MichaIng
934e5d20d1
docs(admin): remove X-XSS-Protection header from hardening section
...
Signed-off-by: MichaIng <micha@dietpi.com >
2025-06-30 21:39:35 +02:00
Tobias Kaminsky
47a9a28ca9
Clarify that downloads can come from gh
...
Signed-off-by: Tobias Kaminsky <tobias@kaminsky.me >
2025-05-20 12:55:45 +02:00
rakekniven
df0cb8d30d
Merge branch 'master' into patch-1
...
Signed-off-by: rakekniven <2069590+rakekniven@users.noreply.github.com >
2025-03-21 22:46:47 +01:00
Joas Schilling
d47918e6bf
fix: Add marker to positions that need adjusting on branch off
...
Signed-off-by: Joas Schilling <coding@schilljs.com >
2025-01-31 16:00:27 +01:00
tgoeg
410319591c
Update harden_server.rst - improve fail2ban section
...
Nextcloud won't log failed login attempts in log levels > 2.
Added this to the documentation, and, while at it, improved the fail2ban guide in a few other places.
Fixes #12327 .
Signed-off-by: tgoeg <39340276+tgoeg@users.noreply.github.com >
2024-10-28 13:06:34 +01:00
Daniel Kesselberg
8ce8939735
chore: add trailing comma for allowed_admin_ranges
...
Most of our examples have a trailing comma to easier copy and paste.
Signed-off-by: Daniel Kesselberg <mail@danielkesselberg.de >
2024-09-09 14:17:04 +02:00
Benjamin Gaussorgues
b5f414b989
feat(admin): harden server with admin IP restrict
...
Signed-off-by: Benjamin Gaussorgues <benjamin.gaussorgues@nextcloud.com >
2024-07-24 16:01:42 +02:00
Daniel Kesselberg
2f269adec6
feat: hello codespell
...
Signed-off-by: Daniel Kesselberg <mail@danielkesselberg.de >
2024-07-23 13:04:10 +02:00
Maxime LE HERICY
60f6340dce
Update harden_server.rst
...
Signed-off-by: Maxime LE HERICY <87175513+maximelehericy@users.noreply.github.com >
2024-07-10 11:42:59 +02:00
Michael
8c28795b1e
Update harden_server.rst
...
Add missing letter
Signed-off-by: Michael <2052646+bean5@users.noreply.github.com >
2024-06-21 16:16:30 -06:00
Rello
d8e84f8822
Update harden_server.rst
...
add link to detailed field list for survery server
Signed-off-by: Rello <Rello@users.noreply.github.com >
2024-05-22 14:50:05 +02:00
Rello
0e62fbc0b4
Update harden_server.rst
...
Signed-off-by: Rello <Rello@users.noreply.github.com >
2024-05-17 12:58:37 +02:00
Bastian Derigs
f926534f95
Update harden_server.rst
...
Signed-off-by: Bastian Derigs <155444921+derigs@users.noreply.github.com >
2024-05-17 11:23:02 +02:00
Rello
af3c0ecc56
Update harden_server.rst
...
Signed-off-by: Rello <Rello@users.noreply.github.com >
2024-05-17 09:55:59 +02:00
Rello
ce4a1a0af0
Update harden_server.rst
...
Signed-off-by: Rello <Rello@users.noreply.github.com >
2024-05-17 09:52:02 +02:00
Bastian Derigs
0b0cb86c7a
Update harden_server.rst
...
Signed-off-by: Bastian Derigs <155444921+derigs@users.noreply.github.com >
2024-05-16 15:17:55 +02:00
Rello
f4b2b2a251
Update harden_server.rst
...
Signed-off-by: Rello <Rello@users.noreply.github.com >
2024-05-16 14:28:45 +02:00
Rello
19342c0b8d
Update harden_server.rst
...
Signed-off-by: Rello <Rello@users.noreply.github.com >
2024-05-16 10:28:40 +02:00
Rello
219867f1d0
Update harden_server.rst
...
add fields to be submitted to Nextcloud servers
Signed-off-by: Rello <Rello@users.noreply.github.com >
2024-05-16 10:06:25 +02:00
Maik Wegener
edfeb7a40c
Add totp regex to fail2ban example on harden_server.rst
...
Signed-off-by: Maik Wegener <76479431+mwegnr@users.noreply.github.com >
2024-05-04 00:48:28 +02:00
Andrew McGuinness
f3f5b84a14
Update harden_server.rst
...
remove duplicated phrase
Signed-off-by: Andrew McGuinness <andrew@arobeia.co.uk >
2023-12-28 09:45:11 +00:00
Rello
1a8860c73f
Update harden_server.rst
...
Signed-off-by: Rello <Rello@users.noreply.github.com >
2023-08-21 10:54:37 +02:00
Rello
1ca7835979
Update admin_manual/installation/harden_server.rst
...
Co-authored-by: Simon L. <szaimen@e.mail.de >
Signed-off-by: Rello <Rello@users.noreply.github.com >
2023-08-11 13:22:49 +02:00
Rello
1eda3a1fdc
Update admin_manual/installation/harden_server.rst
...
Co-authored-by: Simon L. <szaimen@e.mail.de >
Signed-off-by: Rello <Rello@users.noreply.github.com >
2023-08-11 12:21:02 +02:00
Rello
057b608c7c
Update harden_server.rst
...
Signed-off-by: Rello <Rello@users.noreply.github.com >
2023-08-11 10:53:24 +02:00
Josh Richards
926057153a
(hardening and security) Add disabling debug mode recommendation
...
Signed-off-by: Josh Richards <josh.t.richards@gmail.com >
2023-06-08 10:11:48 -04:00
MichaIng
10d9cc6a79
Replace X-Robots-Tag header value with "noindex, nofollow"
...
For reference: https://github.com/nextcloud/server/pull/36689
Signed-off-by: MichaIng <micha@dietpi.com >
2023-02-15 17:49:55 +01:00
Lukas Reschke
9d458affee
Document that access tokens shouldn't be stored
...
Access tokens are sensitive key materials and shouldn't be stored, especially not on backup systems that also store the Nextcloud database and configuration backup.
2021-10-18 12:59:50 +02:00
Eibe
981accc0e7
Add fail2ban hardening
...
Signed-off-by: Eibe <40539455+eibex@users.noreply.github.com >
2020-07-29 23:47:39 +02:00
Fabian Hauck
f174909c76
improved SSL hardening guide
...
Signed-off-by: Fabian Hauck <hauckfabian@gmail.com >
2020-05-10 14:11:08 +02:00
Wehzie
0974dcb824
Fixed varying capitalization
...
Settled for "includeSubDomains" over "includeSubdomains" as also found on Mozilla docs https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
Furthermore removed semicolon as it doesn't appear in the Apache config
2019-08-04 02:41:38 +02:00
Julius Härtl
f2f700e506
Add list of possible remote connection destinations
...
Signed-off-by: Julius Härtl <jus@bitgrid.net >
2019-05-02 10:16:45 +02:00
Jack Hazlehurst
dc03320f8a
Fixed grammar error.
...
an -> a
2019-02-18 16:05:49 +00:00
Morris Jobke
64d62c6489
Move "hardening server" section from configuration to installation part
...
Signed-off-by: Morris Jobke <hey@morrisjobke.de >
2019-02-01 16:37:14 +01:00