====== Serveur Perso ======
Serveur basé sur une Debian 12 (bookworm) AMD64.
===== Disques =====
- disque SSD monté normalement avec partitions physiques:
* / (~50G)
* /home (~200G)
- disque RAID 2x 2T (voir ci-dessous)
===== Raid =====
sudo mdadm --create --verbose /dev/md0 --metadata 1.2 --level=mirror --raid-devices=2 /dev/sda1 /dev/sdb1
sudo reboot
cat /proc/mdstat
sudo mdadm --detail --scan >> my_mdadm.conf
Ensuite j'ai rajouté une ligne (celle du fichier ''my_mdadm.conf'' dans le fichier ''/etc/mdadm/mdadm.conf''). Mais je ne sais pas si c'est utile :
# mdadm.conf
#
# !NB! Run update-initramfs -u after updating this file.
# !NB! This will ensure that initramfs has an uptodate copy.
#
# Please refer to mdadm.conf(5) for information about this file.
#
# by default (built-in), scan all partitions (/proc/partitions) and all
# containers for MD superblocks. alternatively, specify devices to scan, using
# wildcards if desired.
#DEVICE partitions containers
# automatically tag new arrays as belonging to the local system
HOMEHOST
# instruct the monitoring daemon where to send mail alerts
MAILADDR beafrancois@beafrancois.fr
# definitions of existing MD arrays
ARRAY /dev/md/cahute:0 metadata=1.2 name=cahute:0 UUID=4a1d7069:3a4a17d0:06e37696:8d5c340d
# This configuration was auto-generated on Wed, 25 Jul 2018 23:01:52 +0000 by mkconf
===== montages bind =====
/mnt/stockage/system/mysql /var/lib/mysql none bind
/mnt/stockage/system/gitea /var/lib/gitea none bind
/mnt/stockage/system/web /var/www/html none bind
===== nfs =====
Installer le serveur nfs:
sudo apt install nfs-kernel-server
Modifier ''/etc/fstab'':
[...]
/media/stockage/multimedia /export/multimedia none bind 0 0
/media/stockage/famille /export/famille none bind 0 0
/media/stockage/partage /export/partage none bind 0 0
/media/stockage/homes/francois /export/home/francois none bind 0 0
/media/stockage/homes/beatrice /export/home/beatrice none bind 0 0
/media/stockage/repositories /export/repositories none bind 0 0
[...]
la suite [[commun:shares_du_nas_fstab|ici]].
===== apache2 =====
Les commandes suivantes sont utilisées pour l'install:
sudo apt install apache2
**Activation du site https et désactivation du site http**
sudo a2enmod ssl
sudo a2enmod rewrite
sudo a2enmod headers
sudo a2dissite 000-default
sudo a2ensite default-ssl
===== Firewall =====
Utilisation d'ufw.
ssh
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 22
https
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 443
nfs
sudo ufw allow from 192.168.1.0/26 proto udp to any port 2049
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 2049
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 111
sudo ufw allow from 192.168.1.0/26 proto udp to any port 111
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 2048
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 4045
gitea https
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 3000
gitea ssh
sudo ufw allow from 192.168.1.0/26 proto tcp to any port 2222
===== msmtp =====
installation
sudo apt install msmtp
sudo apt install msmtp-mta
fichier de configuration globale ''/etc/msmtprc''
# Example for a system wide configuration file
# A system wide configuration file is optional.
# If it exists, it usually defines a default account.
# This allows msmtp to be used like /usr/sbin/sendmail.
account default
# The SMTP smarthost.
host smtp.free.fr
# Construct envelope-from addresses of the form "user@oursite.example".
#auto_from on
#maildomain oursite.example
from maison@beafrancois.fr
# Use TLS.
#tls on
#tls_trust_file /etc/ssl/certs/ca-certificates.crt
# Syslog logging with facility LOG_MAIL instead of the default LOG_USER.
syslog LOG_MAIL
Exemple de commande pour tester le fonctionnement
printf "Subject:DeQuoiOnParle\nLeCorpsDuMessage" | msmtp francois@beafrancois.fr
===== Fail2ban =====
installation
sudo apt install fail2ban
Ajout du fichier de configuration ''/etc/fail2ban/jail.local''
[DEFAULT]
bantime = 1h
destemail = beafrancois@beafrancois.fr
sender = cahute@beafrancois.fr
# to ban & send an e-mail with whois report to the destemail.
action = %(action_mw)s
# same as action_mw but also send relevant log lines
#action = %(action_mwl)s
Pour le port spécial sftp, modifier le fichier ''/etc/fail2ban/jail.d/defaults-debian.conf''
[sshd]
enabled = true
port=ssh,2200