Skip to content
This repository has been archived by the owner on Jun 21, 2018. It is now read-only.

!DO NOT MERGE! Stripped branch #175

Open
wants to merge 600 commits into
base: master
Choose a base branch
from
Open
Changes from 3 commits
Commits
Show all changes
600 commits
Select commit Hold shift + click to select a range
a99c4c8
direct people to end-to-end setup for more complex changes
lrvick Jun 26, 2016
75d69be
remove cumbersome and near pointless multi-commit signing instruction
lrvick Jun 30, 2016
4d8e05a
Merge pull request #98 from hashbang/new-flow
lrvick Jun 30, 2016
d5e3f3f
committing changes in /etc after apt run
KellerFuchs Jul 1, 2016
b85be3a
Merge remote-tracking branch 'origin/master'
Jul 1, 2016
3396ead
apt: Switch to deb.debian.org
KellerFuchs Jul 21, 2016
0921602
apt: Add security mirror for Stretch
KellerFuchs Jul 21, 2016
b4121f9
Merge pull request #101 from KellerFuchs/mirrors
lrvick Aug 1, 2016
ba9f45b
Add a firejail profile for mutt
KellerFuchs Aug 3, 2016
c446095
Do not expose Unbound's secrets
KellerFuchs Aug 6, 2016
bd2a8e3
Remove spurious /etc/etc directory
KellerFuchs Aug 6, 2016
08aad9a
Merge remote-tracking branch 'origin/master'
Aug 6, 2016
ebdbc4f
committing changes in /etc after apt run
KellerFuchs Aug 8, 2016
1ac3ffc
committing changes in /etc after apt run
KellerFuchs Aug 8, 2016
538b2dd
committing changes in /etc after apt run
KellerFuchs Aug 8, 2016
b46022d
committing changes in /etc after apt run
KellerFuchs Aug 8, 2016
e12498b
Merge pull request #104 from KellerFuchs/no-testing
lrvick Aug 9, 2016
ba30a9f
apt: Never install silently from testing
KellerFuchs Aug 9, 2016
7067e84
committing changes in /etc after apt run
KellerFuchs Aug 12, 2016
962ad3e
committing changes in /etc after apt run
KellerFuchs Aug 12, 2016
aa84fd4
Merge remote-tracking branch 'KellerFuchs/stow-dotfiles'
KellerFuchs Aug 14, 2016
63f87f7
sudoers: Do not keep SSH_AUTH_SOCK
KellerFuchs Aug 14, 2016
e853d5a
Merge branch 'git-infra'
KellerFuchs Aug 14, 2016
2c8837c
committing changes in /etc after apt run
KellerFuchs Aug 14, 2016
d9b34cd
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Aug 14, 2016
7498811
apt: Pull mosh from jessie-backports
Aug 14, 2016
2241693
Merge remote-tracking branch 'git-infra/ny1'
KellerFuchs Aug 14, 2016
0b1095c
Merge branch 'firejail-mutt'
KellerFuchs Aug 15, 2016
d6ad08c
committing changes in /etc after apt run
KellerFuchs Aug 16, 2016
ddb9dbf
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Aug 16, 2016
5ab02a8
committing changes in /etc after apt run
KellerFuchs Aug 19, 2016
a202c10
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Aug 19, 2016
b9cddc5
haveged: Sets the “low entropy” watermark at 2kb
KellerFuchs Aug 19, 2016
0e6d30d
committing changes in /etc after apt run
KellerFuchs Aug 19, 2016
b56513d
Merge branch 'etckeeper'
KellerFuchs Aug 20, 2016
77d652a
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Aug 20, 2016
647e796
committing changes in /etc after apt run
KellerFuchs Aug 21, 2016
e61818c
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Aug 21, 2016
7aeb48b
committing changes in /etc after apt run
Aug 21, 2016
ad044da
committing changes in /etc after apt run
Aug 21, 2016
860ce2d
committing changes in /etc after apt run
Aug 21, 2016
06233ad
committing changes in /etc after apt run
KellerFuchs Aug 21, 2016
9ce6df8
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Aug 21, 2016
5a85643
committing changes in /etc after apt run
Aug 21, 2016
1d91f5b
committing changes in /etc after apt run
Aug 21, 2016
8cfc7f7
committing changes in /etc after apt run
Aug 21, 2016
7ccd676
committing changes in /etc after apt run
Aug 21, 2016
bd96388
committing changes in /etc after apt run
Aug 21, 2016
4a4b12e
Merge branches 'da1', 'ny1', 'sf1' and 'to1'
KellerFuchs Aug 21, 2016
dfcc794
firejail: Allow mutt to read its own config
KellerFuchs Aug 28, 2016
a51b4c3
Merge branch 'firejail-mutt'
KellerFuchs Aug 28, 2016
5644d94
committing changes in /etc after apt run
Aug 28, 2016
b819a94
committing changes in /etc after apt run
Aug 28, 2016
bec1aa3
committing changes in /etc after apt run
Aug 28, 2016
07df193
committing changes in /etc after apt run
Aug 28, 2016
77bfb93
Keep track of passwd and group
KellerFuchs Aug 20, 2016
9a3d856
commit /etc changes after apt run
KellerFuchs Aug 28, 2016
d385c93
Merge remote-tracking branch 'KellerFuchs/setup.sh'
KellerFuchs Aug 28, 2016
9b973ec
Merge remote-tracking branches 'git-infra/da1', 'git-infra/ny1', 'git…
KellerFuchs Aug 28, 2016
7d957cf
committing changes in /etc after apt run
Aug 28, 2016
507106e
committing changes in /etc after apt run
Aug 28, 2016
6c5fad5
committing changes in /etc after apt run
Aug 28, 2016
61a0412
committing changes in /etc after apt run
Aug 28, 2016
7ffaad2
committing changes in /etc after apt run
Aug 28, 2016
1ec7e14
committing changes in /etc after apt run
Aug 28, 2016
c3e7082
apt: More permissions fixups
KellerFuchs Sep 1, 2016
4e1a4b0
committing changes in /etc after apt run
KellerFuchs Sep 1, 2016
cda3854
committing changes in /etc after apt run
KellerFuchs Sep 6, 2016
a3f1c02
committing changes in /etc after apt run
Sep 6, 2016
3a3505b
committing changes in /etc after apt run
Sep 6, 2016
5d12edf
committing changes in /etc after apt run
Sep 6, 2016
668828c
Merge remote-tracking branches 'git-infra/da1', 'git-infra/ny1', 'git…
KellerFuchs Sep 6, 2016
b045d6e
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Sep 6, 2016
18cc711
ferm: Add a firewall policy
KellerFuchs Sep 6, 2016
b8d31bc
ferm: Ban bitcoinshell.mooo.com
KellerFuchs Sep 13, 2016
9d2d206
Merge remote-tracking branches 'git-infra/da1', 'git-infra/ny1' and '…
KellerFuchs Sep 13, 2016
3978e80
man: Fix links in hashbang(7)
KellerFuchs Sep 15, 2016
64fccc8
ferm: Fix indentation
KellerFuchs Sep 15, 2016
be42732
sysctl: Use CoDel for packet scheduling
KellerFuchs Sep 24, 2016
d72d940
sysctl: Forbid unprivileged kernel instrumentation
KellerFuchs Sep 24, 2016
3f2fff8
Merge branch 'sysctl'
KellerFuchs Sep 24, 2016
b1a14e1
committing changes in /etc after apt run
Sep 24, 2016
43ea4e6
committing changes in /etc after apt run
Sep 24, 2016
9df3522
committing changes in /etc after apt run
Sep 24, 2016
f0b3316
Merge remote-tracking branches 'git-infra/da1', 'git-infra/ny1' and '…
KellerFuchs Oct 5, 2016
499a597
committing changes in /etc after apt run
RyanSquared Oct 16, 2016
ce2f152
Merge remote-tracking branch 'git-infra/ny1'
KellerFuchs Oct 16, 2016
f5c89e2
committing changes in /etc after apt run
Oct 16, 2016
6f5ddca
committing changes in /etc after apt run
Oct 20, 2016
bf30d97
Merge remote-tracking branch 'git-infra/da1'
KellerFuchs Oct 20, 2016
a8a84d9
committing changes in /etc after apt run
Oct 20, 2016
862464f
Install package `dialog`.
KellerFuchs Oct 20, 2016
6105f04
gnupg: Update my key
KellerFuchs Oct 27, 2016
8cfaa0b
Merge pull request #113 from KellerFuchs/gpg
dpflug Oct 28, 2016
343b6a5
profile.d/npm.sh: add support for n and paths for npm/node
Oct 29, 2016
3dd72b3
profile.d/local_path.sh: add support for $HOME/.local/bin
Oct 29, 2016
078a5d3
profile.d/python.sh: add aliases for pip to auto `--user`
Oct 29, 2016
92a2acf
profile.d/manpath.sh: add support for MANPATH via /usr/bin/manpath
Oct 29, 2016
e04c541
manpath.sh => z_manpath.sh to force loading last
Oct 29, 2016
ac56256
Merge remote-tracking branch 'origin/manpath'
KellerFuchs Oct 29, 2016
3191cd0
Merge remote-tracking branch 'origin/add-python-defaults'
KellerFuchs Oct 29, 2016
4cd3c75
committing changes in /etc after apt run
Oct 29, 2016
9eaab9e
committing changes in /etc after apt run
Oct 29, 2016
5f3598a
cron.hourly: Remove obsolete “group 3000” script
KellerFuchs Oct 29, 2016
17cf287
Remove confusing pip aliases
KellerFuchs Oct 29, 2016
3048941
Merge firejail upgrade
KellerFuchs Oct 29, 2016
55168fd
committing changes in /etc after apt run
Oct 30, 2016
5fda9be
Merge remote-tracking branch 'git-infra/da1'
KellerFuchs Oct 31, 2016
9e7a4c8
firejail/weechat: Allow access to .dotfiles/weechat
KellerFuchs Oct 31, 2016
5c9a191
firejail/weechat: Profile hardening
KellerFuchs Oct 31, 2016
40af493
firejail/mutt: Fixup profile
KellerFuchs Oct 31, 2016
15d69e0
Merge branch 'KellerFuchs-firejail-fixup'
dpflug Oct 31, 2016
3e644bb
firejail/mutt: Fixup fixup
KellerFuchs Oct 31, 2016
36a1b8b
firejail/weechat: Fixup fixup too!
KellerFuchs Oct 31, 2016
6dfcdf6
Merge branch 'firejail-fixup'
KellerFuchs Oct 31, 2016
f849fce
apt: Using openntpd backports
Nov 7, 2016
9ebbc7c
committing changes in /etc after apt run
Nov 7, 2016
0917901
group: Adding missing ntpd group (fixup)
Nov 7, 2016
1caec72
passwd: Add ntpd system user
Nov 7, 2016
9096625
Remove {group,passwd}+
Nov 7, 2016
f1e75ae
Merge branch 'ntpd'
KellerFuchs Nov 7, 2016
88c3d97
profile.d/go.sh: add GOPATH
Oct 29, 2016
071b3f5
profile.d/npm.sh: clarify npm alias
Oct 29, 2016
cefdad0
committing changes in /etc after apt run
Dec 3, 2016
668ea97
Merge remote-tracking branch 'git-infra/ny1'
KellerFuchs Dec 3, 2016
562df01
profile.d/npm: Use an if instead of a subshell
KellerFuchs Dec 3, 2016
e55e893
committing changes in /etc after apt run
Dec 4, 2016
236eabc
committing changes in /etc after apt run
Dec 4, 2016
7f97426
Merge remote-tracking branch 'git-infra/sf1'
KellerFuchs Dec 4, 2016
c68a36d
Merge branch 'add-go-defaults' of github.com:hashbang/shell-etc
Dec 4, 2016
ed22b56
Merge branch 'master' of github.com:hashbang/shell-etc
Dec 4, 2016
0f07a90
profile.d: Reject wall(1) messages from unprivileged users
KellerFuchs Dec 6, 2016
e4e2feb
limits: Raise process limit to 75/100 (soft/hard)
KellerFuchs Dec 6, 2016
198014e
limits: Remove memlock
KellerFuchs Dec 6, 2016
60aebeb
Merge branch 'wall'
KellerFuchs Dec 6, 2016
f25118b
Merge branch 'process-limit'
KellerFuchs Dec 6, 2016
b85f2ee
Fixup permissions on profile.d/luarocks_aliases.sh
KellerFuchs Dec 6, 2016
164761d
Add example network configuration
KellerFuchs Aug 6, 2016
82cf7f0
sysctl: Enable reverse-path filtering
KellerFuchs Jan 4, 2017
68484d9
firejail: Make NPM's location read-only
KellerFuchs Dec 3, 2016
b2788b0
Merge branch 'add-node-defaults'
KellerFuchs Jan 4, 2017
60f1cef
firejail/disable-common: Fixup comment
KellerFuchs Jan 4, 2017
9aa9474
firejail/disable-common: Make ~/.gem read-only
KellerFuchs Jan 4, 2017
82e4ce1
firejail/disable-common: Make ~/.local read-only
KellerFuchs Jan 4, 2017
6c93b04
firejail/disable-common: Make ~/.luarocks readonly
KellerFuchs Jan 4, 2017
6af768c
firejail: Disable X sandboxing
KellerFuchs Jan 4, 2017
4669285
Merge branch 'CVE-2017-5180'
KellerFuchs Jan 4, 2017
b687120
Merge branch 'firejail-local'
KellerFuchs Jan 4, 2017
84a0055
Merge branch 'rp_filter'
KellerFuchs Jan 9, 2017
848f136
Merge branch 'ipv6'
KellerFuchs Jan 9, 2017
4a22fb3
ssh/sshd_config: Allow binding to non-loopback address
RyanSquared Jan 8, 2017
32aaa2c
npmrc: add default configuration, PREFIX in $HOME/.npm-packages
RyanSquared Jan 8, 2017
a3c0c95
firejail: Merge profiles from upstream
KellerFuchs Jan 9, 2017
ae99f1f
sssd: Use LDAPS (LDAP over TLS)
KellerFuchs Jan 13, 2017
5b2e509
nslcd: Fixup LDAP URI
KellerFuchs Jan 13, 2017
a1260eb
Merge branch 'ldaps'
KellerFuchs Jan 16, 2017
14355e8
Merge branch 'allow-gateway-port'
KellerFuchs Jan 16, 2017
3ff41cd
Merge branch 'fix-npm-install-latest-node'
KellerFuchs Jan 16, 2017
5d7cbba
firejail: Restore #! customizations
KellerFuchs Jan 9, 2017
aa2a899
firejail: Cryptocat: Fix missing app name
KellerFuchs Jan 16, 2017
8e0d496
Merge branch 'firejail-local'
KellerFuchs Jan 17, 2017
173dc7b
Add welcome message in /etc
KellerFuchs Jan 18, 2017
38c82db
Update z_manpath.sh
mwgamera Jan 24, 2017
3d578aa
profile.d/nvm.sh: add support for nvm
drGrove Jan 23, 2017
be09a04
profile.d/nvm: remove excess bracket, use git -C instead of cd
drGrove Jan 25, 2017
6f4477a
Merge remote-tracking branch 'pull/145'
KellerFuchs Jan 27, 2017
2601bc3
gnupg: Update drGrove's key in keyring
KellerFuchs Jan 27, 2017
ecff0c3
sssd: Disable debug logs
KellerFuchs Feb 9, 2017
1a089c3
Merge branch 'sssd-logs'
KellerFuchs Feb 9, 2017
eedfc6e
Merge branch 'skel-perm'
KellerFuchs Feb 9, 2017
bfea987
Merge branch 'welcome'
KellerFuchs Feb 9, 2017
094140b
Merge branch 'drGrove-key'
KellerFuchs Feb 12, 2017
b946382
Make the dotfiles deployment script a “profile.d” thing
KellerFuchs Feb 21, 2017
d15380f
Merge branch 'dotfiles-deploy'
KellerFuchs Feb 23, 2017
9717859
cron.daily/clean-lurkers: Proper user ranges
KellerFuchs Apr 15, 2017
b4f1536
man: Add hashbangctl to software list in hashbang.7 man page
Apr 21, 2017
e7e2944
limits.conf: Double nproc limits
KellerFuchs Apr 22, 2017
e09c0a5
Merge PR#161: limits.conf: Double nproc limits
KellerFuchs Apr 22, 2017
1b6d851
Merge remote-tracking branch 'git-infra/ny1'
KellerFuchs Apr 22, 2017
3af01d0
journald: Limit the amount of logs kept
KellerFuchs Apr 22, 2017
c497eb0
Merge PR#162: journald: Limit the amount of logs kept
KellerFuchs Apr 22, 2017
48e3e72
cron.daily/clean-lurkers: Only process new entries
KellerFuchs Apr 23, 2017
ab89768
Merge PR#152: cron.daily/clean-lurkers: Proper user ranges
KellerFuchs Apr 23, 2017
c81a598
cron.daily/clean-lurkers: Fixup
KellerFuchs Apr 23, 2017
214c560
systemd: Periodically execute /etc/cron.*
KellerFuchs Apr 23, 2017
48e07ef
Merge PR#163: cron.daily/clean-lurkers: Fixup
KellerFuchs Apr 24, 2017
48b4206
Merge PR#143: systemd: Disable atd & cron
KellerFuchs Apr 24, 2017
4d9c2a4
Merge PR#158: Add hashbangctl to software list in hashbang(7)
KellerFuchs Apr 24, 2017
603aaef
gnupg: Update admins keyring
KellerFuchs Apr 25, 2017
5c9c711
committing changes in /etc after apt run
Apr 25, 2017
9903233
update hashbang admin keys with all subkeys
lrvick Apr 25, 2017
1524d6c
committing changes in /etc after apt run
Apr 25, 2017
d6f1c71
Merge remote-tracking branch 'git-infra/to1'
KellerFuchs Apr 25, 2017
8c78a64
committing changes in /etc after apt run
Apr 25, 2017
f50374e
update kellerfuchs keys
lrvick Apr 25, 2017
7ccea95
Merge remote-tracking branch 'git-infra/to1'
lrvick Apr 25, 2017
e5b9aef
firejail: Revert to #!-specific config.
KellerFuchs Apr 30, 2017
4b67580
Merge PR#166: firejail: Revert to #!-specific config
KellerFuchs Apr 30, 2017
297913a
apt: Pull kernel from debian-backports
KellerFuchs May 1, 2017
0f33c25
pam.d: Uniformly enforce pam_nologin
KellerFuchs May 1, 2017
4c33797
Merge PR#168: pam.d: Uniformly enforce pam_nologin
KellerFuchs May 2, 2017
91639d9
security/namespace.conf: Update comments
KellerFuchs May 12, 2017
be856f9
security/namespace.conf: Disable /dev polyinstantiation
KellerFuchs May 12, 2017
a50350b
Merge PR#173: Disable polyinstanciation for /dev
KellerFuchs May 13, 2017
d8625c1
committing changes in /etc after apt run
May 13, 2017
90ea5f8
gitignore aliases.db
KellerFuchs May 13, 2017
7dbdf3e
aliases: Direct mail for root@ to root@hashbang.sh
KellerFuchs May 13, 2017
8f096a1
committing changes in /etc after apt run
May 13, 2017
87d84a2
committing changes in /etc after apt run
May 13, 2017
5f9430f
committing changes in /etc after apt run
May 13, 2017
5ae4f3a
committing changes in /etc after apt run
May 31, 2017
aa87d9b
committing changes in /etc after apt run
May 31, 2017
bc86bf5
Manually fixing up apt state
May 31, 2017
892f287
committing changes in /etc after apt run
May 31, 2017
0cd9705
committing changes in /etc after apt run
May 31, 2017
c55eac5
Manually fixing up apt state
May 31, 2017
fff9ff8
committing changes in /etc after apt run
May 31, 2017
37328de
committing changes in /etc after apt run
May 31, 2017
a9ce043
Manually fixing up apt state
May 31, 2017
3f41bec
committing changes in /etc after apt run
May 31, 2017
e01b18c
committing changes in /etc after apt run
May 31, 2017
8a89c2a
Manually fixing up apt state
May 31, 2017
b7cc14c
committing changes in /etc after apt run
May 31, 2017
db556f8
committing changes in /etc after apt run
Jun 20, 2017
471d95e
sshd: Ignore ~/.ssh/authorized_keys
KellerFuchs Jun 20, 2017
bcd93e4
etckeeper fixup
KellerFuchs Jun 24, 2017
7d3c3bd
etckeeper fixup
KellerFuchs Jun 24, 2017
f92fce2
etckeeper fixup
KellerFuchs Jun 24, 2017
f9e24c1
etckeeper fixup
KellerFuchs Jun 24, 2017
6b02910
Merge branches 'da1', 'ny1', 'to1' and 'sf1' from 'git-infra'
KellerFuchs Jun 24, 2017
1b27345
etckeeper: Do not deinstall mysql
KellerFuchs Jun 24, 2017
4c40f5f
Merge branch 'ssh_authorizedkeys'
KellerFuchs Jun 24, 2017
743613d
committing changes in /etc after apt run
Jun 24, 2017
2950e70
committing changes in /etc after apt run
Jun 24, 2017
54ae758
committing changes in /etc after apt run
Jun 24, 2017
865b8b6
committing changes in /etc after apt run
Jun 24, 2017
afebc98
ssh: Allow root to use authorized_keys file (HOTFIX)
KellerFuchs Jun 24, 2017
6cd287f
Merge branches 'da1', 'ny1', 'to1' and 'sf1' from 'git-infra'
KellerFuchs Jun 24, 2017
a0f7319
ssh: Hotfix for the previous hotfix
KellerFuchs Jun 24, 2017
74fecda
committing changes in /etc after apt run
Jun 25, 2017
ff79e6c
committing changes in /etc after apt run
Jun 25, 2017
25f71d7
committing changes in /etc after apt run
Aug 29, 2017
d4aaaf6
committing changes in /etc after apt run
Aug 29, 2017
89867d2
committing changes in /etc after apt run
Aug 29, 2017
5c3dc62
committing changes in /etc after apt run
Aug 29, 2017
a193338
Merge remote-tracking branches 'git-infra/ny1', 'git-infra/to1' and '…
KellerFuchs Sep 12, 2017
9abbd77
Merge remote-tracking branch 'git-infra/da1'
KellerFuchs Sep 12, 2017
06cc3d5
msmtp: Require valid certificate, rather than pinning by fingerprint
l2dy Sep 11, 2017
94febc2
Merge PR#181: Fix msmtp after the mail server's fingerprint changed
KellerFuchs Sep 12, 2017
3b1e942
Bringing back skel/
KellerFuchs Sep 20, 2017
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 11 additions & 8 deletions apt/sources.list
Original file line number Diff line number Diff line change
@@ -1,13 +1,16 @@
deb http://httpredir.debian.org/debian/ jessie main contrib non-free
deb-src http://httpredir.debian.org/debian/ jessie main contrib non-free
deb http://deb.debian.org/debian/ jessie main contrib non-free
deb-src http://deb.debian.org/debian/ jessie main contrib non-free

deb http://security.debian.org/ jessie/updates main contrib non-free
deb-src http://security.debian.org/ jessie/updates main contrib non-free
deb http://deb.debian.org/debian-security/ jessie/updates main contrib non-free
deb-src http://deb.debian.org/debian-security/ jessie/updates main contrib non-free

# Backports. Must be enabled per-package using a pin
deb http://httpredir.debian.org/debian/ jessie-backports main contrib non-free
deb-src http://httpredir.debian.org/debian/ jessie-backports main contrib non-free
deb http://deb.debian.org/debian/ jessie-backports main contrib non-free
deb-src http://deb.debian.org/debian/ jessie-backports main contrib non-free

# Newer releases. Use with care and pin.
deb http://httpredir.debian.org/debian/ stretch main contrib non-free
deb-src http://httpredir.debian.org/debian/ stretch main contrib non-free
deb http://deb.debian.org/debian/ stretch main contrib non-free
deb-src http://deb.debian.org/debian/ stretch main contrib non-free

deb http://deb.debian.org/debian-security/ stretch/updates main contrib non-free
deb-src http://deb.debian.org/debian-security/ stretch/updates main contrib non-free