrypt/live/ Your cert will expire on 2018-09-18. To obtain a new or tweaked version of this certificate in the future, simply run certbot again. To non-interactively renew *all* of your certificates, run "certbot renew" - Your account credentials have been saved in your Certbot configuration directory at /etc/letsencrypt. You should make a secure backup of this folder now. This configuration directory will also contain certificates and private keys obtained by Certbot so making regular backups of this folder is ideal. - If you like Certbot, please consider supporting our work by: Donating to ISRG / Let's Encrypt: Donating to EFF:

Misc packages installed

lynx lynx-cur

  This also installed:  lynx-common



This also installed: libgmime-2.6-0 libgpgme11 libnotmuch4 libtalloc2 libtokyocabinet9




Not listed here

For a list of installed packages and when, a good resource is /var/log/apt/history.log*

Misc configuration

Documentation /usr/source/Docuwiki

Edit /etc/ssh/sshd_config to change PermitRootLogin value from yes to forced-commands-only.

Add all users in the sudo group to the adm and systemd-journal groups to allow them to see logs without being root. See

amber_replacment.1530155165.txt.gz · Last modified: 2018/06/27 22:06 by SLUUG Administration