TLS: letsencrypt DNS-01 via Dynadot hook; fail2ban ignoreip guard (#114)
- scripts/dynadot-dns.sh: DNS-01 hook (snapshot -> append TXT -> restore); set_dns2 wants lowercase record types, ResponseCode checks on deploy/clean - compose: SSL_TYPE=letsencrypt, mount tls/letsencrypt/<domain> -> /etc/letsencrypt/live/<domain>; drop-in jail.d/ignoreip.local so the postfix jail can't ban the docker bridge gateway (host self-DoS) - cert issued for mail.produktor.io (Let's Encrypt, ECDSA); renewal via acme.sh cron + reloadcmd (postfix/dovecot reload)
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
# Host-originated connections reach postfix/dovecot via the docker bridge
|
||||
# gateway. Without ignoring it, the postfix jail bans our own host as
|
||||
# collateral of port-25 scanner noise + local TLS probes (self-DoS: host
|
||||
# submission times out). Keep in sync with the compose network subnet.
|
||||
[DEFAULT]
|
||||
ignoreip = 127.0.0.1/8 192.168.32.0/24 192.168.1.0/24
|
||||
Reference in New Issue
Block a user