!coeAONBrWyDJnYMbMi:nixos.org

NixOS System Operations

550 Members
About system administration for running NixOS systems in production. Declaratively manage your operations. | Room recommendations: #networking:nixos.org146 Servers

Load older messages


SenderMessageTime
19 Feb 2025
@loc:locrealloc.de@loc:locrealloc.de left the room.11:40:32
@tobinary:stapelueberfluss.deTobiNary joined the room.21:25:51
20 Feb 2025
@mmongelli99:matrix.orgmmongelli99 set a profile picture.03:40:47
21 Feb 2025
@alexandi:matrix.orgalexandi joined the room.06:52:42
@jolly.roberts:matrix.orgjolly.roberts left the room.16:32:28
@adam:robins.wtf@adam:robins.wtf
In reply to @hexa:lossy.network
please report back once you know 🙂
Yes Lego can do 6 day certs now https://github.com/go-acme/lego/releases/tag/v4.22.0
22:21:05
@adam:robins.wtf@adam:robins.wtf https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued/ 22:21:24
@hexa:lossy.networkhexaYes, I saw that earlier as well22:58:13
22 Feb 2025
@adam:robins.wtf@adam:robins.wtf And already merged a few days ago https://github.com/NixOS/nixpkgs/pull/382863 02:18:35
@hexa:lossy.networkhexayup, set a profile and gg02:19:55
@hexa:lossy.networkhexa --profile shortlived 02:22:56
@adam:robins.wtf@adam:robins.wtf Guess I’ll close these two outdated PRs for lego… 02:30:33
24 Feb 2025
@zm94zgv2:private.coffeeZm94ZGV2 changed their profile picture.13:16:03
@thunder:kotiboksi.xyz@thunder:kotiboksi.xyz left the room.21:04:30
25 Feb 2025
@federicodschonborn:matrix.orgFederico Damián Schonborn changed their profile picture.01:35:55
26 Feb 2025
@whatever2576:matrix.orgtactfulvessel joined the room.00:02:22
@samw:fairydust.spacesamw joined the room.09:50:42
@hexa:lossy.networkhexathe ssh connect rate on my oracle box is super high20:16:42
@hexa:lossy.networkhexalike multiple per second20:16:45
@hexa:lossy.networkhexavarying ip addresses, few penalties issued by sshd20:17:04
@hexa:lossy.networkhexathey mostly fail in preauth20:17:43
@hexa:lossy.networkhexa so now i reduced the kexAlgorithms to just sntrup761x25519-sha512@openssh.com and now I get close to 100% kexalgo mismatches 20:17:59
@hexa:lossy.networkhexahow does everyone else deal with that?20:18:59
@hexa:lossy.networkhexathe first thought would be fail2ban, maybe crowdsec20:20:26
@hexa:lossy.networkhexabut crowdsec is of course a bit weird 🙂 20:20:51
@hexa:lossy.networkhexaI don't want to trust a random community of people20:21:04
@hexa:lossy.networkhexaanother idea would of course be a bastion host20:22:11
@hexa:lossy.networkhexabut that would make accessing the host a bit more tedious, given ssh jumps etc.20:22:27
@dgrig:erethon.comdgrigIt's not foolproof, but changing the default port away from 22 helps with a lot of bots20:22:28
@hexa:lossy.networkhexaalso a valid choice20:24:05

Show newer messages


Back to Room ListRoom Version: 10