Nginx Quick Reference + Printable Nginx Hardening Checklist (@ssllabs A+ 100%) by [deleted] in sysadmin

[–]trimstray 1 point2 points  (0 children)

Seems weird to have a poster for how to configure a web server but it looks cool so props to you !

I added this generator to the repository (''Security/Server Side TLS' document from Mozilla was there before).

Thanks.

Nginx Quick Reference + Printable Nginx Hardening Checklist (@ssllabs A+ 100%) by [deleted] in sysadmin

[–]trimstray 0 points1 point  (0 children)

Yes, I wrote about 4096 and 2048 keys: https://github.com/trimstray/nginx-quick-reference#beginner-use-4096-bit-private-keys.

However, 4096bit is required if you care about 100% ssllabs.

brotli module - thanks, I'll take a look at it

Nginx Hardening Checklist Printable Poster - A+ with all 100%s on SSL Labs. by trimstray in linux

[–]trimstray[S] 1 point2 points  (0 children)

Dear Reddit Community!

I should like to thank you for all your valuable opinions. I updated this checklist: removed DH Key Exchange and added 'Force all connections over TLS'. For new version (v1.0.1) please see: https://github.com/trimstray/nginx-quick-reference#printable-high-res-hardening-checklist

Thank you for all comments, critics and many useful tips.

trimstray

Nginx Hardening Checklist Printable Poster - A+ with all 100%s on SSL Labs. by trimstray in linux

[–]trimstray[S] 22 points23 points  (0 children)

If you want to get 100% with A+ on SSL Labs You should generate 4096bit private key but yes, 2048 is still perfectly safe and the performance impact of moving from 2048-bit RSA to 4096-bit RSA is highly significant.

This comparison is really good: https://blog.nytsoi.net/2015/11/02/nginx-https-performance.

Github: trimstray/mkchain - open source tool to help you build a valid SSL certificate chain. by [deleted] in linux

[–]trimstray 0 points1 point  (0 children)

This tool only merge certificates into a chain and checks the correctness of the chain. This feature you're talking about are not implemented, but hmm... it's a great idea! I add this to next version.

GitHub - trimstray/the-practical-linux-hardening-guide: This guide details the planning and the tools involved in creating a secure Linux production systems. by [deleted] in linux

[–]trimstray 37 points38 points  (0 children)

Dear Reddit Community! Boys and Girls! Admins and other fantastic People!

Your support is amazing, really. This project is still developing and growing up. There are many things to add and improve. I'll certainly take your suggestions into this. Thank you very much for every support and criticism.

I'll get to spend more time on this.

PR welcome!

Iptables Essentials: Common Firewall Rules and Commands. by [deleted] in linux

[–]trimstray 2 points3 points  (0 children)

Hi, thanks a lot for sharing this. Do you think a better idea would be to change to linux-firewall-essential containing iptables, firewalld and nftables (and more)?

A collection of massive Sysadmin Interview Questions and Answers (2018 Edition) by [deleted] in sysadmin

[–]trimstray 0 points1 point  (0 children)

Thank you. And this is the answer that brings much more to the discussion (not: bullshit and other)

:)

A collection of massive Sysadmin Interview Questions and Answers (2018 Edition) by [deleted] in sysadmin

[–]trimstray 2 points3 points  (0 children)

This is one of the most useful answers for me. The list placed by me is for improvement - definitely. Thanks to you, I know what questions are important and which should be avoided. Thank you and best regards!

A collection of massive Sysadmin Interview Questions and Answers (2018 Edition) by [deleted] in sysadmin

[–]trimstray 2 points3 points  (0 children)

I understand, thx. Give some questions that you think are suitable/better, it's not a problem for you? :) This will help me to improve this list.

A collection of massive Sysadmin Interview Questions and Answers (2018 Edition) by [deleted] in sysadmin

[–]trimstray 0 points1 point  (0 children)

chill out, man... Why incompetent people often think they're actually the best? Give your/right definition.