mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2025-11-23 00:10:25 -05:00
use consistent naming for session ticket key scripts/units
This commit is contained in:
parent
768cc9ada3
commit
0d1705320f
13 changed files with 38 additions and 38 deletions
|
|
@ -12,13 +12,13 @@ for host in ${hosts_web[@]}; do
|
||||||
|
|
||||||
ssh $remote ln -snf /usr/lib/nginx/modules/ /etc/nginx/modules
|
ssh $remote ln -snf /usr/lib/nginx/modules/ /etc/nginx/modules
|
||||||
|
|
||||||
rsync etc/systemd/system/{create-session-ticket-keys.service,rotate-session-ticket-keys.service,rotate-session-ticket-keys.timer} $remote:/etc/systemd/system/
|
rsync etc/systemd/system/{session-ticket-keys-create.service,session-ticket-keys-rotate.service,session-ticket-keys-rotate.timer} $remote:/etc/systemd/system/
|
||||||
rsync --chmod=755 create-session-ticket-keys rotate-session-ticket-keys $remote:/usr/local/bin/
|
rsync --chmod=755 session-ticket-keys-create session-ticket-keys-rotate $remote:/usr/local/bin/
|
||||||
rsync -r --delete etc/systemd/system/nginx.service.d/ $remote:/etc/systemd/system/nginx.service.d
|
rsync -r --delete etc/systemd/system/nginx.service.d/ $remote:/etc/systemd/system/nginx.service.d
|
||||||
|
|
||||||
ssh $remote "mkdir -pm755 /var/cache/nginx
|
ssh $remote "mkdir -pm755 /var/cache/nginx
|
||||||
groupadd -fg 2100 tls
|
groupadd -fg 2100 tls
|
||||||
mkdir -p -m 750 /etc/session-ticket-keys && chgrp tls /etc/session-ticket-keys
|
mkdir -p -m 750 /etc/session-ticket-keys && chgrp tls /etc/session-ticket-keys
|
||||||
systemctl daemon-reload &&
|
systemctl daemon-reload &&
|
||||||
systemctl enable create-session-ticket-keys.service rotate-session-ticket-keys.timer nginx"
|
systemctl enable session-ticket-keys-create.service session-ticket-keys-rotate.timer nginx"
|
||||||
done
|
done
|
||||||
|
|
|
||||||
|
|
@ -2,4 +2,4 @@
|
||||||
/dev/md/boot /boot vfat rw,nosuid,nodev,noexec,fmask=0177,dmask=0077 0 2
|
/dev/md/boot /boot vfat rw,nosuid,nodev,noexec,fmask=0177,dmask=0077 0 2
|
||||||
|
|
||||||
/dev/mapper/swap none swap x-systemd.device-timeout=30 0 0
|
/dev/mapper/swap none swap x-systemd.device-timeout=30 0 0
|
||||||
tmpfs /etc/session-ticket-keys tmpfs size=1M,mode=750,gid=tls,noswap,x-systemd.before=create-session-ticket-keys.service,x-systemd.required-by=create-session-ticket-keys.service 0 0
|
tmpfs /etc/session-ticket-keys tmpfs size=1M,mode=750,gid=tls,noswap,x-systemd.before=session-ticket-keys-create.service,x-systemd.required-by=session-ticket-keys-create.service 0 0
|
||||||
|
|
|
||||||
|
|
@ -1,2 +1,2 @@
|
||||||
/dev/mapper/swap none swap x-systemd.device-timeout=30 0 0
|
/dev/mapper/swap none swap x-systemd.device-timeout=30 0 0
|
||||||
tmpfs /etc/session-ticket-keys tmpfs size=1M,mode=750,gid=tls,noswap,x-systemd.before=create-session-ticket-keys.service,x-systemd.required-by=create-session-ticket-keys.service 0 0
|
tmpfs /etc/session-ticket-keys tmpfs size=1M,mode=750,gid=tls,noswap,x-systemd.before=session-ticket-keys-create.service,x-systemd.required-by=session-ticket-keys-create.service 0 0
|
||||||
|
|
|
||||||
|
|
@ -4,7 +4,6 @@ IgnoreUnowned = etc/letsencrypt
|
||||||
IgnoreUnowned = etc/locale.conf
|
IgnoreUnowned = etc/locale.conf
|
||||||
IgnoreUnowned = etc/modprobe.d/local.conf
|
IgnoreUnowned = etc/modprobe.d/local.conf
|
||||||
IgnoreUnowned = etc/modules-load.d/60-local.conf
|
IgnoreUnowned = etc/modules-load.d/60-local.conf
|
||||||
IgnoreUnowned = etc/session-ticket-keys
|
|
||||||
IgnoreUnowned = etc/sysctl.d/60-local.conf
|
IgnoreUnowned = etc/sysctl.d/60-local.conf
|
||||||
IgnoreUnowned = etc/sysctl.d/60-conntrack_size.conf
|
IgnoreUnowned = etc/sysctl.d/60-conntrack_size.conf
|
||||||
IgnoreUnowned = etc/sysctl.d/60-reserved-ports.conf
|
IgnoreUnowned = etc/sysctl.d/60-reserved-ports.conf
|
||||||
|
|
@ -87,13 +86,14 @@ mdadm = etc/systemd/system/mdmonitor.service.wants
|
||||||
mdadm = var/lib/mdcheck
|
mdadm = var/lib/mdcheck
|
||||||
nftables = etc/sysctl.d/local-conntrack_size.conf
|
nftables = etc/sysctl.d/local-conntrack_size.conf
|
||||||
nginx = etc/nginx
|
nginx = etc/nginx
|
||||||
nginx = etc/systemd/system/create-session-ticket-keys.service
|
nginx = etc/session-ticket-keys
|
||||||
nginx = etc/systemd/system/nginx.service.d
|
nginx = etc/systemd/system/nginx.service.d
|
||||||
nginx = etc/systemd/system/rotate-session-ticket-keys.service
|
nginx = etc/systemd/system/session-ticket-keys-create.service
|
||||||
nginx = etc/systemd/system/rotate-session-ticket-keys.timer
|
nginx = etc/systemd/system/session-ticket-keys-rotate.service
|
||||||
|
nginx = etc/systemd/system/session-ticket-keys-rotate.timer
|
||||||
nginx = srv
|
nginx = srv
|
||||||
nginx = usr/local/bin/create-session-ticket-keys
|
nginx = usr/local/bin/session-ticket-keys-create
|
||||||
nginx = usr/local/bin/rotate-session-ticket-keys
|
nginx = usr/local/bin/session-ticket-keys-rotate
|
||||||
nginx = var/lib/nginx
|
nginx = var/lib/nginx
|
||||||
opendkim = etc/opendkim
|
opendkim = etc/opendkim
|
||||||
opendkim = etc/systemd/system/opendkim.service
|
opendkim = etc/systemd/system/opendkim.service
|
||||||
|
|
|
||||||
|
|
@ -1,10 +0,0 @@
|
||||||
[Unit]
|
|
||||||
Description=Rotate TLS session ticket keys
|
|
||||||
After=dnsdist.service nginx.service create-session-ticket-keys.service
|
|
||||||
Requires=create-session-ticket-keys.service
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
ExecStart=/usr/local/bin/rotate-session-ticket-keys
|
|
||||||
Group=tls
|
|
||||||
Type=oneshot
|
|
||||||
UMask=0027
|
|
||||||
|
|
@ -1,11 +0,0 @@
|
||||||
[Unit]
|
|
||||||
Description=Run rotate-session-ticket-keys every 6 hours
|
|
||||||
After=create-session-ticket-keys.service
|
|
||||||
Requires=create-session-ticket-keys.service
|
|
||||||
|
|
||||||
[Timer]
|
|
||||||
OnActiveSec=6h
|
|
||||||
OnUnitActiveSec=6h
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=timers.target
|
|
||||||
|
|
@ -3,7 +3,7 @@ Description=Create TLS session ticket keys
|
||||||
Before=dnsdist.service nginx.service
|
Before=dnsdist.service nginx.service
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
ExecStart=/usr/local/bin/create-session-ticket-keys
|
ExecStart=/usr/local/bin/session-ticket-keys-create
|
||||||
Group=tls
|
Group=tls
|
||||||
RemainAfterExit=yes
|
RemainAfterExit=yes
|
||||||
Type=oneshot
|
Type=oneshot
|
||||||
10
etc/systemd/system/session-ticket-keys-rotate.service
Normal file
10
etc/systemd/system/session-ticket-keys-rotate.service
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Rotate TLS session ticket keys
|
||||||
|
After=dnsdist.service nginx.service session-ticket-keys-create.service
|
||||||
|
Requires=session-ticket-keys-create.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/usr/local/bin/session-ticket-keys-rotate
|
||||||
|
Group=tls
|
||||||
|
Type=oneshot
|
||||||
|
UMask=0027
|
||||||
11
etc/systemd/system/session-ticket-keys-rotate.timer
Normal file
11
etc/systemd/system/session-ticket-keys-rotate.timer
Normal file
|
|
@ -0,0 +1,11 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Rotate session ticket keys every 6 hours
|
||||||
|
After=session-ticket-keys-create.service
|
||||||
|
Requires=session-ticket-keys-create.service
|
||||||
|
|
||||||
|
[Timer]
|
||||||
|
OnActiveSec=6h
|
||||||
|
OnUnitActiveSec=6h
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=timers.target
|
||||||
|
|
@ -1,7 +1,7 @@
|
||||||
[Unit]
|
[Unit]
|
||||||
Description=Sync TLS session ticket keys
|
Description=Sync TLS session ticket keys
|
||||||
After=dnsdist.service nginx.service create-session-ticket-keys.service
|
After=dnsdist.service nginx.service session-ticket-keys-create.service
|
||||||
Requires=create-session-ticket-keys.service
|
Requires=session-ticket-keys-create.service
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
ExecStart=/usr/local/bin/session-ticket-keys-sync
|
ExecStart=/usr/local/bin/session-ticket-keys-sync
|
||||||
|
|
|
||||||
|
|
@ -1,7 +1,7 @@
|
||||||
[Unit]
|
[Unit]
|
||||||
Description=Run session-ticket-keys-sync.service every minute
|
Description=Sync session ticket keys every minute
|
||||||
After=create-session-ticket-keys.service
|
After=session-ticket-keys-create.service
|
||||||
Requires=create-session-ticket-keys.service
|
Requires=session-ticket-keys-create.service
|
||||||
|
|
||||||
[Timer]
|
[Timer]
|
||||||
AccuracySec=1s
|
AccuracySec=1s
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue