commit 0ecbcf50958ee72b2566f5041c6d2eaa592c1109 Author: Gitea Date: Wed Jul 6 13:20:54 2022 +0200 Initial commit diff --git a/.etckeeper b/.etckeeper new file mode 100755 index 00000000..239bb44d --- /dev/null +++ b/.etckeeper @@ -0,0 +1,4037 @@ +# Generated by etckeeper. Do not edit. + +mkdir -p './X11/xkb' +mkdir -p './aide/aide.conf.d' +mkdir -p './aide/aide.settings.d' +mkdir -p './apache2/mods-available' +mkdir -p './apm/event.d' +mkdir -p './apparmor.d/disable' +mkdir -p './apparmor.d/force-complain' +mkdir -p './apt/auth.conf.d' +mkdir -p './apt/listchanges.conf.d' +mkdir -p './binfmt.d' +mkdir -p './ca-certificates/update.d' +mkdir -p './clamav/onerrorexecute.d' +mkdir -p './clamav/onupdateexecute.d' +mkdir -p './clamav/virusevent.d' +mkdir -p './dbus-1/session.d' +mkdir -p './dbus-1/system.d' +mkdir -p './dovecot/private' +mkdir -p './dpkg/dpkg.cfg.d' +mkdir -p './fail2ban/fail2ban.d' +mkdir -p './gss/mech.d' +mkdir -p './initramfs-tools/hooks' +mkdir -p './initramfs-tools/scripts/init-bottom' +mkdir -p './initramfs-tools/scripts/init-premount' +mkdir -p './initramfs-tools/scripts/init-top' +mkdir -p './initramfs-tools/scripts/local-bottom' +mkdir -p './initramfs-tools/scripts/local-premount' +mkdir -p './initramfs-tools/scripts/local-top' +mkdir -p './initramfs-tools/scripts/nfs-bottom' +mkdir -p './initramfs-tools/scripts/nfs-premount' +mkdir -p './initramfs-tools/scripts/nfs-top' +mkdir -p './initramfs-tools/scripts/panic' +mkdir -p './kernel/install.d' +mkdir -p './libpaper.d' +mkdir -p './logwatch/conf/logfiles' +mkdir -p './logwatch/conf/services' +mkdir -p './logwatch/scripts/services' +mkdir -p './monit/conf-available' +mkdir -p './mysql/conf.d' +mkdir -p './network/if-post-down.d' +mkdir -p './network/if-pre-up.d' +mkdir -p './nginx/modules-available' +mkdir -p './opt' +mkdir -p './php/8.0/cgi/conf.d' +mkdir -p './php/8.0/cli/conf.d' +mkdir -p './php/8.0/fpm/conf.d' +mkdir -p './postfix/dynamicmaps.cf.d' +mkdir -p './postfix/sasl' +mkdir -p './qemu/fsfreeze-hook.d' +mkdir -p './security/limits.d' +mkdir -p './security/namespace.d' +mkdir -p './ssh/ssh_config.d' +mkdir -p './ssh/sshd_config.d' +mkdir -p './ssl/private' +mkdir -p './systemd/network' +mkdir -p './tmpfiles.d' +mkdir -p './udev/hwdb.d' +maybe chmod 0755 '.' +maybe chmod 0700 '.etckeeper' +maybe chmod 0644 '.gitignore' +maybe chmod 0755 'ImageMagick-6' +maybe chmod 0644 'ImageMagick-6/coder.xml' +maybe chmod 0644 'ImageMagick-6/colors.xml' +maybe chmod 0644 'ImageMagick-6/delegates.xml' +maybe chmod 0644 'ImageMagick-6/log.xml' +maybe chmod 0644 'ImageMagick-6/magic.xml' +maybe chmod 0644 'ImageMagick-6/mime.xml' +maybe chmod 0644 'ImageMagick-6/policy.xml' +maybe chmod 0644 'ImageMagick-6/quantization-table.xml' +maybe chmod 0644 'ImageMagick-6/thresholds.xml' +maybe chmod 0644 'ImageMagick-6/type-apple.xml' +maybe chmod 0644 'ImageMagick-6/type-dejavu.xml' +maybe chmod 0644 'ImageMagick-6/type-ghostscript.xml' +maybe chmod 0644 'ImageMagick-6/type-urw-base35.xml' +maybe chmod 0644 'ImageMagick-6/type-windows.xml' +maybe chmod 0644 'ImageMagick-6/type.xml' +maybe chmod 0755 'NetworkManager' +maybe chmod 0755 'NetworkManager/dispatcher.d' +maybe chmod 0755 'NetworkManager/dispatcher.d/cloud-init-hook-network-manager' +maybe chmod 0755 'X11' +maybe chmod 0755 'X11/Xsession.d' +maybe chmod 0644 'X11/Xsession.d/90gpg-agent' +maybe chmod 0755 'X11/xkb' +maybe chmod 0644 'adduser.conf' +maybe chmod 0755 'aide' +maybe chmod 0755 'aide/aide.conf.d' +maybe chmod 0755 'aide/aide.settings.d' +maybe chmod 0755 'alternatives' +maybe chmod 0644 'alternatives/README' +maybe chmod 0755 'amavis' +maybe chmod 0644 'amavis/README.l10n' +maybe chmod 0755 'amavis/conf.d' +maybe chmod 0644 'amavis/conf.d/01-debian' +maybe chmod 0644 'amavis/conf.d/05-domain_id' +maybe chmod 0644 'amavis/conf.d/05-node_id' +maybe chmod 0644 'amavis/conf.d/15-av_scanners' +maybe chmod 0644 'amavis/conf.d/15-content_filter_mode' +maybe chmod 0644 'amavis/conf.d/20-debian_defaults' +maybe chmod 0644 'amavis/conf.d/25-amavis_helpers' +maybe chmod 0644 'amavis/conf.d/30-template_localization' +maybe chmod 0644 'amavis/conf.d/50-user' +maybe chmod 0755 'amavis/en_US' +maybe chmod 0644 'amavis/en_US/charset' +maybe chmod 0644 'amavis/en_US/template-auto-response.txt' +maybe chmod 0644 'amavis/en_US/template-dsn.txt' +maybe chmod 0644 'amavis/en_US/template-problem-feedback.txt' +maybe chmod 0644 'amavis/en_US/template-release-quarantine.txt' +maybe chmod 0644 'amavis/en_US/template-spam-admin.txt' +maybe chmod 0644 'amavis/en_US/template-spam-sender.txt' +maybe chmod 0644 'amavis/en_US/template-virus-admin.txt' +maybe chmod 0644 'amavis/en_US/template-virus-recipient.txt' +maybe chmod 0644 'amavis/en_US/template-virus-sender.txt' +maybe chmod 0755 'apache2' +maybe chmod 0755 'apache2/conf-available' +maybe chmod 0644 'apache2/conf-available/javascript-common.conf' +maybe chmod 0755 'apache2/mods-available' +maybe chmod 0755 'apm' +maybe chmod 0755 'apm/event.d' +maybe chmod 0755 'apparmor' +maybe chmod 0755 'apparmor.d' +maybe chmod 0755 'apparmor.d/abstractions' +maybe chmod 0644 'apparmor.d/abstractions/X' +maybe chmod 0644 'apparmor.d/abstractions/apache2-common' +maybe chmod 0755 'apparmor.d/abstractions/apparmor_api' +maybe chmod 0644 'apparmor.d/abstractions/apparmor_api/change_profile' +maybe chmod 0644 'apparmor.d/abstractions/apparmor_api/examine' +maybe chmod 0644 'apparmor.d/abstractions/apparmor_api/find_mountpoint' +maybe chmod 0644 'apparmor.d/abstractions/apparmor_api/introspect' +maybe chmod 0644 'apparmor.d/abstractions/apparmor_api/is_enabled' +maybe chmod 0644 'apparmor.d/abstractions/aspell' +maybe chmod 0644 'apparmor.d/abstractions/audio' +maybe chmod 0644 'apparmor.d/abstractions/authentication' +maybe chmod 0644 'apparmor.d/abstractions/base' +maybe chmod 0644 'apparmor.d/abstractions/bash' +maybe chmod 0644 'apparmor.d/abstractions/consoles' +maybe chmod 0644 'apparmor.d/abstractions/cups-client' +maybe chmod 0644 'apparmor.d/abstractions/dbus' +maybe chmod 0644 'apparmor.d/abstractions/dbus-accessibility' +maybe chmod 0644 'apparmor.d/abstractions/dbus-accessibility-strict' +maybe chmod 0644 'apparmor.d/abstractions/dbus-network-manager-strict' +maybe chmod 0644 'apparmor.d/abstractions/dbus-session' +maybe chmod 0644 'apparmor.d/abstractions/dbus-session-strict' +maybe chmod 0644 'apparmor.d/abstractions/dbus-strict' +maybe chmod 0644 'apparmor.d/abstractions/dconf' +maybe chmod 0644 'apparmor.d/abstractions/dovecot-common' +maybe chmod 0644 'apparmor.d/abstractions/dri-common' +maybe chmod 0644 'apparmor.d/abstractions/dri-enumerate' +maybe chmod 0644 'apparmor.d/abstractions/enchant' +maybe chmod 0644 'apparmor.d/abstractions/exo-open' +maybe chmod 0644 'apparmor.d/abstractions/fcitx' +maybe chmod 0644 'apparmor.d/abstractions/fcitx-strict' +maybe chmod 0644 'apparmor.d/abstractions/fonts' +maybe chmod 0644 'apparmor.d/abstractions/freedesktop.org' +maybe chmod 0644 'apparmor.d/abstractions/gio-open' +maybe chmod 0644 'apparmor.d/abstractions/gnome' +maybe chmod 0644 'apparmor.d/abstractions/gnupg' +maybe chmod 0644 'apparmor.d/abstractions/gvfs-open' +maybe chmod 0644 'apparmor.d/abstractions/hosts_access' +maybe chmod 0644 'apparmor.d/abstractions/ibus' +maybe chmod 0644 'apparmor.d/abstractions/kde' +maybe chmod 0644 'apparmor.d/abstractions/kde-globals-write' +maybe chmod 0644 'apparmor.d/abstractions/kde-icon-cache-write' +maybe chmod 0644 'apparmor.d/abstractions/kde-language-write' +maybe chmod 0644 'apparmor.d/abstractions/kde-open5' +maybe chmod 0644 'apparmor.d/abstractions/kerberosclient' +maybe chmod 0644 'apparmor.d/abstractions/ldapclient' +maybe chmod 0644 'apparmor.d/abstractions/libpam-systemd' +maybe chmod 0644 'apparmor.d/abstractions/likewise' +maybe chmod 0644 'apparmor.d/abstractions/mdns' +maybe chmod 0644 'apparmor.d/abstractions/mesa' +maybe chmod 0644 'apparmor.d/abstractions/mir' +maybe chmod 0644 'apparmor.d/abstractions/mozc' +maybe chmod 0644 'apparmor.d/abstractions/mysql' +maybe chmod 0644 'apparmor.d/abstractions/nameservice' +maybe chmod 0644 'apparmor.d/abstractions/nis' +maybe chmod 0644 'apparmor.d/abstractions/nvidia' +maybe chmod 0644 'apparmor.d/abstractions/opencl' +maybe chmod 0644 'apparmor.d/abstractions/opencl-common' +maybe chmod 0644 'apparmor.d/abstractions/opencl-intel' +maybe chmod 0644 'apparmor.d/abstractions/opencl-mesa' +maybe chmod 0644 'apparmor.d/abstractions/opencl-nvidia' +maybe chmod 0644 'apparmor.d/abstractions/opencl-pocl' +maybe chmod 0644 'apparmor.d/abstractions/openssl' +maybe chmod 0644 'apparmor.d/abstractions/orbit2' +maybe chmod 0644 'apparmor.d/abstractions/p11-kit' +maybe chmod 0644 'apparmor.d/abstractions/perl' +maybe chmod 0644 'apparmor.d/abstractions/php' +maybe chmod 0644 'apparmor.d/abstractions/php5' +maybe chmod 0644 'apparmor.d/abstractions/postfix-common' +maybe chmod 0644 'apparmor.d/abstractions/private-files' +maybe chmod 0644 'apparmor.d/abstractions/private-files-strict' +maybe chmod 0644 'apparmor.d/abstractions/python' +maybe chmod 0644 'apparmor.d/abstractions/qt5' +maybe chmod 0644 'apparmor.d/abstractions/qt5-compose-cache-write' +maybe chmod 0644 'apparmor.d/abstractions/qt5-settings-write' +maybe chmod 0644 'apparmor.d/abstractions/recent-documents-write' +maybe chmod 0644 'apparmor.d/abstractions/ruby' +maybe chmod 0644 'apparmor.d/abstractions/samba' +maybe chmod 0644 'apparmor.d/abstractions/smbpass' +maybe chmod 0644 'apparmor.d/abstractions/ssl_certs' +maybe chmod 0644 'apparmor.d/abstractions/ssl_keys' +maybe chmod 0644 'apparmor.d/abstractions/svn-repositories' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-bittorrent-clients' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers' +maybe chmod 0755 'apparmor.d/abstractions/ubuntu-browsers.d' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/java' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/kde' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/mailto' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/multimedia' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/plugins-common' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/productivity' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/text-editors' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration-xul' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-browsers.d/user-files' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-console-browsers' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-console-email' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-email' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-feed-readers' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-gnome-terminal' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-helpers' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-konsole' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-media-players' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-unity7-base' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-unity7-launcher' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-unity7-messaging' +maybe chmod 0644 'apparmor.d/abstractions/ubuntu-xterm' +maybe chmod 0644 'apparmor.d/abstractions/user-download' +maybe chmod 0644 'apparmor.d/abstractions/user-mail' +maybe chmod 0644 'apparmor.d/abstractions/user-manpages' +maybe chmod 0644 'apparmor.d/abstractions/user-tmp' +maybe chmod 0644 'apparmor.d/abstractions/user-write' +maybe chmod 0644 'apparmor.d/abstractions/video' +maybe chmod 0644 'apparmor.d/abstractions/vulkan' +maybe chmod 0644 'apparmor.d/abstractions/wayland' +maybe chmod 0644 'apparmor.d/abstractions/web-data' +maybe chmod 0644 'apparmor.d/abstractions/winbind' +maybe chmod 0644 'apparmor.d/abstractions/wutmp' +maybe chmod 0644 'apparmor.d/abstractions/xad' +maybe chmod 0644 'apparmor.d/abstractions/xdg-desktop' +maybe chmod 0644 'apparmor.d/abstractions/xdg-open' +maybe chmod 0755 'apparmor.d/disable' +maybe chmod 0755 'apparmor.d/force-complain' +maybe chmod 0755 'apparmor.d/local' +maybe chmod 0644 'apparmor.d/local/README' +maybe chmod 0644 'apparmor.d/local/lsb_release' +maybe chmod 0644 'apparmor.d/local/nvidia_modprobe' +maybe chmod 0644 'apparmor.d/local/usr.bin.man' +maybe chmod 0644 'apparmor.d/lsb_release' +maybe chmod 0644 'apparmor.d/nvidia_modprobe' +maybe chmod 0755 'apparmor.d/tunables' +maybe chmod 0644 'apparmor.d/tunables/alias' +maybe chmod 0644 'apparmor.d/tunables/apparmorfs' +maybe chmod 0644 'apparmor.d/tunables/dovecot' +maybe chmod 0644 'apparmor.d/tunables/global' +maybe chmod 0644 'apparmor.d/tunables/home' +maybe chmod 0755 'apparmor.d/tunables/home.d' +maybe chmod 0644 'apparmor.d/tunables/home.d/site.local' +maybe chmod 0644 'apparmor.d/tunables/home.d/ubuntu' +maybe chmod 0644 'apparmor.d/tunables/kernelvars' +maybe chmod 0644 'apparmor.d/tunables/multiarch' +maybe chmod 0755 'apparmor.d/tunables/multiarch.d' +maybe chmod 0644 'apparmor.d/tunables/multiarch.d/site.local' +maybe chmod 0644 'apparmor.d/tunables/proc' +maybe chmod 0644 'apparmor.d/tunables/run' +maybe chmod 0644 'apparmor.d/tunables/securityfs' +maybe chmod 0644 'apparmor.d/tunables/share' +maybe chmod 0644 'apparmor.d/tunables/sys' +maybe chmod 0644 'apparmor.d/tunables/xdg-user-dirs' +maybe chmod 0755 'apparmor.d/tunables/xdg-user-dirs.d' +maybe chmod 0644 'apparmor.d/tunables/xdg-user-dirs.d/site.local' +maybe chmod 0644 'apparmor.d/usr.bin.man' +maybe chmod 0644 'apparmor.d/usr.sbin.mariadbd' +maybe chmod 0755 'apparmor/init' +maybe chmod 0755 'apparmor/init/network-interface-security' +maybe chmod 0644 'apparmor/parser.conf' +maybe chmod 0755 'apt' +maybe chmod 0755 'apt/apt.conf.d' +maybe chmod 0644 'apt/apt.conf.d/00CDMountPoint' +maybe chmod 0644 'apt/apt.conf.d/00trustcdrom' +maybe chmod 0644 'apt/apt.conf.d/01autoremove' +maybe chmod 0444 'apt/apt.conf.d/01autoremove-kernels' +maybe chmod 0644 'apt/apt.conf.d/05etckeeper' +maybe chmod 0644 'apt/apt.conf.d/20listchanges' +maybe chmod 0644 'apt/apt.conf.d/70debconf' +maybe chmod 0755 'apt/auth.conf.d' +maybe chmod 0755 'apt/keyrings' +maybe chmod 0644 'apt/keyrings/rspamd.gpg' +maybe chmod 0644 'apt/listchanges.conf' +maybe chmod 0755 'apt/listchanges.conf.d' +maybe chmod 0755 'apt/preferences.d' +maybe chmod 0644 'apt/preferences.d/mariadb-enterprise.pref' +maybe chmod 0644 'apt/sources.list' +maybe chmod 0755 'apt/sources.list.d' +maybe chmod 0644 'apt/sources.list.d/mariadb.list' +maybe chmod 0644 'apt/sources.list.d/php.list' +maybe chmod 0644 'apt/sources.list.d/rspamd.list' +maybe chmod 0755 'apt/trusted.gpg.d' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-bullseye-automatic.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-bullseye-security-automatic.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-bullseye-stable.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-buster-automatic.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-buster-security-automatic.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-buster-stable.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-stretch-automatic.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-stretch-security-automatic.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/debian-archive-stretch-stable.gpg' +maybe chmod 0644 'apt/trusted.gpg.d/mariadb-keyring-2019.gpg' +maybe chmod 0644 'bash.bashrc' +maybe chmod 0644 'bash_completion' +maybe chmod 0755 'bash_completion.d' +maybe chmod 0644 'bash_completion.d/git-prompt' +maybe chmod 0644 'bindresvport.blacklist' +maybe chmod 0755 'binfmt.d' +maybe chmod 0755 'ca-certificates' +maybe chmod 0644 'ca-certificates.conf' +maybe chmod 0755 'ca-certificates/update.d' +maybe chmod 0755 'calendar' +maybe chmod 0644 'calendar/default' +maybe chmod 0755 'clamav' +maybe chmod 0755 'clamav-unofficial-sigs' +maybe chmod 0644 'clamav-unofficial-sigs/master.conf' +maybe chmod 0644 'clamav-unofficial-sigs/os.conf' +maybe chmod 0644 'clamav-unofficial-sigs/user.conf' +maybe chmod 0644 'clamav/clamd.conf' +maybe chmod 0644 'clamav/freshclam.conf' +maybe chmod 0755 'clamav/onerrorexecute.d' +maybe chmod 0755 'clamav/onupdateexecute.d' +maybe chmod 0755 'clamav/virusevent.d' +maybe chmod 0755 'cloud' +maybe chmod 0644 'cloud/cloud-init.disabled' +maybe chmod 0644 'cloud/cloud.cfg' +maybe chmod 0755 'cloud/cloud.cfg.d' +maybe chmod 0644 'cloud/cloud.cfg.d/00_debian.cfg' +maybe chmod 0644 'cloud/cloud.cfg.d/05_logging.cfg' +maybe chmod 0644 'cloud/cloud.cfg.d/99_nc.cfg' +maybe chmod 0644 'cloud/cloud.cfg.d/99_nc_network_disable.cfg' +maybe chmod 0644 'cloud/cloud.cfg.d/README' +maybe chmod 0755 'cloud/templates' +maybe chmod 0644 'cloud/templates/chef_client.rb.tmpl' +maybe chmod 0644 'cloud/templates/chrony.conf.alpine.tmpl' +maybe chmod 0644 'cloud/templates/chrony.conf.debian.tmpl' +maybe chmod 0644 'cloud/templates/chrony.conf.fedora.tmpl' +maybe chmod 0644 'cloud/templates/chrony.conf.opensuse.tmpl' +maybe chmod 0644 'cloud/templates/chrony.conf.rhel.tmpl' +maybe chmod 0644 'cloud/templates/chrony.conf.sles.tmpl' +maybe chmod 0644 'cloud/templates/chrony.conf.ubuntu.tmpl' +maybe chmod 0644 'cloud/templates/hosts.alpine.tmpl' +maybe chmod 0644 'cloud/templates/hosts.debian.tmpl' +maybe chmod 0644 'cloud/templates/hosts.freebsd.tmpl' +maybe chmod 0644 'cloud/templates/hosts.redhat.tmpl' +maybe chmod 0644 'cloud/templates/hosts.suse.tmpl' +maybe chmod 0644 'cloud/templates/ntp.conf.alpine.tmpl' +maybe chmod 0644 'cloud/templates/ntp.conf.debian.tmpl' +maybe chmod 0644 'cloud/templates/ntp.conf.fedora.tmpl' +maybe chmod 0644 'cloud/templates/ntp.conf.opensuse.tmpl' +maybe chmod 0644 'cloud/templates/ntp.conf.rhel.tmpl' +maybe chmod 0644 'cloud/templates/ntp.conf.sles.tmpl' +maybe chmod 0644 'cloud/templates/ntp.conf.ubuntu.tmpl' +maybe chmod 0644 'cloud/templates/resolv.conf.tmpl' +maybe chmod 0644 'cloud/templates/sources.list.debian.tmpl' +maybe chmod 0644 'cloud/templates/sources.list.ubuntu.tmpl' +maybe chmod 0644 'cloud/templates/timesyncd.conf.tmpl' +maybe chmod 0755 'console-setup' +maybe chmod 0644 'console-setup/cached_Lat15-Fixed16.psf.gz' +maybe chmod 0644 'console-setup/cached_Lat15-VGA16.psf.gz' +maybe chmod 0644 'console-setup/cached_UTF-8_del.kmap.gz' +maybe chmod 0755 'console-setup/cached_setup_font.sh' +maybe chmod 0755 'console-setup/cached_setup_keyboard.sh' +maybe chmod 0755 'console-setup/cached_setup_terminal.sh' +maybe chmod 0644 'console-setup/compose.ARMSCII-8.inc' +maybe chmod 0644 'console-setup/compose.CP1251.inc' +maybe chmod 0644 'console-setup/compose.CP1255.inc' +maybe chmod 0644 'console-setup/compose.CP1256.inc' +maybe chmod 0644 'console-setup/compose.GEORGIAN-ACADEMY.inc' +maybe chmod 0644 'console-setup/compose.GEORGIAN-PS.inc' +maybe chmod 0644 'console-setup/compose.IBM1133.inc' +maybe chmod 0644 'console-setup/compose.ISIRI-3342.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-1.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-10.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-11.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-13.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-14.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-15.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-16.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-2.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-3.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-4.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-5.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-6.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-7.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-8.inc' +maybe chmod 0644 'console-setup/compose.ISO-8859-9.inc' +maybe chmod 0644 'console-setup/compose.KOI8-R.inc' +maybe chmod 0644 'console-setup/compose.KOI8-U.inc' +maybe chmod 0644 'console-setup/compose.TIS-620.inc' +maybe chmod 0644 'console-setup/compose.VISCII.inc' +maybe chmod 0644 'console-setup/remap.inc' +maybe chmod 0755 'cron.d' +maybe chmod 0644 'cron.d/.placeholder' +maybe chmod 0644 'cron.d/e2scrub_all' +maybe chmod 0644 'cron.d/kernel' +maybe chmod 0644 'cron.d/php' +maybe chmod 0755 'cron.daily' +maybe chmod 0644 'cron.daily/.placeholder' +maybe chmod 0755 'cron.daily/apt-compat' +maybe chmod 0755 'cron.daily/dpkg' +maybe chmod 0755 'cron.daily/etckeeper' +maybe chmod 0755 'cron.daily/logrotate' +maybe chmod 0755 'cron.daily/man-db' +maybe chmod 0755 'cron.hourly' +maybe chmod 0644 'cron.hourly/.placeholder' +maybe chmod 0755 'cron.monthly' +maybe chmod 0644 'cron.monthly/.placeholder' +maybe chmod 0755 'cron.weekly' +maybe chmod 0644 'cron.weekly/.placeholder' +maybe chmod 0755 'cron.weekly/man-db' +maybe chmod 0644 'crontab' +maybe chmod 0755 'cruft' +maybe chmod 0755 'cruft/filters-unex' +maybe chmod 0644 'cruft/filters-unex/etckeeper' +maybe chmod 0755 'dbus-1' +maybe chmod 0755 'dbus-1/session.d' +maybe chmod 0755 'dbus-1/system.d' +maybe chmod 0644 'debconf.conf' +maybe chmod 0644 'debian_version' +maybe chmod 0755 'default' +maybe chmod 0644 'default/console-setup' +maybe chmod 0644 'default/cron' +maybe chmod 0644 'default/dbus' +maybe chmod 0644 'default/fail2ban' +maybe chmod 0644 'default/grub' +maybe chmod 0755 'default/grub.d' +maybe chmod 0644 'default/grub.d/init-select.cfg' +maybe chmod 0644 'default/hwclock' +maybe chmod 0644 'default/keyboard' +maybe chmod 0644 'default/locale' +maybe chmod 0644 'default/networking' +maybe chmod 0644 'default/nginx' +maybe chmod 0644 'default/nss' +maybe chmod 0644 'default/redis-server' +maybe chmod 0644 'default/rsync' +maybe chmod 0644 'default/ssh' +maybe chmod 0644 'default/useradd' +maybe chmod 0644 'deluser.conf' +maybe chmod 0755 'dhcp' +maybe chmod 0644 'dhcp/debug' +maybe chmod 0755 'dhcp/dhclient-enter-hooks.d' +maybe chmod 0755 'dhcp/dhclient-exit-hooks.d' +maybe chmod 0755 'dhcp/dhclient-exit-hooks.d/hook-dhclient' +maybe chmod 0644 'dhcp/dhclient-exit-hooks.d/rfc3442-classless-routes' +maybe chmod 0644 'dhcp/dhclient-exit-hooks.d/timesyncd' +maybe chmod 0644 'dhcp/dhclient.conf' +maybe chmod 0755 'dictionaries-common' +maybe chmod 0644 'discover-modprobe.conf' +maybe chmod 0755 'discover.conf.d' +maybe chmod 0644 'discover.conf.d/00discover' +maybe chmod 0755 'dkimkeys' +maybe chmod 0644 'dkimkeys/README.PrivateKeys' +maybe chmod 0755 'dkms' +maybe chmod 0644 'dkms/framework.conf' +maybe chmod 0755 'dkms/template-dkms-mkbmdeb' +maybe chmod 0644 'dkms/template-dkms-mkbmdeb/Makefile' +maybe chmod 0755 'dkms/template-dkms-mkbmdeb/debian' +maybe chmod 0644 'dkms/template-dkms-mkbmdeb/debian/README.Debian' +maybe chmod 0644 'dkms/template-dkms-mkbmdeb/debian/changelog' +maybe chmod 0644 'dkms/template-dkms-mkbmdeb/debian/compat' +maybe chmod 0644 'dkms/template-dkms-mkbmdeb/debian/control' +maybe chmod 0644 'dkms/template-dkms-mkbmdeb/debian/copyright' +maybe chmod 0755 'dkms/template-dkms-mkbmdeb/debian/rules' +maybe chmod 0755 'dkms/template-dkms-mkdeb' +maybe chmod 0644 'dkms/template-dkms-mkdeb/Makefile' +maybe chmod 0755 'dkms/template-dkms-mkdeb/debian' +maybe chmod 0644 'dkms/template-dkms-mkdeb/debian/README.Debian' +maybe chmod 0644 'dkms/template-dkms-mkdeb/debian/changelog' +maybe chmod 0644 'dkms/template-dkms-mkdeb/debian/compat' +maybe chmod 0644 'dkms/template-dkms-mkdeb/debian/control' +maybe chmod 0644 'dkms/template-dkms-mkdeb/debian/copyright' +maybe chmod 0644 'dkms/template-dkms-mkdeb/debian/dirs' +maybe chmod 0755 'dkms/template-dkms-mkdeb/debian/postinst' +maybe chmod 0755 'dkms/template-dkms-mkdeb/debian/prerm' +maybe chmod 0755 'dkms/template-dkms-mkdeb/debian/rules' +maybe chmod 0755 'dovecot' +maybe chmod 0755 'dovecot/conf.d' +maybe chmod 0644 'dovecot/conf.d/10-ssl.conf' +maybe chmod 0644 'dovecot/conf.d/20-imap.conf' +maybe chmod 0644 'dovecot/conf.d/90-sieve.conf' +maybe chmod 0644 'dovecot/dovecot-mysql.conf' +maybe chmod 0644 'dovecot/dovecot.conf' +maybe chmod 0755 'dovecot/private' +maybe chmod 0755 'dovecot/sieve' +maybe chmod 0755 'dovecot/sieve-after' +maybe chmod 0644 'dovecot/sieve-after/spam-to-folder.sieve' +maybe chmod 0644 'dovecot/sieve-after/spam-to-folder.svbin' +maybe chmod 0644 'dovecot/sieve/learn-ham.sieve' +maybe chmod 0644 'dovecot/sieve/learn-spam.sieve' +maybe chmod 0644 'dovecot/ssl-params.conf' +maybe chmod 0755 'dpkg' +maybe chmod 0644 'dpkg/dpkg.cfg' +maybe chmod 0755 'dpkg/dpkg.cfg.d' +maybe chmod 0755 'dpkg/origins' +maybe chmod 0644 'dpkg/origins/debian' +maybe chmod 0644 'e2scrub.conf' +maybe chmod 0755 'emacs' +maybe chmod 0755 'emacs/site-start.d' +maybe chmod 0644 'emacs/site-start.d/50dictionaries-common.el' +maybe chmod 0644 'environment' +maybe chmod 0755 'etckeeper' +maybe chmod 0755 'etckeeper/commit.d' +maybe chmod 0755 'etckeeper/commit.d/10vcs-test' +maybe chmod 0755 'etckeeper/commit.d/30bzr-add' +maybe chmod 0755 'etckeeper/commit.d/30darcs-add' +maybe chmod 0755 'etckeeper/commit.d/30git-add' +maybe chmod 0755 'etckeeper/commit.d/30hg-addremove' +maybe chmod 0755 'etckeeper/commit.d/50vcs-commit' +maybe chmod 0755 'etckeeper/commit.d/60-push' +maybe chmod 0755 'etckeeper/commit.d/99push' +maybe chmod 0644 'etckeeper/commit.d/README' +maybe chmod 0755 'etckeeper/daily' +maybe chmod 0644 'etckeeper/etckeeper.conf' +maybe chmod 0755 'etckeeper/init.d' +maybe chmod 0755 'etckeeper/init.d/10restore-metadata' +maybe chmod 0755 'etckeeper/init.d/20restore-etckeeper' +maybe chmod 0755 'etckeeper/init.d/40vcs-init' +maybe chmod 0755 'etckeeper/init.d/50vcs-ignore' +maybe chmod 0755 'etckeeper/init.d/50vcs-perm' +maybe chmod 0755 'etckeeper/init.d/50vcs-pre-commit-hook' +maybe chmod 0755 'etckeeper/init.d/60darcs-deleted-symlinks' +maybe chmod 0755 'etckeeper/init.d/70vcs-add' +maybe chmod 0644 'etckeeper/init.d/README' +maybe chmod 0755 'etckeeper/list-installed.d' +maybe chmod 0755 'etckeeper/list-installed.d/50list-installed' +maybe chmod 0755 'etckeeper/post-install.d' +maybe chmod 0755 'etckeeper/post-install.d/50vcs-commit' +maybe chmod 0644 'etckeeper/post-install.d/README' +maybe chmod 0755 'etckeeper/pre-commit.d' +maybe chmod 0755 'etckeeper/pre-commit.d/20warn-problem-files' +maybe chmod 0755 'etckeeper/pre-commit.d/30store-metadata' +maybe chmod 0644 'etckeeper/pre-commit.d/README' +maybe chmod 0755 'etckeeper/pre-install.d' +maybe chmod 0755 'etckeeper/pre-install.d/10packagelist' +maybe chmod 0755 'etckeeper/pre-install.d/50uncommitted-changes' +maybe chmod 0644 'etckeeper/pre-install.d/README' +maybe chmod 0755 'etckeeper/unclean.d' +maybe chmod 0755 'etckeeper/unclean.d/50test' +maybe chmod 0644 'etckeeper/unclean.d/README' +maybe chmod 0755 'etckeeper/uninit.d' +maybe chmod 0755 'etckeeper/uninit.d/01prompt' +maybe chmod 0755 'etckeeper/uninit.d/50remove-metadata' +maybe chmod 0755 'etckeeper/uninit.d/50vcs-uninit' +maybe chmod 0644 'etckeeper/uninit.d/README' +maybe chmod 0755 'etckeeper/update-ignore.d' +maybe chmod 0755 'etckeeper/update-ignore.d/01update-ignore' +maybe chmod 0644 'etckeeper/update-ignore.d/README' +maybe chmod 0755 'etckeeper/vcs.d' +maybe chmod 0755 'etckeeper/vcs.d/50vcs-cmd' +maybe chmod 0644 'ethertypes' +maybe chmod 0755 'fail2ban' +maybe chmod 0755 'fail2ban/action.d' +maybe chmod 0644 'fail2ban/action.d/abuseipdb.conf' +maybe chmod 0644 'fail2ban/action.d/apf.conf' +maybe chmod 0644 'fail2ban/action.d/badips.conf' +maybe chmod 0644 'fail2ban/action.d/badips.py' +maybe chmod 0644 'fail2ban/action.d/blocklist_de.conf' +maybe chmod 0644 'fail2ban/action.d/bsd-ipfw.conf' +maybe chmod 0644 'fail2ban/action.d/cloudflare.conf' +maybe chmod 0644 'fail2ban/action.d/complain.conf' +maybe chmod 0644 'fail2ban/action.d/dshield.conf' +maybe chmod 0644 'fail2ban/action.d/dummy.conf' +maybe chmod 0644 'fail2ban/action.d/firewallcmd-allports.conf' +maybe chmod 0644 'fail2ban/action.d/firewallcmd-common.conf' +maybe chmod 0644 'fail2ban/action.d/firewallcmd-ipset.conf' +maybe chmod 0644 'fail2ban/action.d/firewallcmd-multiport.conf' +maybe chmod 0644 'fail2ban/action.d/firewallcmd-new.conf' +maybe chmod 0644 'fail2ban/action.d/firewallcmd-rich-logging.conf' +maybe chmod 0644 'fail2ban/action.d/firewallcmd-rich-rules.conf' +maybe chmod 0644 'fail2ban/action.d/helpers-common.conf' +maybe chmod 0644 'fail2ban/action.d/hostsdeny.conf' +maybe chmod 0644 'fail2ban/action.d/ipfilter.conf' +maybe chmod 0644 'fail2ban/action.d/ipfw.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-allports.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-blocktype.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-common.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-ipset-proto4.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-ipset-proto6-allports.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-ipset-proto6.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-multiport-log.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-multiport.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-new.conf' +maybe chmod 0644 'fail2ban/action.d/iptables-xt_recent-echo.conf' +maybe chmod 0644 'fail2ban/action.d/iptables.conf' +maybe chmod 0644 'fail2ban/action.d/mail-buffered.conf' +maybe chmod 0644 'fail2ban/action.d/mail-whois-common.conf' +maybe chmod 0644 'fail2ban/action.d/mail-whois-lines.conf' +maybe chmod 0644 'fail2ban/action.d/mail-whois.conf' +maybe chmod 0644 'fail2ban/action.d/mail.conf' +maybe chmod 0644 'fail2ban/action.d/mynetwatchman.conf' +maybe chmod 0644 'fail2ban/action.d/netscaler.conf' +maybe chmod 0644 'fail2ban/action.d/nftables-allports.conf' +maybe chmod 0644 'fail2ban/action.d/nftables-common.conf' +maybe chmod 0644 'fail2ban/action.d/nftables-multiport.conf' +maybe chmod 0644 'fail2ban/action.d/nftables.conf' +maybe chmod 0644 'fail2ban/action.d/nginx-block-map.conf' +maybe chmod 0644 'fail2ban/action.d/npf.conf' +maybe chmod 0644 'fail2ban/action.d/nsupdate.conf' +maybe chmod 0644 'fail2ban/action.d/osx-afctl.conf' +maybe chmod 0644 'fail2ban/action.d/osx-ipfw.conf' +maybe chmod 0644 'fail2ban/action.d/pf.conf' +maybe chmod 0644 'fail2ban/action.d/route.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-buffered.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-common.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-geoip-lines.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-whois-ipjailmatches.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-whois-ipmatches.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-whois-lines.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-whois-matches.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail-whois.conf' +maybe chmod 0644 'fail2ban/action.d/sendmail.conf' +maybe chmod 0644 'fail2ban/action.d/shorewall-ipset-proto6.conf' +maybe chmod 0644 'fail2ban/action.d/shorewall.conf' +maybe chmod 0644 'fail2ban/action.d/smtp.py' +maybe chmod 0644 'fail2ban/action.d/symbiosis-blacklist-allports.conf' +maybe chmod 0644 'fail2ban/action.d/ufw.conf' +maybe chmod 0644 'fail2ban/action.d/xarf-login-attack.conf' +maybe chmod 0644 'fail2ban/fail2ban.conf' +maybe chmod 0755 'fail2ban/fail2ban.d' +maybe chmod 0755 'fail2ban/filter.d' +maybe chmod 0644 'fail2ban/filter.d/3proxy.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-badbots.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-botsearch.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-common.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-ddos.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-fakegooglebot.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-modsec.conf.test' +maybe chmod 0644 'fail2ban/filter.d/apache-modsecurity.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-nohome.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-noscript.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-overflows.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-pass.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-searx.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-shellshock.conf' +maybe chmod 0644 'fail2ban/filter.d/apache-wootwoot.conf' +maybe chmod 0644 'fail2ban/filter.d/assp.conf' +maybe chmod 0644 'fail2ban/filter.d/asterisk.conf' +maybe chmod 0644 'fail2ban/filter.d/bitwarden.conf' +maybe chmod 0644 'fail2ban/filter.d/botsearch-common.conf' +maybe chmod 0644 'fail2ban/filter.d/centreon.conf' +maybe chmod 0644 'fail2ban/filter.d/common.conf' +maybe chmod 0644 'fail2ban/filter.d/counter-strike.conf' +maybe chmod 0644 'fail2ban/filter.d/courier-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/courier-smtp.conf' +maybe chmod 0644 'fail2ban/filter.d/cyrus-imap.conf' +maybe chmod 0644 'fail2ban/filter.d/directadmin.conf' +maybe chmod 0644 'fail2ban/filter.d/domino-smtp.conf' +maybe chmod 0644 'fail2ban/filter.d/dovecot-pop3imap.conf' +maybe chmod 0644 'fail2ban/filter.d/dovecot.conf' +maybe chmod 0644 'fail2ban/filter.d/dropbear.conf' +maybe chmod 0644 'fail2ban/filter.d/drupal-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/ejabberd-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/exim-common.conf' +maybe chmod 0644 'fail2ban/filter.d/exim-spam.conf' +maybe chmod 0644 'fail2ban/filter.d/exim.conf' +maybe chmod 0644 'fail2ban/filter.d/eximhelo.conf' +maybe chmod 0644 'fail2ban/filter.d/freeswitch.conf' +maybe chmod 0644 'fail2ban/filter.d/froxlor-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/gitea.conf' +maybe chmod 0644 'fail2ban/filter.d/gitlab.conf' +maybe chmod 0644 'fail2ban/filter.d/grafana.conf' +maybe chmod 0644 'fail2ban/filter.d/groupoffice.conf' +maybe chmod 0644 'fail2ban/filter.d/gssftpd.conf' +maybe chmod 0644 'fail2ban/filter.d/guacamole.conf' +maybe chmod 0644 'fail2ban/filter.d/haproxy-http-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/horde.conf' +maybe chmod 0755 'fail2ban/filter.d/ignorecommands' +maybe chmod 0755 'fail2ban/filter.d/ignorecommands/apache-fakegooglebot' +maybe chmod 0644 'fail2ban/filter.d/kerio.conf' +maybe chmod 0644 'fail2ban/filter.d/lighttpd-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/lighttpd-fastcgi.conf' +maybe chmod 0644 'fail2ban/filter.d/modsec.conf' +maybe chmod 0644 'fail2ban/filter.d/mongodb-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/monit.conf' +maybe chmod 0644 'fail2ban/filter.d/murmur.conf' +maybe chmod 0644 'fail2ban/filter.d/mysqld-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/nagios.conf' +maybe chmod 0644 'fail2ban/filter.d/named-refused.conf' +maybe chmod 0644 'fail2ban/filter.d/nginx-botsearch.conf' +maybe chmod 0644 'fail2ban/filter.d/nginx-http-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/nginx-limit-req.conf' +maybe chmod 0644 'fail2ban/filter.d/nsd.conf' +maybe chmod 0644 'fail2ban/filter.d/openhab.conf' +maybe chmod 0644 'fail2ban/filter.d/openwebmail.conf' +maybe chmod 0644 'fail2ban/filter.d/oracleims.conf' +maybe chmod 0644 'fail2ban/filter.d/pam-generic.conf' +maybe chmod 0644 'fail2ban/filter.d/perdition.conf' +maybe chmod 0644 'fail2ban/filter.d/php-cgi.conf' +maybe chmod 0644 'fail2ban/filter.d/php-myadmin.conf' +maybe chmod 0644 'fail2ban/filter.d/php-url-fopen.conf' +maybe chmod 0644 'fail2ban/filter.d/phpmyadmin-syslog.conf' +maybe chmod 0644 'fail2ban/filter.d/portsentry.conf' +maybe chmod 0644 'fail2ban/filter.d/postfix-rbl.conf' +maybe chmod 0644 'fail2ban/filter.d/postfix-sasl.conf' +maybe chmod 0644 'fail2ban/filter.d/postfix.conf' +maybe chmod 0644 'fail2ban/filter.d/proftpd.conf' +maybe chmod 0644 'fail2ban/filter.d/pure-ftpd.conf' +maybe chmod 0644 'fail2ban/filter.d/qmail.conf' +maybe chmod 0644 'fail2ban/filter.d/recidive.conf' +maybe chmod 0644 'fail2ban/filter.d/roundcube-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/sasl.conf' +maybe chmod 0644 'fail2ban/filter.d/screensharingd.conf' +maybe chmod 0644 'fail2ban/filter.d/selinux-common.conf' +maybe chmod 0644 'fail2ban/filter.d/selinux-ssh.conf' +maybe chmod 0644 'fail2ban/filter.d/sendmail-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/sendmail-reject.conf' +maybe chmod 0644 'fail2ban/filter.d/sieve.conf' +maybe chmod 0644 'fail2ban/filter.d/slapd.conf' +maybe chmod 0644 'fail2ban/filter.d/softethervpn.conf' +maybe chmod 0644 'fail2ban/filter.d/sogo-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/solid-pop3d.conf' +maybe chmod 0644 'fail2ban/filter.d/squid.conf' +maybe chmod 0644 'fail2ban/filter.d/squirrelmail.conf' +maybe chmod 0644 'fail2ban/filter.d/sshd-ddos.conf' +maybe chmod 0644 'fail2ban/filter.d/sshd.conf' +maybe chmod 0644 'fail2ban/filter.d/stunnel.conf' +maybe chmod 0644 'fail2ban/filter.d/suhosin.conf' +maybe chmod 0644 'fail2ban/filter.d/tine20.conf' +maybe chmod 0644 'fail2ban/filter.d/traefik-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/uwimap-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/vsftpd.conf' +maybe chmod 0644 'fail2ban/filter.d/webmin-auth.conf' +maybe chmod 0644 'fail2ban/filter.d/wp-spam.conf' +maybe chmod 0644 'fail2ban/filter.d/wuftpd.conf' +maybe chmod 0644 'fail2ban/filter.d/xinetd-fail.conf' +maybe chmod 0644 'fail2ban/filter.d/znc-adminlog.conf' +maybe chmod 0644 'fail2ban/filter.d/zoneminder.conf' +maybe chmod 0644 'fail2ban/ip.blacklist' +maybe chmod 0644 'fail2ban/jail.conf' +maybe chmod 0755 'fail2ban/jail.d' +maybe chmod 0644 'fail2ban/jail.d/defaults-debian.conf' +maybe chmod 0644 'fail2ban/jail.local' +maybe chmod 0644 'fail2ban/paths-arch.conf' +maybe chmod 0644 'fail2ban/paths-common.conf' +maybe chmod 0644 'fail2ban/paths-debian.conf' +maybe chmod 0644 'fail2ban/paths-opensuse.conf' +maybe chmod 0755 'fonts' +maybe chmod 0755 'fonts/conf.avail' +maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-lgc-sans-mono.conf' +maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-lgc-sans.conf' +maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-lgc-serif.conf' +maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-sans-mono.conf' +maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-sans.conf' +maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-serif.conf' +maybe chmod 0644 'fonts/conf.avail/30-droid-noto-mono.conf' +maybe chmod 0644 'fonts/conf.avail/57-dejavu-sans-mono.conf' +maybe chmod 0644 'fonts/conf.avail/57-dejavu-sans.conf' +maybe chmod 0644 'fonts/conf.avail/57-dejavu-serif.conf' +maybe chmod 0644 'fonts/conf.avail/58-dejavu-lgc-sans-mono.conf' +maybe chmod 0644 'fonts/conf.avail/58-dejavu-lgc-sans.conf' +maybe chmod 0644 'fonts/conf.avail/58-dejavu-lgc-serif.conf' +maybe chmod 0644 'fonts/conf.avail/65-droid-sans-fallback.conf' +maybe chmod 0755 'fonts/conf.d' +maybe chmod 0644 'fonts/conf.d/README' +maybe chmod 0644 'fonts/fonts.conf' +maybe chmod 0644 'fstab' +maybe chmod 0644 'fuse.conf' +maybe chmod 0644 'gai.conf' +maybe chmod 0755 'ghostscript' +maybe chmod 0755 'ghostscript/cidfmap.d' +maybe chmod 0644 'ghostscript/cidfmap.d/90gs-cjk-resource-cns1.conf' +maybe chmod 0644 'ghostscript/cidfmap.d/90gs-cjk-resource-gb1.conf' +maybe chmod 0644 'ghostscript/cidfmap.d/90gs-cjk-resource-japan1.conf' +maybe chmod 0644 'ghostscript/cidfmap.d/90gs-cjk-resource-japan2.conf' +maybe chmod 0644 'ghostscript/cidfmap.d/90gs-cjk-resource-korea1.conf' +maybe chmod 0755 'ghostscript/fontmap.d' +maybe chmod 0644 'ghostscript/fontmap.d/10gsfonts.conf' +maybe chmod 0755 'groff' +maybe chmod 0644 'groff/man.local' +maybe chmod 0644 'groff/mdoc.local' +maybe chmod 0644 'group' +maybe chmod 0644 'group-' +maybe chmod 0644 'group.org' +maybe chmod 0755 'grub.d' +maybe chmod 0755 'grub.d/00_header' +maybe chmod 0755 'grub.d/05_debian_theme' +maybe chmod 0755 'grub.d/10_linux' +maybe chmod 0755 'grub.d/20_linux_xen' +maybe chmod 0755 'grub.d/30_os-prober' +maybe chmod 0755 'grub.d/30_uefi-firmware' +maybe chmod 0755 'grub.d/40_custom' +maybe chmod 0755 'grub.d/41_custom' +maybe chmod 0644 'grub.d/README' +maybe chgrp 'shadow' 'gshadow' +maybe chmod 0640 'gshadow' +maybe chgrp 'shadow' 'gshadow-' +maybe chmod 0640 'gshadow-' +maybe chmod 0755 'gss' +maybe chmod 0755 'gss/mech.d' +maybe chmod 0644 'hdparm.conf' +maybe chmod 0644 'host.conf' +maybe chmod 0644 'hostname' +maybe chmod 0644 'hosts' +maybe chmod 0644 'hosts.allow' +maybe chmod 0644 'hosts.deny' +maybe chmod 0755 'init.d' +maybe chmod 0755 'init.d/apparmor' +maybe chmod 0755 'init.d/cloud-config' +maybe chmod 0755 'init.d/cloud-final' +maybe chmod 0755 'init.d/cloud-init' +maybe chmod 0755 'init.d/cloud-init-local' +maybe chmod 0755 'init.d/console-setup.sh' +maybe chmod 0755 'init.d/cron' +maybe chmod 0755 'init.d/dbus' +maybe chmod 0755 'init.d/fail2ban' +maybe chmod 0755 'init.d/hwclock.sh' +maybe chmod 0755 'init.d/keyboard-setup.sh' +maybe chmod 0755 'init.d/kmod' +maybe chmod 0755 'init.d/lm-sensors' +maybe chmod 0755 'init.d/mariadb' +maybe chmod 0755 'init.d/networking' +maybe chmod 0755 'init.d/nginx' +maybe chmod 0755 'init.d/procps' +maybe chmod 0755 'init.d/qemu-guest-agent' +maybe chmod 0755 'init.d/redis-server' +maybe chmod 0755 'init.d/rsync' +maybe chmod 0755 'init.d/rsyslog' +maybe chmod 0755 'init.d/ssh' +maybe chmod 0755 'init.d/sudo' +maybe chmod 0755 'init.d/udev' +maybe chmod 0755 'initramfs-tools' +maybe chmod 0755 'initramfs-tools/conf.d' +maybe chmod 0644 'initramfs-tools/conf.d/resume' +maybe chmod 0755 'initramfs-tools/hooks' +maybe chmod 0644 'initramfs-tools/initramfs.conf' +maybe chmod 0644 'initramfs-tools/modules' +maybe chmod 0755 'initramfs-tools/scripts' +maybe chmod 0755 'initramfs-tools/scripts/init-bottom' +maybe chmod 0755 'initramfs-tools/scripts/init-premount' +maybe chmod 0755 'initramfs-tools/scripts/init-top' +maybe chmod 0755 'initramfs-tools/scripts/local-bottom' +maybe chmod 0755 'initramfs-tools/scripts/local-premount' +maybe chmod 0755 'initramfs-tools/scripts/local-top' +maybe chmod 0755 'initramfs-tools/scripts/nfs-bottom' +maybe chmod 0755 'initramfs-tools/scripts/nfs-premount' +maybe chmod 0755 'initramfs-tools/scripts/nfs-top' +maybe chmod 0755 'initramfs-tools/scripts/panic' +maybe chmod 0644 'initramfs-tools/update-initramfs.conf' +maybe chmod 0644 'inputrc' +maybe chmod 0755 'insserv.conf.d' +maybe chmod 0755 'iproute2' +maybe chmod 0644 'iproute2/bpf_pinning' +maybe chmod 0644 'iproute2/ematch_map' +maybe chmod 0644 'iproute2/group' +maybe chmod 0644 'iproute2/nl_protos' +maybe chmod 0644 'iproute2/rt_dsfield' +maybe chmod 0644 'iproute2/rt_protos' +maybe chmod 0755 'iproute2/rt_protos.d' +maybe chmod 0644 'iproute2/rt_protos.d/README' +maybe chmod 0644 'iproute2/rt_realms' +maybe chmod 0644 'iproute2/rt_scopes' +maybe chmod 0644 'iproute2/rt_tables' +maybe chmod 0755 'iproute2/rt_tables.d' +maybe chmod 0644 'iproute2/rt_tables.d/README' +maybe chmod 0644 'issue' +maybe chmod 0644 'issue.net' +maybe chmod 0755 'kernel' +maybe chmod 0644 'kernel-img.conf' +maybe chmod 0755 'kernel/header_postinst.d' +maybe chmod 0755 'kernel/install.d' +maybe chmod 0755 'kernel/postinst.d' +maybe chmod 0755 'kernel/postinst.d/apt-auto-removal' +maybe chmod 0755 'kernel/postinst.d/initramfs-tools' +maybe chmod 0755 'kernel/postinst.d/zz-update-grub' +maybe chmod 0755 'kernel/postrm.d' +maybe chmod 0755 'kernel/postrm.d/initramfs-tools' +maybe chmod 0755 'kernel/postrm.d/zz-update-grub' +maybe chmod 0755 'kernel/prerm.d' +maybe chmod 0644 'ld.so.conf' +maybe chmod 0755 'ld.so.conf.d' +maybe chmod 0644 'ld.so.conf.d/libc.conf' +maybe chmod 0644 'ld.so.conf.d/x86_64-linux-gnu.conf' +maybe chmod 0755 'ldap' +maybe chmod 0644 'ldap/ldap.conf' +maybe chmod 0755 'ldap/schema' +maybe chmod 0755 'letsencrypt' +maybe chmod 0644 'letsencrypt/.updated-options-ssl-apache-conf-digest.txt' +maybe chmod 0644 'letsencrypt/.updated-options-ssl-nginx-conf-digest.txt' +maybe chmod 0644 'letsencrypt/.updated-ssl-dhparams-pem-digest.txt' +maybe chmod 0755 'letsencrypt/accounts' +maybe chmod 0755 'letsencrypt/accounts/acme-staging-v02.api.letsencrypt.org' +maybe chmod 0755 'letsencrypt/accounts/acme-staging.api.letsencrypt.org' +maybe chmod 0755 'letsencrypt/accounts/acme-staging.api.letsencrypt.org/directory' +maybe chmod 0755 'letsencrypt/accounts/acme-staging.api.letsencrypt.org/directory/c13bb9612c9dca6d60c6bb71ea65fc8c' +maybe chmod 0644 'letsencrypt/accounts/acme-staging.api.letsencrypt.org/directory/c13bb9612c9dca6d60c6bb71ea65fc8c/meta.json' +maybe chmod 0644 'letsencrypt/accounts/acme-staging.api.letsencrypt.org/directory/c13bb9612c9dca6d60c6bb71ea65fc8c/private_key.json' +maybe chmod 0644 'letsencrypt/accounts/acme-staging.api.letsencrypt.org/directory/c13bb9612c9dca6d60c6bb71ea65fc8c/regr.json' +maybe chmod 0755 'letsencrypt/accounts/acme-v01.api.letsencrypt.org' +maybe chmod 0755 'letsencrypt/accounts/acme-v01.api.letsencrypt.org/directory' +maybe chmod 0755 'letsencrypt/accounts/acme-v01.api.letsencrypt.org/directory/b22cdfdfbdc4b2ff1a8cb7095890f7e0' +maybe chmod 0644 'letsencrypt/accounts/acme-v01.api.letsencrypt.org/directory/b22cdfdfbdc4b2ff1a8cb7095890f7e0/meta.json' +maybe chmod 0644 'letsencrypt/accounts/acme-v01.api.letsencrypt.org/directory/b22cdfdfbdc4b2ff1a8cb7095890f7e0/private_key.json' +maybe chmod 0644 'letsencrypt/accounts/acme-v01.api.letsencrypt.org/directory/b22cdfdfbdc4b2ff1a8cb7095890f7e0/regr.json' +maybe chmod 0755 'letsencrypt/accounts/acme-v02.api.letsencrypt.org' +maybe chmod 0755 'letsencrypt/accounts/acme-v02.api.letsencrypt.org/directory' +maybe chmod 0755 'letsencrypt/accounts/acme-v02.api.letsencrypt.org/directory/8b7806ff874ad192eb557b295a53e1f8' +maybe chmod 0644 'letsencrypt/accounts/acme-v02.api.letsencrypt.org/directory/8b7806ff874ad192eb557b295a53e1f8/meta.json' +maybe chmod 0644 'letsencrypt/accounts/acme-v02.api.letsencrypt.org/directory/8b7806ff874ad192eb557b295a53e1f8/private_key.json' +maybe chmod 0644 'letsencrypt/accounts/acme-v02.api.letsencrypt.org/directory/8b7806ff874ad192eb557b295a53e1f8/regr.json' +maybe chmod 0755 'letsencrypt/archive' +maybe chmod 0755 'letsencrypt/archive/indra.solusar.de' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert12.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert13.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert14.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert15.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert16.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert17.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert18.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert19.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert20.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert21.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert22.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert23.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert24.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert25.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert26.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert27.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert28.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert29.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain12.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain13.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain14.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain15.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain16.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain17.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain18.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain19.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain20.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain21.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain22.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain23.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain24.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain25.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain26.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain27.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain28.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain29.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain12.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain13.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain14.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain15.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain16.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain17.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain18.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain19.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain20.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain21.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain22.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain23.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain24.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain25.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain26.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain27.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain28.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain29.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey12.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey13.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey14.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey15.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey16.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey17.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey18.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey19.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey20.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey21.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey22.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey23.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey24.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey25.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey26.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey27.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey28.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey29.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/indra.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/mail.solusar.de' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert12.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert13.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert14.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert15.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert16.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert17.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert18.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert19.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert20.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert21.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert22.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert23.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert24.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert25.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert26.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert27.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert28.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert29.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert38.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain12.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain13.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain14.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain15.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain16.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain17.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain18.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain19.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain20.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain21.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain22.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain23.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain24.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain25.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain26.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain27.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain28.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain29.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain38.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain12.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain13.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain14.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain15.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain16.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain17.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain18.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain19.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain20.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain21.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain22.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain23.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain24.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain25.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain26.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain27.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain28.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain29.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain38.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey12.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey13.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey14.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey15.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey16.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey17.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey18.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey19.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey20.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey21.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey22.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey23.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey24.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey25.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey26.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey27.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey28.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey29.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey38.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/mail.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/nc.solusar.de' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/nc.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/ohc.solusar.de' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/ohc.solusar.de/privkey7.pem' +maybe chmod 0755 'letsencrypt/archive/photos.solusar.de' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/photos.solusar.de/privkey7.pem' +maybe chmod 0755 'letsencrypt/archive/pma.solusar.de' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert12.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert13.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert14.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert15.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert16.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert17.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert18.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert19.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert20.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert21.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert22.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert23.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert24.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert25.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert26.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert27.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert28.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert29.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain12.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain13.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain14.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain15.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain16.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain17.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain18.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain19.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain20.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain21.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain22.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain23.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain24.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain25.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain26.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain27.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain28.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain29.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain12.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain13.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain14.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain15.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain16.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain17.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain18.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain19.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain20.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain21.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain22.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain23.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain24.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain25.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain26.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain27.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain28.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain29.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey12.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey13.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey14.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey15.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey16.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey17.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey18.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey19.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey20.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey21.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey22.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey23.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey24.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey25.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey26.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey27.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey28.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey29.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/pma.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/postfix.solusar.de' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert12.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert13.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert14.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert15.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert16.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert17.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert18.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert19.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert20.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert21.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert22.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert23.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert24.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert25.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert26.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert27.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert28.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert29.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain12.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain13.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain14.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain15.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain16.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain17.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain18.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain19.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain20.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain21.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain22.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain23.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain24.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain25.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain26.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain27.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain28.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain29.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain12.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain13.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain14.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain15.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain16.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain17.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain18.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain19.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain20.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain21.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain22.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain23.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain24.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain25.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain26.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain27.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain28.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain29.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey12.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey13.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey14.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey15.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey16.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey17.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey18.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey19.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey20.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey21.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey22.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey23.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey24.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey25.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey26.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey27.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey28.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey29.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/postfix.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/ps.solusar.de' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/ps.solusar.de/privkey6.pem' +maybe chmod 0755 'letsencrypt/archive/rspamd.solusar.de' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/rspamd.solusar.de/privkey2.pem' +maybe chmod 0755 'letsencrypt/archive/searx.solusar.de' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert12.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert13.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert14.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert15.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert16.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert17.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert18.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert19.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert20.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert21.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert22.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert23.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert24.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert25.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert26.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert27.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert28.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert29.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert38.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain12.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain13.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain14.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain15.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain16.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain17.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain18.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain19.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain20.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain21.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain22.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain23.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain24.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain25.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain26.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain27.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain28.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain29.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain38.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain12.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain13.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain14.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain15.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain16.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain17.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain18.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain19.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain20.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain21.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain22.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain23.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain24.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain25.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain26.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain27.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain28.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain29.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain38.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey12.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey13.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey14.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey15.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey16.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey17.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey18.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey19.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey20.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey21.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey22.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey23.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey24.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey25.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey26.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey27.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey28.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey29.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey38.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/searx.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/webmail.solusar.de' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert12.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert13.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert14.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert15.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert16.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert17.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert18.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert19.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert20.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert21.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert22.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert23.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert24.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert25.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert26.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert27.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert28.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert29.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain12.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain13.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain14.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain15.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain16.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain17.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain18.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain19.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain20.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain21.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain22.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain23.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain24.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain25.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain26.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain27.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain28.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain29.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain12.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain13.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain14.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain15.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain16.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain17.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain18.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain19.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain20.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain21.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain22.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain23.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain24.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain25.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain26.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain27.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain28.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain29.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey12.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey13.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey14.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey15.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey16.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey17.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey18.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey19.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey20.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey21.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey22.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey23.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey24.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey25.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey26.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey27.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey28.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey29.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/webmail.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/wiki.solusar.de' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert1.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert10.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert11.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert12.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert13.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert14.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert15.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert16.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert17.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert18.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert19.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert2.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert20.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert21.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert22.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert23.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert24.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert25.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert26.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert27.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert28.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert29.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain1.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain10.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain11.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain12.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain13.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain14.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain15.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain16.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain17.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain18.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain19.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain2.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain20.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain21.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain22.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain23.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain24.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain25.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain26.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain27.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain28.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain29.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain1.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain10.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain11.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain12.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain13.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain14.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain15.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain16.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain17.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain18.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain19.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain2.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain20.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain21.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain22.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain23.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain24.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain25.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain26.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain27.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain28.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain29.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey1.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey10.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey11.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey12.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey13.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey14.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey15.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey16.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey17.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey18.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey19.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey2.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey20.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey21.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey22.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey23.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey24.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey25.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey26.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey27.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey28.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey29.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/wiki.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/archive/www.solusar.de' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert3.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert30.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert31.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert32.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert33.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert34.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert35.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert36.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert37.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert4.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert5.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert6.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert7.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert8.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/cert9.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain3.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain30.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain31.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain32.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain33.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain34.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain35.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain36.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain37.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain4.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain5.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain6.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain7.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain8.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/chain9.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain3.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain30.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain31.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain32.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain33.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain34.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain35.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain36.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain37.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain4.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain5.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain6.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain7.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain8.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/fullchain9.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey3.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey30.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey31.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey32.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey33.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey34.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey35.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey36.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey37.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey4.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey5.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey6.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey7.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey8.pem' +maybe chmod 0644 'letsencrypt/archive/www.solusar.de/privkey9.pem' +maybe chmod 0755 'letsencrypt/csr' +maybe chmod 0644 'letsencrypt/csr/0000_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0001_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0002_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0003_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0004_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0005_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0006_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0007_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0008_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0009_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0010_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0011_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0012_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0013_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0014_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0015_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0016_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0017_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0018_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0019_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0020_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0021_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0022_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0023_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0024_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0025_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0026_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0027_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0028_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0029_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0030_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0031_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0032_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0033_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0034_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0035_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0036_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0037_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0038_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0039_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0040_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0041_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0042_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0043_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0044_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0045_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0046_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0047_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0048_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0049_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0050_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0051_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0052_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0053_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0054_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0055_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0056_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0057_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0058_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0059_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0060_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0061_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0062_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0063_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0064_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0065_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0066_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0067_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0068_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0069_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0070_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0071_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0072_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0073_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0074_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0075_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0076_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0077_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0078_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0079_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0080_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0081_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0082_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0083_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0084_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0085_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0086_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0087_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0088_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0089_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0090_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0091_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0092_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0093_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0094_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0095_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0096_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0097_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0098_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0099_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0100_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0101_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0102_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0103_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0104_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0105_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0106_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0107_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0108_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0109_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0110_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0111_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0112_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0113_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0114_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0115_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0116_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0117_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0118_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0119_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0120_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0121_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0122_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0123_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0124_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0125_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0126_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0127_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0128_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0129_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0130_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0131_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0132_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0133_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0134_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0135_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0136_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0137_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0138_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0139_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0140_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0141_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0142_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0143_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0144_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0145_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0146_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0147_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0148_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0149_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0150_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0151_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0152_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0153_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0154_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0155_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0156_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0157_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0158_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0159_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0160_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0161_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0162_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0163_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0164_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0165_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0166_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0167_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0168_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0169_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0170_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0171_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0172_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0173_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0174_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0175_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0176_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0177_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0178_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0179_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0180_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0181_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0182_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0183_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0184_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0185_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0186_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0187_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0188_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0189_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0190_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0191_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0192_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0193_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0194_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0195_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0196_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0197_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0198_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0199_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0200_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0201_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0202_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0203_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0204_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0205_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0206_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0207_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0208_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0209_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0210_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0211_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0212_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0213_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0214_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0215_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0216_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0217_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0218_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0219_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0220_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0221_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0222_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0223_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0224_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0225_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0226_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0227_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0228_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0229_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0230_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0231_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0232_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0233_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0234_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0235_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0236_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0237_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0238_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0239_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0240_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0241_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0242_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0243_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0244_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0245_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0246_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0247_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0248_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0249_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0250_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0251_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0252_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0253_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0254_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0255_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0256_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0257_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0258_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0259_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0260_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0261_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0262_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0263_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0264_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0265_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0266_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0267_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0268_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0269_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0270_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0271_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0272_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0273_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0274_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0275_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0276_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0277_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0278_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0279_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0280_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0281_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0282_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0283_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0284_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0285_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0286_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0287_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0288_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0289_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0290_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0291_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0292_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0293_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0294_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0295_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0296_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0297_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0298_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0299_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0300_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0301_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0302_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0303_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0304_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0305_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0306_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0307_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0308_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0309_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0310_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0311_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0312_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0313_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0314_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0315_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0316_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0317_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0318_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0319_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0320_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0321_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0322_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0323_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0324_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0325_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0326_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0327_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0328_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0329_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0330_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0331_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0332_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0333_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0334_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0335_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0336_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0337_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0338_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0339_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0340_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0341_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0342_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0343_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0344_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0345_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0346_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0347_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0348_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0349_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0350_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0351_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0352_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0353_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0354_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0355_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0356_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0357_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0358_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0359_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0360_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0361_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0362_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0363_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0364_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0365_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0366_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0367_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0368_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0369_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0370_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0371_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0372_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0373_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0374_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0375_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0376_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0377_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0378_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0379_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0380_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0381_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0382_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0383_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0384_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0385_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0386_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0387_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0388_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0389_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0390_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0391_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0392_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0393_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0394_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0395_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0396_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0397_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0398_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0399_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0400_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0401_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0402_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0403_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0404_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0405_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0406_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0407_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0408_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0409_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0410_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0411_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0412_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0413_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0414_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0415_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0416_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0417_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0418_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0419_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0420_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0421_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0422_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0423_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0424_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0425_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0426_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0427_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0428_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0429_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0430_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0431_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0432_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0433_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0434_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0435_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0436_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0437_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0438_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0439_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0440_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0441_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0442_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0443_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0444_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0445_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0446_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0447_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0448_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0449_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0450_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0451_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0452_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0453_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0454_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0455_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0456_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0457_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0458_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0459_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0460_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0461_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0462_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0463_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0464_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0465_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0466_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0467_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0468_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0469_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0470_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0471_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0472_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0473_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0474_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0475_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0476_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0477_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0478_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0479_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0480_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0481_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0482_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0483_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0484_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0485_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0486_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0487_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0488_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0489_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0490_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0491_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0492_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0493_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0494_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0495_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0496_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0497_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0498_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0499_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0500_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0501_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0502_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0503_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0504_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0505_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0506_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0507_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0508_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0509_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0510_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0511_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0512_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0513_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0514_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0515_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0516_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0517_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0518_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0519_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0520_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0521_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0522_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0523_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0524_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0525_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0526_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0527_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0528_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0529_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0530_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0531_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0532_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0533_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0534_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0535_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0536_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0537_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0538_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0539_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0540_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0541_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0542_csr-certbot.pem' +maybe chmod 0644 'letsencrypt/csr/0543_csr-certbot.pem' +maybe chmod 0755 'letsencrypt/keys' +maybe chmod 0644 'letsencrypt/keys/0000_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0001_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0002_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0003_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0004_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0005_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0006_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0007_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0008_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0009_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0010_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0011_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0012_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0013_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0014_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0015_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0016_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0017_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0018_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0019_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0020_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0021_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0022_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0023_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0024_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0025_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0026_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0027_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0028_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0029_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0030_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0031_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0032_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0033_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0034_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0035_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0036_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0037_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0038_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0039_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0040_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0041_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0042_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0043_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0044_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0045_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0046_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0047_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0048_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0049_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0050_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0051_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0052_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0053_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0054_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0055_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0056_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0057_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0058_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0059_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0060_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0061_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0062_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0063_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0064_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0065_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0066_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0067_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0068_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0069_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0070_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0071_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0072_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0073_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0074_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0075_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0076_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0077_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0078_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0079_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0080_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0081_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0082_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0083_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0084_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0085_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0086_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0087_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0088_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0089_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0090_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0091_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0092_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0093_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0094_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0095_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0096_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0097_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0098_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0099_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0100_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0101_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0102_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0103_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0104_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0105_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0106_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0107_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0108_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0109_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0110_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0111_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0112_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0113_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0114_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0115_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0116_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0117_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0118_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0119_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0120_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0121_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0122_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0123_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0124_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0125_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0126_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0127_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0128_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0129_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0130_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0131_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0132_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0133_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0134_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0135_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0136_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0137_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0138_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0139_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0140_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0141_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0142_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0143_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0144_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0145_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0146_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0147_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0148_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0149_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0150_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0151_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0152_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0153_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0154_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0155_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0156_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0157_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0158_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0159_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0160_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0161_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0162_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0163_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0164_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0165_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0166_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0167_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0168_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0169_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0170_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0171_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0172_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0173_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0174_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0175_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0176_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0177_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0178_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0179_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0180_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0181_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0182_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0183_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0184_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0185_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0186_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0187_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0188_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0189_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0190_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0191_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0192_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0193_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0194_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0195_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0196_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0197_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0198_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0199_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0200_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0201_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0202_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0203_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0204_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0205_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0206_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0207_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0208_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0209_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0210_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0211_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0212_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0213_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0214_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0215_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0216_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0217_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0218_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0219_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0220_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0221_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0222_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0223_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0224_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0225_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0226_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0227_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0228_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0229_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0230_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0231_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0232_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0233_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0234_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0235_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0236_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0237_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0238_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0239_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0240_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0241_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0242_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0243_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0244_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0245_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0246_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0247_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0248_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0249_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0250_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0251_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0252_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0253_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0254_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0255_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0256_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0257_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0258_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0259_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0260_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0261_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0262_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0263_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0264_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0265_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0266_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0267_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0268_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0269_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0270_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0271_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0272_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0273_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0274_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0275_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0276_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0277_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0278_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0279_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0280_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0281_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0282_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0283_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0284_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0285_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0286_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0287_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0288_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0289_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0290_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0291_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0292_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0293_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0294_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0295_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0296_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0297_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0298_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0299_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0300_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0301_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0302_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0303_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0304_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0305_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0306_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0307_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0308_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0309_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0310_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0311_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0312_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0313_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0314_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0315_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0316_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0317_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0318_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0319_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0320_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0321_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0322_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0323_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0324_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0325_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0326_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0327_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0328_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0329_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0330_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0331_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0332_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0333_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0334_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0335_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0336_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0337_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0338_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0339_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0340_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0341_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0342_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0343_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0344_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0345_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0346_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0347_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0348_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0349_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0350_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0351_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0352_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0353_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0354_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0355_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0356_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0357_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0358_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0359_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0360_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0361_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0362_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0363_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0364_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0365_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0366_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0367_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0368_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0369_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0370_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0371_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0372_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0373_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0374_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0375_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0376_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0377_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0378_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0379_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0380_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0381_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0382_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0383_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0384_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0385_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0386_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0387_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0388_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0389_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0390_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0391_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0392_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0393_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0394_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0395_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0396_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0397_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0398_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0399_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0400_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0401_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0402_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0403_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0404_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0405_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0406_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0407_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0408_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0409_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0410_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0411_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0412_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0413_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0414_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0415_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0416_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0417_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0418_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0419_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0420_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0421_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0422_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0423_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0424_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0425_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0426_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0427_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0428_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0429_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0430_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0431_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0432_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0433_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0434_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0435_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0436_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0437_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0438_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0439_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0440_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0441_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0442_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0443_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0444_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0445_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0446_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0447_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0448_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0449_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0450_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0451_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0452_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0453_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0454_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0455_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0456_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0457_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0458_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0459_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0460_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0461_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0462_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0463_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0464_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0465_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0466_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0467_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0468_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0469_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0470_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0471_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0472_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0473_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0474_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0475_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0476_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0477_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0478_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0479_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0480_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0481_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0482_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0483_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0484_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0485_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0486_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0487_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0488_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0489_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0490_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0491_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0492_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0493_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0494_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0495_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0496_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0497_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0498_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0499_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0500_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0501_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0502_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0503_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0504_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0505_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0506_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0507_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0508_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0509_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0510_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0511_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0512_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0513_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0514_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0515_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0516_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0517_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0518_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0519_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0520_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0521_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0522_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0523_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0524_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0525_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0526_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0527_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0528_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0529_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0530_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0531_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0532_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0533_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0534_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0535_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0536_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0537_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0538_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0539_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0540_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0541_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0542_key-certbot.pem' +maybe chmod 0644 'letsencrypt/keys/0543_key-certbot.pem' +maybe chmod 0755 'letsencrypt/live' +maybe chmod 0644 'letsencrypt/live/README' +maybe chmod 0755 'letsencrypt/live/indra.solusar.de' +maybe chmod 0755 'letsencrypt/live/mail.solusar.de' +maybe chmod 0755 'letsencrypt/live/nc.solusar.de' +maybe chmod 0644 'letsencrypt/live/nc.solusar.de/README' +maybe chmod 0755 'letsencrypt/live/ohc.solusar.de' +maybe chmod 0644 'letsencrypt/live/ohc.solusar.de/README' +maybe chmod 0755 'letsencrypt/live/photos.solusar.de' +maybe chmod 0644 'letsencrypt/live/photos.solusar.de/README' +maybe chmod 0755 'letsencrypt/live/pma.solusar.de' +maybe chmod 0755 'letsencrypt/live/postfix.solusar.de' +maybe chmod 0755 'letsencrypt/live/ps.solusar.de' +maybe chmod 0644 'letsencrypt/live/ps.solusar.de/README' +maybe chmod 0755 'letsencrypt/live/rspamd.solusar.de' +maybe chmod 0644 'letsencrypt/live/rspamd.solusar.de/README' +maybe chmod 0755 'letsencrypt/live/searx.solusar.de' +maybe chmod 0755 'letsencrypt/live/webmail.solusar.de' +maybe chmod 0755 'letsencrypt/live/wiki.solusar.de' +maybe chmod 0755 'letsencrypt/live/www.solusar.de' +maybe chmod 0644 'letsencrypt/options-ssl-apache.conf' +maybe chmod 0644 'letsencrypt/options-ssl-nginx.conf' +maybe chmod 0755 'letsencrypt/renewal' +maybe chmod 0755 'letsencrypt/renewal-hooks' +maybe chmod 0755 'letsencrypt/renewal-hooks/post' +maybe chmod 0755 'letsencrypt/renewal-hooks/post/nginx.sh' +maybe chmod 0755 'letsencrypt/renewal-hooks/pre' +maybe chmod 0755 'letsencrypt/renewal-hooks/pre/nginx.sh' +maybe chmod 0644 'letsencrypt/renewal/indra.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/mail.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/nc.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/ohc.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/photos.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/pma.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/postfix.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/ps.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/rspamd.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/searx.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/webmail.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/wiki.solusar.de.conf' +maybe chmod 0644 'letsencrypt/renewal/www.solusar.de.conf' +maybe chmod 0644 'letsencrypt/ssl-dhparams.pem' +maybe chmod 0644 'libaudit.conf' +maybe chmod 0755 'libnl-3' +maybe chmod 0644 'libnl-3/classid' +maybe chmod 0644 'libnl-3/pktloc' +maybe chmod 0755 'libpaper.d' +maybe chmod 0755 'lighttpd' +maybe chmod 0755 'lighttpd/conf-available' +maybe chmod 0644 'lighttpd/conf-available/90-javascript-alias.conf' +maybe chmod 0755 'lighttpd/conf-enabled' +maybe chmod 0644 'locale.alias' +maybe chmod 0644 'locale.gen' +maybe chmod 0644 'locale.gen.orig' +maybe chmod 0755 'logcheck' +maybe chmod 0755 'logcheck/cracking.d' +maybe chmod 0644 'logcheck/cracking.d/kernel' +maybe chmod 0644 'logcheck/cracking.d/rlogind' +maybe chmod 0644 'logcheck/cracking.d/rsh' +maybe chmod 0644 'logcheck/cracking.d/smartd' +maybe chmod 0644 'logcheck/cracking.d/tftpd' +maybe chmod 0644 'logcheck/cracking.d/uucico' +maybe chmod 0755 'logcheck/ignore.d.paranoid' +maybe chmod 0644 'logcheck/ignore.d.paranoid/bind' +maybe chmod 0644 'logcheck/ignore.d.paranoid/clamav-daemon' +maybe chmod 0644 'logcheck/ignore.d.paranoid/cracklib-runtime' +maybe chmod 0644 'logcheck/ignore.d.paranoid/cron' +maybe chmod 0644 'logcheck/ignore.d.paranoid/incron' +maybe chmod 0644 'logcheck/ignore.d.paranoid/logcheck' +maybe chmod 0644 'logcheck/ignore.d.paranoid/mariadb-server-10_7' +maybe chmod 0644 'logcheck/ignore.d.paranoid/mariadb-server-10_8' +maybe chmod 0644 'logcheck/ignore.d.paranoid/postfix' +maybe chmod 0644 'logcheck/ignore.d.paranoid/ppp' +maybe chmod 0644 'logcheck/ignore.d.paranoid/pureftp' +maybe chmod 0644 'logcheck/ignore.d.paranoid/qpopper' +maybe chmod 0644 'logcheck/ignore.d.paranoid/squid' +maybe chmod 0644 'logcheck/ignore.d.paranoid/ssh' +maybe chmod 0644 'logcheck/ignore.d.paranoid/stunnel' +maybe chmod 0644 'logcheck/ignore.d.paranoid/sysklogd' +maybe chmod 0644 'logcheck/ignore.d.paranoid/telnetd' +maybe chmod 0644 'logcheck/ignore.d.paranoid/tripwire' +maybe chmod 0644 'logcheck/ignore.d.paranoid/usb' +maybe chmod 0755 'logcheck/ignore.d.server' +maybe chmod 0644 'logcheck/ignore.d.server/acpid' +maybe chmod 0644 'logcheck/ignore.d.server/amandad' +maybe chmod 0644 'logcheck/ignore.d.server/amavisd-new' +maybe chmod 0644 'logcheck/ignore.d.server/anacron' +maybe chmod 0644 'logcheck/ignore.d.server/anon-proxy' +maybe chmod 0644 'logcheck/ignore.d.server/apache' +maybe chmod 0644 'logcheck/ignore.d.server/apcupsd' +maybe chmod 0644 'logcheck/ignore.d.server/arpwatch' +maybe chmod 0644 'logcheck/ignore.d.server/asterisk' +maybe chmod 0644 'logcheck/ignore.d.server/automount' +maybe chmod 0644 'logcheck/ignore.d.server/bind' +maybe chmod 0644 'logcheck/ignore.d.server/bluez-utils' +maybe chmod 0644 'logcheck/ignore.d.server/clamav-daemon' +maybe chmod 0644 'logcheck/ignore.d.server/clamav-freshclam' +maybe chmod 0644 'logcheck/ignore.d.server/courier' +maybe chmod 0644 'logcheck/ignore.d.server/cpqarrayd' +maybe chmod 0644 'logcheck/ignore.d.server/cpufreqd' +maybe chmod 0644 'logcheck/ignore.d.server/cron' +maybe chmod 0644 'logcheck/ignore.d.server/cron-apt' +maybe chmod 0644 'logcheck/ignore.d.server/cups-lpd' +maybe chmod 0644 'logcheck/ignore.d.server/cvs-pserver' +maybe chmod 0644 'logcheck/ignore.d.server/cvsd' +maybe chmod 0644 'logcheck/ignore.d.server/cyrus' +maybe chmod 0644 'logcheck/ignore.d.server/dcc' +maybe chmod 0644 'logcheck/ignore.d.server/ddclient' +maybe chmod 0644 'logcheck/ignore.d.server/dhclient' +maybe chmod 0644 'logcheck/ignore.d.server/dhcp' +maybe chmod 0644 'logcheck/ignore.d.server/dictd' +maybe chmod 0644 'logcheck/ignore.d.server/dkfilter' +maybe chmod 0644 'logcheck/ignore.d.server/dnsmasq' +maybe chmod 0644 'logcheck/ignore.d.server/dovecot' +maybe chmod 0644 'logcheck/ignore.d.server/dropbear' +maybe chmod 0644 'logcheck/ignore.d.server/dspam' +maybe chmod 0644 'logcheck/ignore.d.server/epmd' +maybe chmod 0644 'logcheck/ignore.d.server/exim4' +maybe chmod 0644 'logcheck/ignore.d.server/fcron' +maybe chmod 0644 'logcheck/ignore.d.server/ftpd' +maybe chmod 0644 'logcheck/ignore.d.server/git-daemon' +maybe chmod 0644 'logcheck/ignore.d.server/gnu-imap4d' +maybe chmod 0644 'logcheck/ignore.d.server/gpg-agent' +maybe chmod 0644 'logcheck/ignore.d.server/gps' +maybe chmod 0644 'logcheck/ignore.d.server/grinch' +maybe chmod 0644 'logcheck/ignore.d.server/hddtemp' +maybe chmod 0644 'logcheck/ignore.d.server/horde3' +maybe chmod 0644 'logcheck/ignore.d.server/hplip' +maybe chmod 0644 'logcheck/ignore.d.server/hylafax' +maybe chmod 0644 'logcheck/ignore.d.server/ikiwiki' +maybe chmod 0644 'logcheck/ignore.d.server/imap' +maybe chmod 0644 'logcheck/ignore.d.server/imapproxy' +maybe chmod 0644 'logcheck/ignore.d.server/imp' +maybe chmod 0644 'logcheck/ignore.d.server/imp4' +maybe chmod 0644 'logcheck/ignore.d.server/innd' +maybe chmod 0644 'logcheck/ignore.d.server/ipppd' +maybe chmod 0644 'logcheck/ignore.d.server/isdnlog' +maybe chmod 0644 'logcheck/ignore.d.server/isdnutils' +maybe chmod 0644 'logcheck/ignore.d.server/jabberd' +maybe chmod 0644 'logcheck/ignore.d.server/kernel' +maybe chmod 0644 'logcheck/ignore.d.server/klogind' +maybe chmod 0644 'logcheck/ignore.d.server/krb5-kdc' +maybe chmod 0644 'logcheck/ignore.d.server/libpam-krb5' +maybe chmod 0644 'logcheck/ignore.d.server/libpam-mount' +maybe chmod 0644 'logcheck/ignore.d.server/libsasl2-modules' +maybe chmod 0644 'logcheck/ignore.d.server/logcheck' +maybe chmod 0644 'logcheck/ignore.d.server/login' +maybe chmod 0644 'logcheck/ignore.d.server/maradns' +maybe chmod 0644 'logcheck/ignore.d.server/mariadb-server-10_7' +maybe chmod 0644 'logcheck/ignore.d.server/mariadb-server-10_8' +maybe chmod 0644 'logcheck/ignore.d.server/mldonkey-server' +maybe chmod 0644 'logcheck/ignore.d.server/mon' +maybe chmod 0644 'logcheck/ignore.d.server/mountd' +maybe chmod 0644 'logcheck/ignore.d.server/nagios' +maybe chmod 0644 'logcheck/ignore.d.server/netconsole' +maybe chmod 0644 'logcheck/ignore.d.server/nfs' +maybe chmod 0644 'logcheck/ignore.d.server/nntpcache' +maybe chmod 0644 'logcheck/ignore.d.server/nscd' +maybe chmod 0644 'logcheck/ignore.d.server/nslcd' +maybe chmod 0644 'logcheck/ignore.d.server/ntpdate' +maybe chmod 0644 'logcheck/ignore.d.server/openvpn' +maybe chmod 0644 'logcheck/ignore.d.server/otrs' +maybe chmod 0644 'logcheck/ignore.d.server/passwd' +maybe chmod 0644 'logcheck/ignore.d.server/pdns' +maybe chmod 0644 'logcheck/ignore.d.server/perdition' +maybe chmod 0644 'logcheck/ignore.d.server/policyd' +maybe chmod 0644 'logcheck/ignore.d.server/popa3d' +maybe chmod 0644 'logcheck/ignore.d.server/postfix' +maybe chmod 0644 'logcheck/ignore.d.server/postfix-policyd' +maybe chmod 0644 'logcheck/ignore.d.server/postgrey' +maybe chmod 0644 'logcheck/ignore.d.server/ppp' +maybe chmod 0644 'logcheck/ignore.d.server/pptpd' +maybe chmod 0644 'logcheck/ignore.d.server/procmail' +maybe chmod 0644 'logcheck/ignore.d.server/proftpd' +maybe chmod 0644 'logcheck/ignore.d.server/pure-ftpd' +maybe chmod 0644 'logcheck/ignore.d.server/pureftp' +maybe chmod 0644 'logcheck/ignore.d.server/qpopper' +maybe chmod 0644 'logcheck/ignore.d.server/razor' +maybe chmod 0644 'logcheck/ignore.d.server/rbldnsd' +maybe chmod 0644 'logcheck/ignore.d.server/rkhunter' +maybe chmod 0644 'logcheck/ignore.d.server/rpc_statd' +maybe chmod 0644 'logcheck/ignore.d.server/rsnapshot' +maybe chmod 0644 'logcheck/ignore.d.server/rsync' +maybe chmod 0644 'logcheck/ignore.d.server/rsyslog' +maybe chmod 0644 'logcheck/ignore.d.server/sa-exim' +maybe chmod 0644 'logcheck/ignore.d.server/samba' +maybe chmod 0644 'logcheck/ignore.d.server/saned' +maybe chmod 0644 'logcheck/ignore.d.server/sasl2-bin' +maybe chmod 0644 'logcheck/ignore.d.server/saslauthd' +maybe chmod 0644 'logcheck/ignore.d.server/schroot' +maybe chmod 0644 'logcheck/ignore.d.server/scponly' +maybe chmod 0644 'logcheck/ignore.d.server/slapd' +maybe chmod 0644 'logcheck/ignore.d.server/smartd' +maybe chmod 0644 'logcheck/ignore.d.server/smbd_audit' +maybe chmod 0644 'logcheck/ignore.d.server/smokeping' +maybe chmod 0644 'logcheck/ignore.d.server/snmpd' +maybe chmod 0644 'logcheck/ignore.d.server/snort' +maybe chmod 0644 'logcheck/ignore.d.server/spamc' +maybe chmod 0644 'logcheck/ignore.d.server/spamd' +maybe chmod 0644 'logcheck/ignore.d.server/squid' +maybe chmod 0644 'logcheck/ignore.d.server/ssh' +maybe chmod 0644 'logcheck/ignore.d.server/stunnel' +maybe chmod 0644 'logcheck/ignore.d.server/su' +maybe chmod 0644 'logcheck/ignore.d.server/sudo' +maybe chmod 0644 'logcheck/ignore.d.server/sympa' +maybe chmod 0644 'logcheck/ignore.d.server/syslogd' +maybe chmod 0644 'logcheck/ignore.d.server/systemd' +maybe chmod 0644 'logcheck/ignore.d.server/systemd-timesyncd' +maybe chmod 0644 'logcheck/ignore.d.server/teapop' +maybe chmod 0644 'logcheck/ignore.d.server/telnetd' +maybe chmod 0644 'logcheck/ignore.d.server/tftpd' +maybe chmod 0644 'logcheck/ignore.d.server/thy' +maybe chmod 0644 'logcheck/ignore.d.server/ucd-snmp' +maybe chmod 0644 'logcheck/ignore.d.server/upsd' +maybe chmod 0644 'logcheck/ignore.d.server/uptimed' +maybe chmod 0644 'logcheck/ignore.d.server/userv' +maybe chmod 0644 'logcheck/ignore.d.server/vsftpd' +maybe chmod 0644 'logcheck/ignore.d.server/watchdog' +maybe chmod 0644 'logcheck/ignore.d.server/wu-ftpd' +maybe chmod 0644 'logcheck/ignore.d.server/xinetd' +maybe chmod 0755 'logcheck/ignore.d.workstation' +maybe chmod 0644 'logcheck/ignore.d.workstation/automount' +maybe chmod 0644 'logcheck/ignore.d.workstation/bind' +maybe chmod 0644 'logcheck/ignore.d.workstation/bluetooth-alsa' +maybe chmod 0644 'logcheck/ignore.d.workstation/bluez-utils' +maybe chmod 0644 'logcheck/ignore.d.workstation/bonobo' +maybe chmod 0644 'logcheck/ignore.d.workstation/dhcpcd' +maybe chmod 0644 'logcheck/ignore.d.workstation/francine' +maybe chmod 0644 'logcheck/ignore.d.workstation/gconf' +maybe chmod 0644 'logcheck/ignore.d.workstation/gdm' +maybe chmod 0644 'logcheck/ignore.d.workstation/hald' +maybe chmod 0644 'logcheck/ignore.d.workstation/hcid' +maybe chmod 0644 'logcheck/ignore.d.workstation/ifplugd' +maybe chmod 0644 'logcheck/ignore.d.workstation/ippl' +maybe chmod 0644 'logcheck/ignore.d.workstation/kdm' +maybe chmod 0644 'logcheck/ignore.d.workstation/kernel' +maybe chmod 0644 'logcheck/ignore.d.workstation/laptop-mode-tools' +maybe chmod 0644 'logcheck/ignore.d.workstation/libmtp-runtime' +maybe chmod 0644 'logcheck/ignore.d.workstation/libpam-gnome-keyring' +maybe chmod 0644 'logcheck/ignore.d.workstation/logcheck' +maybe chmod 0644 'logcheck/ignore.d.workstation/login' +maybe chmod 0644 'logcheck/ignore.d.workstation/mariadb-server-10_7' +maybe chmod 0644 'logcheck/ignore.d.workstation/mariadb-server-10_8' +maybe chmod 0644 'logcheck/ignore.d.workstation/net-acct' +maybe chmod 0644 'logcheck/ignore.d.workstation/nntpcache' +maybe chmod 0644 'logcheck/ignore.d.workstation/polypaudio' +maybe chmod 0644 'logcheck/ignore.d.workstation/postfix' +maybe chmod 0644 'logcheck/ignore.d.workstation/ppp' +maybe chmod 0644 'logcheck/ignore.d.workstation/proftpd' +maybe chmod 0644 'logcheck/ignore.d.workstation/pump' +maybe chmod 0644 'logcheck/ignore.d.workstation/sendfile' +maybe chmod 0644 'logcheck/ignore.d.workstation/slim' +maybe chmod 0644 'logcheck/ignore.d.workstation/squid' +maybe chmod 0644 'logcheck/ignore.d.workstation/udev' +maybe chmod 0644 'logcheck/ignore.d.workstation/wdm' +maybe chmod 0644 'logcheck/ignore.d.workstation/winbind' +maybe chmod 0644 'logcheck/ignore.d.workstation/wpasupplicant' +maybe chmod 0644 'logcheck/ignore.d.workstation/xdm' +maybe chmod 0644 'logcheck/ignore.d.workstation/xlockmore' +maybe chmod 0755 'logcheck/violations.d' +maybe chmod 0644 'logcheck/violations.d/kernel' +maybe chmod 0644 'logcheck/violations.d/logcheck' +maybe chmod 0644 'logcheck/violations.d/smartd' +maybe chmod 0644 'logcheck/violations.d/su' +maybe chmod 0644 'logcheck/violations.d/sudo' +maybe chmod 0755 'logcheck/violations.ignore.d' +maybe chmod 0644 'logcheck/violations.ignore.d/logcheck-su' +maybe chmod 0644 'logcheck/violations.ignore.d/logcheck-sudo' +maybe chmod 0644 'logcheck/violations.ignore.d/postgrey' +maybe chmod 0644 'login.defs' +maybe chmod 0644 'logrotate.conf' +maybe chmod 0755 'logrotate.d' +maybe chmod 0644 'logrotate.d/alternatives' +maybe chmod 0644 'logrotate.d/apt' +maybe chmod 0644 'logrotate.d/btmp' +maybe chmod 0644 'logrotate.d/dpkg' +maybe chmod 0644 'logrotate.d/fail2ban' +maybe chmod 0644 'logrotate.d/mysql-server' +maybe chmod 0644 'logrotate.d/nginx' +maybe chmod 0644 'logrotate.d/redis-server' +maybe chmod 0644 'logrotate.d/rsyslog' +maybe chmod 0644 'logrotate.d/wtmp' +maybe chmod 0755 'logwatch' +maybe chmod 0755 'logwatch/conf' +maybe chmod 0755 'logwatch/conf/logfiles' +maybe chmod 0755 'logwatch/conf/services' +maybe chmod 0755 'logwatch/scripts' +maybe chmod 0755 'logwatch/scripts/services' +maybe chmod 0444 'machine-id' +maybe chmod 0644 'magic' +maybe chmod 0644 'magic.mime' +maybe chmod 0755 'mail' +maybe chmod 0755 'mail/m4' +maybe chmod 0644 'mailcap' +maybe chmod 0644 'mailcap.order' +maybe chmod 0644 'mailname' +maybe chmod 0644 'manpath.config' +maybe chmod 0644 'mime.types' +maybe chmod 0644 'mke2fs.conf' +maybe chmod 0755 'modprobe.d' +maybe chmod 0644 'modules' +maybe chmod 0755 'modules-load.d' +maybe chmod 0755 'monit' +maybe chmod 0755 'monit/conf-available' +maybe chmod 0755 'monit/monitrc.d' +maybe chmod 0644 'monit/monitrc.d/fail2ban' +maybe chmod 0644 'motd' +maybe chmod 0755 'mysql' +maybe chmod 0755 'mysql/conf.d' +maybe chmod 0755 'mysql/debian-start' +maybe chmod 0600 'mysql/debian.cnf' +maybe chmod 0644 'mysql/mariadb.cnf' +maybe chmod 0755 'mysql/mariadb.conf.d' +maybe chmod 0644 'mysql/mariadb.conf.d/50-client.cnf' +maybe chmod 0644 'mysql/mariadb.conf.d/50-mysql-clients.cnf' +maybe chmod 0644 'mysql/mariadb.conf.d/50-mysqld_safe.cnf' +maybe chmod 0644 'mysql/mariadb.conf.d/50-server.cnf' +maybe chmod 0644 'mysql/mariadb.conf.d/60-galera.cnf' +maybe chmod 0755 'mysql/mariadb.conf.d/99-enable-encryption.cnf.preset' +maybe chmod 0644 'mysql/mariadb.conf.d/99-enable-encryption.cnf.preset/enable_encryption.preset' +maybe chmod 0644 'nanorc' +maybe chmod 0755 'neofetch' +maybe chmod 0644 'neofetch/neofetch.config' +maybe chmod 0644 'netconfig' +maybe chmod 0755 'network' +maybe chmod 0755 'network/if-down.d' +maybe chmod 0755 'network/if-post-down.d' +maybe chmod 0755 'network/if-pre-up.d' +maybe chmod 0755 'network/if-up.d' +maybe chmod 0644 'network/interfaces' +maybe chmod 0755 'network/interfaces.d' +maybe chmod 0644 'network/interfaces.d/50-cloud-init.cfg' +maybe chmod 0644 'networks' +maybe chmod 0755 'nginx' +maybe chmod 0755 'nginx/conf.d' +maybe chmod 0644 'nginx/conf.d/default.conf' +maybe chmod 0644 'nginx/conf.d/status.conf' +maybe chmod 0644 'nginx/conf.d/tls.conf' +maybe chmod 0644 'nginx/conf.d/upstream.conf' +maybe chmod 0644 'nginx/fastcgi.conf' +maybe chmod 0644 'nginx/fastcgi.conf.default' +maybe chmod 0644 'nginx/fastcgi_params' +maybe chmod 0644 'nginx/fastcgi_params.default' +maybe chmod 0755 'nginx/global' +maybe chmod 0644 'nginx/global/php.conf' +maybe chmod 0644 'nginx/global/php74.conf' +maybe chmod 0644 'nginx/global/restrictions.conf' +maybe chmod 0644 'nginx/global/security.conf' +maybe chmod 0644 'nginx/global/wordpress.conf' +maybe chmod 0755 'nginx/html' +maybe chmod 0644 'nginx/html/50x.html' +maybe chmod 0644 'nginx/html/index.html' +maybe chmod 0644 'nginx/koi-utf' +maybe chmod 0644 'nginx/koi-win' +maybe chmod 0644 'nginx/mime.types' +maybe chmod 0644 'nginx/mime.types.default' +maybe chmod 0755 'nginx/modules-available' +maybe chmod 0755 'nginx/modules-enabled' +maybe chmod 0644 'nginx/nginx.conf' +maybe chmod 0644 'nginx/nginx.conf.default' +maybe chmod 0644 'nginx/proxy_params' +maybe chmod 0644 'nginx/scgi_params' +maybe chmod 0644 'nginx/scgi_params.default' +maybe chmod 0755 'nginx/sites-available' +maybe chmod 0644 'nginx/sites-available/default' +maybe chmod 0755 'nginx/sites-enabled' +maybe chmod 0755 'nginx/snippets' +maybe chmod 0644 'nginx/snippets/fastcgi-php.conf' +maybe chmod 0644 'nginx/snippets/snakeoil.conf' +maybe chmod 0644 'nginx/uwsgi_params' +maybe chmod 0644 'nginx/uwsgi_params.default' +maybe chmod 0644 'nginx/win-utf' +maybe chmod 0644 'nsswitch.conf' +maybe chmod 0755 'opendkim' +maybe chmod 0644 'opendkim.conf' +maybe chmod 0755 'opendkim/keys' +maybe chmod 0644 'opendkim/keys/key2016.private' +maybe chmod 0644 'opendkim/keys/key2016.txt' +maybe chmod 0644 'opendkim/keytable' +maybe chmod 0644 'opendkim/signingtable' +maybe chmod 0644 'opendkim/trusted' +maybe chmod 0755 'opt' +maybe chmod 0644 'pam.conf' +maybe chmod 0755 'pam.d' +maybe chmod 0644 'pam.d/chfn' +maybe chmod 0644 'pam.d/chpasswd' +maybe chmod 0644 'pam.d/chsh' +maybe chmod 0644 'pam.d/common-account' +maybe chmod 0644 'pam.d/common-auth' +maybe chmod 0644 'pam.d/common-password' +maybe chmod 0644 'pam.d/common-session' +maybe chmod 0644 'pam.d/common-session-noninteractive' +maybe chmod 0644 'pam.d/cron' +maybe chmod 0644 'pam.d/login' +maybe chmod 0644 'pam.d/newusers' +maybe chmod 0644 'pam.d/other' +maybe chmod 0644 'pam.d/passwd' +maybe chmod 0644 'pam.d/runuser' +maybe chmod 0644 'pam.d/runuser-l' +maybe chmod 0644 'pam.d/sshd' +maybe chmod 0644 'pam.d/su' +maybe chmod 0644 'pam.d/su-l' +maybe chmod 0644 'pam.d/sudo' +maybe chmod 0644 'papersize' +maybe chmod 0644 'passwd' +maybe chmod 0644 'passwd-' +maybe chmod 0644 'passwd.org' +maybe chmod 0755 'perl' +maybe chmod 0755 'perl/Net' +maybe chmod 0644 'perl/Net/libnet.cfg' +maybe chmod 0755 'php' +maybe chmod 0755 'php/8.0' +maybe chmod 0755 'php/8.0/cgi' +maybe chmod 0755 'php/8.0/cgi/conf.d' +maybe chmod 0755 'php/8.0/cli' +maybe chmod 0755 'php/8.0/cli/conf.d' +maybe chmod 0755 'php/8.0/fpm' +maybe chmod 0755 'php/8.0/fpm/conf.d' +maybe chmod 0755 'php/8.0/fpm/pool.d' +maybe chmod 0755 'php/8.0/mods-available' +maybe chmod 0755 'postfix' +maybe chmod 0644 'postfix/dh_1024.pem' +maybe chmod 0644 'postfix/dh_512.pem' +maybe chmod 0644 'postfix/dynamicmaps.cf' +maybe chmod 0755 'postfix/dynamicmaps.cf.d' +maybe chmod 0644 'postfix/main.cf' +maybe chmod 0644 'postfix/main.cf.proto' +maybe chmod 0644 'postfix/makedefs.out' +maybe chmod 0644 'postfix/master.cf' +maybe chmod 0644 'postfix/master.cf.proto' +maybe chmod 0644 'postfix/mysql_sender_login_maps.cf' +maybe chmod 0644 'postfix/mysql_tls_policy.cf' +maybe chmod 0644 'postfix/mysql_virtual_alias_maps.cf' +maybe chmod 0644 'postfix/mysql_virtual_domains_maps.cf' +maybe chmod 0644 'postfix/mysql_virtual_mailbox_maps.cf' +maybe chmod 0644 'postfix/mysql_virtual_recipient_access.cf' +maybe chmod 0755 'postfix/post-install' +maybe chmod 0644 'postfix/postfix-files' +maybe chmod 0755 'postfix/postfix-files.d' +maybe chmod 0644 'postfix/postfix-files.d/mysql.files' +maybe chmod 0644 'postfix/postfix-files.d/pcre.files' +maybe chmod 0644 'postfix/postfix-files.d/sqlite.files' +maybe chmod 0755 'postfix/postfix-script' +maybe chmod 0644 'postfix/postscreen_access' +maybe chmod 0644 'postfix/reject_domains' +maybe chmod 0644 'postfix/reject_domains.db' +maybe chmod 0755 'postfix/sasl' +maybe chmod 0644 'postfix/sender_access' +maybe chmod 0644 'postfix/sender_access.db' +maybe chmod 0755 'postfix/sslcert' +maybe chmod 0644 'postfix/sslcert/mailserver.crt.2015' +maybe chmod 0644 'postfix/sslcert/mailserver.key.2015' +maybe chmod 0644 'postfix/submission_header_cleanup' +maybe chmod 0644 'postfix/without_ptr' +maybe chmod 0644 'postfix/without_ptr.db' +maybe chmod 0755 'postgrey' +maybe chmod 0644 'postgrey/whitelist_clients' +maybe chmod 0644 'postgrey/whitelist_recipients' +maybe chmod 0755 'ppp' +maybe chmod 0755 'ppp/ip-down.d' +maybe chmod 0755 'ppp/ip-up.d' +maybe chmod 0644 'profile' +maybe chmod 0755 'profile.d' +maybe chmod 0644 'profile.d/Z99-cloud-locale-test.sh' +maybe chmod 0644 'profile.d/bash_completion.sh' +maybe chmod 0644 'profile.d/gawk.csh' +maybe chmod 0644 'profile.d/gawk.sh' +maybe chmod 0644 'protocols' +maybe chmod 0755 'python' +maybe chmod 0644 'python/debian_config' +maybe chmod 0755 'python2.7' +maybe chmod 0644 'python2.7/sitecustomize.py' +maybe chmod 0755 'python3' +maybe chmod 0755 'python3.7' +maybe chmod 0644 'python3.7/sitecustomize.py' +maybe chmod 0755 'python3.9' +maybe chmod 0644 'python3.9/sitecustomize.py' +maybe chmod 0644 'python3/debian_config' +maybe chmod 0755 'qemu' +maybe chmod 0755 'qemu/fsfreeze-hook' +maybe chmod 0755 'qemu/fsfreeze-hook.d' +maybe chmod 0755 'razor' +maybe chmod 0644 'razor/razor-agent.conf' +maybe chmod 0755 'rc0.d' +maybe chmod 0755 'rc1.d' +maybe chmod 0755 'rc2.d' +maybe chmod 0755 'rc3.d' +maybe chmod 0755 'rc4.d' +maybe chmod 0755 'rc5.d' +maybe chmod 0755 'rc6.d' +maybe chmod 0755 'rcS.d' +maybe chown 'redis' 'redis' +maybe chgrp 'redis' 'redis' +maybe chmod 2770 'redis' +maybe chgrp 'redis' 'redis/redis-server.post-down.d' +maybe chmod 2755 'redis/redis-server.post-down.d' +maybe chgrp 'redis' 'redis/redis-server.post-down.d/00_example' +maybe chmod 0755 'redis/redis-server.post-down.d/00_example' +maybe chgrp 'redis' 'redis/redis-server.post-up.d' +maybe chmod 2755 'redis/redis-server.post-up.d' +maybe chgrp 'redis' 'redis/redis-server.post-up.d/00_example' +maybe chmod 0755 'redis/redis-server.post-up.d/00_example' +maybe chgrp 'redis' 'redis/redis-server.pre-down.d' +maybe chmod 2755 'redis/redis-server.pre-down.d' +maybe chgrp 'redis' 'redis/redis-server.pre-down.d/00_example' +maybe chmod 0755 'redis/redis-server.pre-down.d/00_example' +maybe chgrp 'redis' 'redis/redis-server.pre-up.d' +maybe chmod 2755 'redis/redis-server.pre-up.d' +maybe chgrp 'redis' 'redis/redis-server.pre-up.d/00_example' +maybe chmod 0755 'redis/redis-server.pre-up.d/00_example' +maybe chown 'redis' 'redis/redis.conf' +maybe chgrp 'redis' 'redis/redis.conf' +maybe chmod 0640 'redis/redis.conf' +maybe chmod 0644 'reportbug.conf' +maybe chmod 0755 'resolvconf' +maybe chmod 0755 'resolvconf/update-libc.d' +maybe chmod 0644 'rkhunter.conf' +maybe chmod 0644 'rkhunter.conf.local' +maybe chmod 0644 'rpc' +maybe chmod 0755 'rspamd' +maybe chmod 0644 'rspamd/actions.conf' +maybe chmod 0644 'rspamd/cgp.inc' +maybe chmod 0644 'rspamd/common.conf' +maybe chmod 0644 'rspamd/composites.conf' +maybe chmod 0644 'rspamd/groups.conf' +maybe chmod 0755 'rspamd/local.d' +maybe chmod 0644 'rspamd/local.d/antivirus.conf' +maybe chmod 0644 'rspamd/local.d/classifier-bayes.inc' +maybe chmod 0644 'rspamd/local.d/dkim_signing.conf' +maybe chmod 0644 'rspamd/local.d/external_services.conf' +maybe chmod 0644 'rspamd/local.d/force_actions.conf' +maybe chmod 0644 'rspamd/local.d/logging.inc' +maybe chmod 0644 'rspamd/local.d/milter_headers.inc' +maybe chmod 0644 'rspamd/local.d/multimap.conf' +maybe chmod 0644 'rspamd/local.d/neural.conf' +maybe chmod 0644 'rspamd/local.d/neural_group.conf' +maybe chmod 0644 'rspamd/local.d/options.inc' +maybe chmod 0644 'rspamd/local.d/phishing.conf' +maybe chmod 0644 'rspamd/local.d/redis.conf' +maybe chmod 0644 'rspamd/local.d/whitelist.sender.domain.map' +maybe chmod 0644 'rspamd/local.d/worker-controller.inc' +maybe chmod 0644 'rspamd/local.d/worker-normal.inc' +maybe chmod 0644 'rspamd/local.d/worker-proxy.inc' +maybe chmod 0644 'rspamd/logging.inc' +maybe chmod 0755 'rspamd/maps.d' +maybe chmod 0644 'rspamd/maps.d/dmarc_whitelist.inc' +maybe chmod 0644 'rspamd/maps.d/maillist.inc' +maybe chmod 0644 'rspamd/maps.d/mid.inc' +maybe chmod 0644 'rspamd/maps.d/mime_types.inc' +maybe chmod 0644 'rspamd/maps.d/redirectors.inc' +maybe chmod 0644 'rspamd/maps.d/spf_dkim_whitelist.inc' +maybe chmod 0644 'rspamd/maps.d/surbl-whitelist.inc' +maybe chmod 0644 'rspamd/metrics.conf' +maybe chmod 0644 'rspamd/modules.conf' +maybe chmod 0755 'rspamd/modules.d' +maybe chmod 0644 'rspamd/modules.d/antivirus.conf' +maybe chmod 0644 'rspamd/modules.d/arc.conf' +maybe chmod 0644 'rspamd/modules.d/asn.conf' +maybe chmod 0644 'rspamd/modules.d/chartable.conf' +maybe chmod 0644 'rspamd/modules.d/clickhouse.conf' +maybe chmod 0644 'rspamd/modules.d/dcc.conf' +maybe chmod 0644 'rspamd/modules.d/dkim.conf' +maybe chmod 0644 'rspamd/modules.d/dkim_signing.conf' +maybe chmod 0644 'rspamd/modules.d/dmarc.conf' +maybe chmod 0644 'rspamd/modules.d/elastic.conf' +maybe chmod 0644 'rspamd/modules.d/emails.conf' +maybe chmod 0644 'rspamd/modules.d/external_services.conf' +maybe chmod 0644 'rspamd/modules.d/force_actions.conf' +maybe chmod 0644 'rspamd/modules.d/forged_recipients.conf' +maybe chmod 0644 'rspamd/modules.d/fuzzy_check.conf' +maybe chmod 0644 'rspamd/modules.d/greylist.conf' +maybe chmod 0644 'rspamd/modules.d/hfilter.conf' +maybe chmod 0644 'rspamd/modules.d/history_redis.conf' +maybe chmod 0644 'rspamd/modules.d/http_headers.conf' +maybe chmod 0644 'rspamd/modules.d/maillist.conf' +maybe chmod 0644 'rspamd/modules.d/metadata_exporter.conf' +maybe chmod 0644 'rspamd/modules.d/metric_exporter.conf' +maybe chmod 0644 'rspamd/modules.d/mid.conf' +maybe chmod 0644 'rspamd/modules.d/milter_headers.conf' +maybe chmod 0644 'rspamd/modules.d/mime_types.conf' +maybe chmod 0644 'rspamd/modules.d/multimap.conf' +maybe chmod 0644 'rspamd/modules.d/mx_check.conf' +maybe chmod 0644 'rspamd/modules.d/neural.conf' +maybe chmod 0644 'rspamd/modules.d/once_received.conf' +maybe chmod 0644 'rspamd/modules.d/p0f.conf' +maybe chmod 0644 'rspamd/modules.d/phishing.conf' +maybe chmod 0644 'rspamd/modules.d/ratelimit.conf' +maybe chmod 0644 'rspamd/modules.d/rbl.conf' +maybe chmod 0644 'rspamd/modules.d/redis.conf' +maybe chmod 0644 'rspamd/modules.d/regexp.conf' +maybe chmod 0644 'rspamd/modules.d/replies.conf' +maybe chmod 0644 'rspamd/modules.d/reputation.conf' +maybe chmod 0644 'rspamd/modules.d/rspamd_update.conf' +maybe chmod 0644 'rspamd/modules.d/spamassassin.conf' +maybe chmod 0644 'rspamd/modules.d/spamtrap.conf' +maybe chmod 0644 'rspamd/modules.d/spf.conf' +maybe chmod 0644 'rspamd/modules.d/surbl.conf' +maybe chmod 0644 'rspamd/modules.d/trie.conf' +maybe chmod 0644 'rspamd/modules.d/url_redirector.conf' +maybe chmod 0644 'rspamd/modules.d/whitelist.conf' +maybe chmod 0644 'rspamd/options.inc' +maybe chmod 0755 'rspamd/override.d' +maybe chmod 0644 'rspamd/override.d/classifier-bayes.conf' +maybe chmod 0644 'rspamd/override.d/milter_headers.inc' +maybe chmod 0644 'rspamd/override.d/worker-fuzzy.conf' +maybe chmod 0644 'rspamd/rspamd.conf' +maybe chmod 0755 'rspamd/scores.d' +maybe chmod 0644 'rspamd/scores.d/content_group.conf' +maybe chmod 0644 'rspamd/scores.d/fuzzy_group.conf' +maybe chmod 0644 'rspamd/scores.d/headers_group.conf' +maybe chmod 0644 'rspamd/scores.d/hfilter_group.conf' +maybe chmod 0644 'rspamd/scores.d/mime_types_group.conf' +maybe chmod 0644 'rspamd/scores.d/mua_group.conf' +maybe chmod 0644 'rspamd/scores.d/phishing_group.conf' +maybe chmod 0644 'rspamd/scores.d/policies_group.conf' +maybe chmod 0644 'rspamd/scores.d/rbl_group.conf' +maybe chmod 0644 'rspamd/scores.d/statistics_group.conf' +maybe chmod 0644 'rspamd/scores.d/subject_group.conf' +maybe chmod 0644 'rspamd/scores.d/surbl_group.conf' +maybe chmod 0644 'rspamd/scores.d/whitelist_group.conf' +maybe chmod 0644 'rspamd/settings.conf' +maybe chmod 0644 'rspamd/statistic.conf' +maybe chmod 0644 'rspamd/worker-controller.inc' +maybe chmod 0644 'rspamd/worker-fuzzy.inc' +maybe chmod 0644 'rspamd/worker-normal.inc' +maybe chmod 0644 'rspamd/worker-proxy.inc' +maybe chmod 0644 'rsyslog.conf' +maybe chmod 0755 'rsyslog.d' +maybe chmod 0644 'rsyslog.d/21-cloudinit.conf' +maybe chmod 0755 'runit' +maybe chmod 0755 'runit/runsvdir' +maybe chmod 0755 'runit/runsvdir/default' +maybe chmod 0755 'security' +maybe chmod 0644 'security/access.conf' +maybe chmod 0644 'security/faillock.conf' +maybe chmod 0644 'security/group.conf' +maybe chmod 0644 'security/limits.conf' +maybe chmod 0755 'security/limits.d' +maybe chmod 0644 'security/namespace.conf' +maybe chmod 0755 'security/namespace.d' +maybe chmod 0755 'security/namespace.init' +maybe chmod 0600 'security/opasswd' +maybe chmod 0644 'security/pam_env.conf' +maybe chmod 0644 'security/sepermit.conf' +maybe chmod 0644 'security/time.conf' +maybe chmod 0644 'security/user_map.conf' +maybe chmod 0755 'selinux' +maybe chmod 0644 'selinux/semanage.conf' +maybe chmod 0755 'sensors.d' +maybe chmod 0644 'sensors.d/.placeholder' +maybe chmod 0644 'sensors3.conf' +maybe chmod 0644 'services' +maybe chgrp 'shadow' 'shadow' +maybe chmod 0640 'shadow' +maybe chgrp 'shadow' 'shadow-' +maybe chmod 0640 'shadow-' +maybe chgrp 'shadow' 'shadow.org' +maybe chmod 0640 'shadow.org' +maybe chmod 0644 'shells' +maybe chmod 0755 'skel' +maybe chmod 0644 'skel/.bash_logout' +maybe chmod 0644 'skel/.bashrc' +maybe chmod 0644 'skel/.profile' +maybe chmod 0755 'spamassassin' +maybe chmod 0755 'spamassassin/sa-update-hooks.d' +maybe chmod 0755 'ssh' +maybe chmod 0644 'ssh/moduli' +maybe chmod 0644 'ssh/ssh_config' +maybe chmod 0755 'ssh/ssh_config.d' +maybe chmod 0600 'ssh/ssh_host_dsa_key' +maybe chmod 0644 'ssh/ssh_host_dsa_key.pub' +maybe chmod 0600 'ssh/ssh_host_ecdsa_key' +maybe chmod 0644 'ssh/ssh_host_ecdsa_key.pub' +maybe chmod 0600 'ssh/ssh_host_ed25519_key' +maybe chmod 0644 'ssh/ssh_host_ed25519_key.pub' +maybe chmod 0600 'ssh/ssh_host_rsa_key' +maybe chmod 0644 'ssh/ssh_host_rsa_key.pub' +maybe chmod 0644 'ssh/sshd_config' +maybe chmod 0755 'ssh/sshd_config.d' +maybe chmod 0755 'ssl' +maybe chmod 0755 'ssl/certs' +maybe chmod 0644 'ssl/certs/ca-certificates.crt' +maybe chmod 0644 'ssl/openssl.cnf' +maybe chmod 0700 'ssl/private' +maybe chmod 0644 'subgid' +maybe chmod 0644 'subgid-' +maybe chmod 0644 'subuid' +maybe chmod 0644 'subuid-' +maybe chmod 0644 'sudo.conf' +maybe chmod 0644 'sudo_logsrvd.conf' +maybe chmod 0440 'sudoers' +maybe chmod 0755 'sudoers.d' +maybe chmod 0440 'sudoers.d/README' +maybe chmod 0755 'sv' +maybe chmod 0755 'sv/ssh' +maybe chmod 0755 'sv/ssh/.meta' +maybe chmod 0644 'sv/ssh/.meta/installed' +maybe chmod 0755 'sv/ssh/finish' +maybe chmod 0755 'sv/ssh/log' +maybe chmod 0755 'sv/ssh/log/run' +maybe chmod 0755 'sv/ssh/run' +maybe chmod 0755 'synth-shell' +maybe chmod 0755 'synth-shell/examples' +maybe chmod 0644 'synth-shell/examples/synth-shell-greeter.org.uma.mapir.cyan.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-greeter.org.uma.mapir.gray.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-greeter.org.uma.mapir.green.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-greeter.org.uma.mapir.orange.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-greeter.org.uma.scbi.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-greeter.uma.ea7rct.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.blue.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.gray.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.green.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.magenta.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.orange.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.red.config' +maybe chmod 0644 'synth-shell/examples/synth-shell-prompt.yellow.config' +maybe chmod 0755 'synth-shell/os' +maybe chmod 0644 'synth-shell/os/synth-shell-greeter.archlinux.config' +maybe chmod 0644 'synth-shell/os/synth-shell-greeter.debian.config' +maybe chmod 0644 'synth-shell/os/synth-shell-greeter.manjaro.config' +maybe chmod 0644 'synth-shell/os/synth-shell-greeter.popos.config' +maybe chmod 0644 'synth-shell/os/synth-shell-greeter.raspbian.config' +maybe chmod 0644 'synth-shell/os/synth-shell-greeter.root.config' +maybe chmod 0644 'synth-shell/os/synth-shell-greeter.ubuntu.config' +maybe chmod 0755 'synth-shell/personal' +maybe chmod 0644 'synth-shell/personal/README.md' +maybe chmod 0644 'synth-shell/personal/synth-shell-greeter.andresgongora.config' +maybe chmod 0644 'synth-shell/synth-shell-greeter.config' +maybe chmod 0644 'synth-shell/synth-shell-greeter.config.default' +maybe chmod 0644 'synth-shell/synth-shell-prompt.config' +maybe chmod 0644 'synth-shell/synth-shell-prompt.config.default' +maybe chmod 0644 'synth-shell/synth-shell-prompt.root.config' +maybe chmod 0644 'sysctl.conf' +maybe chmod 0755 'sysctl.d' +maybe chmod 0644 'sysctl.d/50-IPv6.conf' +maybe chmod 0644 'sysctl.d/99-nc-kernel.conf' +maybe chmod 0644 'sysctl.d/README.sysctl' +maybe chmod 0755 'systemd' +maybe chmod 0644 'systemd/journald.conf' +maybe chmod 0644 'systemd/logind.conf' +maybe chmod 0755 'systemd/network' +maybe chmod 0644 'systemd/networkd.conf' +maybe chmod 0644 'systemd/pstore.conf' +maybe chmod 0644 'systemd/resolved.conf' +maybe chmod 0644 'systemd/sleep.conf' +maybe chmod 0755 'systemd/system' +maybe chmod 0644 'systemd/system.conf' +maybe chmod 0755 'systemd/system/cloud-init.target.wants' +maybe chmod 0755 'systemd/system/default.target.wants' +maybe chmod 0755 'systemd/system/getty.target.wants' +maybe chmod 0755 'systemd/system/mariadb.service.d' +maybe chmod 0644 'systemd/system/mariadb.service.d/migrated-from-my.cnf-settings.conf' +maybe chmod 0755 'systemd/system/multi-user.target.wants' +maybe chmod 0755 'systemd/system/network-online.target.wants' +maybe chmod 0755 'systemd/system/sysinit.target.wants' +maybe chmod 0755 'systemd/system/timers.target.wants' +maybe chmod 0644 'systemd/timesyncd.conf' +maybe chmod 0755 'systemd/user' +maybe chmod 0644 'systemd/user.conf' +maybe chmod 0755 'systemd/user/sockets.target.wants' +maybe chmod 0755 'terminfo' +maybe chmod 0644 'terminfo/README' +maybe chmod 0644 'timezone' +maybe chmod 0755 'tmpfiles.d' +maybe chmod 0644 'ucf.conf' +maybe chmod 0755 'udev' +maybe chmod 0755 'udev/hwdb.d' +maybe chmod 0755 'udev/rules.d' +maybe chmod 0644 'udev/rules.d/70-persistent-net.rules' +maybe chmod 0644 'udev/rules.d/80-hotplug-cpu-mem.rules' +maybe chmod 0644 'udev/udev.conf' +maybe chmod 0755 'ufw' +maybe chmod 0755 'ufw/applications.d' +maybe chmod 0644 'ufw/applications.d/nginx' +maybe chmod 0644 'ufw/applications.d/openssh-server' +maybe chmod 0755 'update-motd.d' +maybe chmod 0755 'update-motd.d/10-uname' +maybe chmod 0644 'vconsole.conf' +maybe chmod 0755 'vim' +maybe chmod 0644 'vim/vimrc' +maybe chmod 0644 'vim/vimrc.tiny' +maybe chmod 0644 'wgetrc' +maybe chmod 0644 'xattr.conf' +maybe chmod 0755 'xdg' +maybe chmod 0755 'xdg/autostart' +maybe chmod 0644 'xdg/autostart/xdg-user-dirs.desktop' +maybe chmod 0755 'xdg/systemd' +maybe chmod 0644 'xdg/user-dirs.conf' +maybe chmod 0644 'xdg/user-dirs.defaults' diff --git a/.gitignore b/.gitignore new file mode 100644 index 00000000..9196cf5c --- /dev/null +++ b/.gitignore @@ -0,0 +1,54 @@ +# begin section managed by etckeeper (do not edit this section by hand) + +# new and old versions of conffiles, stored by dpkg +*.dpkg-* +# new and old versions of conffiles, stored by ucf +*.ucf-* + +# old versions of files +*.old + +# mount(8) records system state here, no need to store these +blkid.tab +blkid.tab.old + +# some other files in /etc that typically do not need to be tracked +nologin +ld.so.cache +prelink.cache +mtab +mtab.fuselock +.pwd.lock +*.LOCK +network/run +adjtime +lvm/cache +lvm/archive +X11/xdm/authdir/authfiles/* +ntp.conf.dhcp +.initctl +webmin/fsdump/*.status +webmin/webmin/oscache +apparmor.d/cache/* +service/*/supervise/* +service/*/log/supervise/* +sv/*/supervise/* +sv/*/log/supervise/* +*.elc +*.pyc +*.pyo +init.d/.depend.* +openvpn/openvpn-status.log +cups/subscriptions.conf +cups/subscriptions.conf.O +fake-hwclock.data +check_mk/logwatch.state + +# editor temp files +*~ +.*.sw? +.sw? +\#*\# +DEADJOE + +# end section managed by etckeeper diff --git a/ImageMagick-6/coder.xml b/ImageMagick-6/coder.xml new file mode 100644 index 00000000..bd80a22d --- /dev/null +++ b/ImageMagick-6/coder.xml @@ -0,0 +1,23 @@ + + + + + +]> + + + + + + diff --git a/ImageMagick-6/colors.xml b/ImageMagick-6/colors.xml new file mode 100644 index 00000000..201b7351 --- /dev/null +++ b/ImageMagick-6/colors.xml @@ -0,0 +1,28 @@ + + + + + + +]> + + + + + + + + + + + + diff --git a/ImageMagick-6/delegates.xml b/ImageMagick-6/delegates.xml new file mode 100644 index 00000000..9e7434d4 --- /dev/null +++ b/ImageMagick-6/delegates.xml @@ -0,0 +1,125 @@ + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/log.xml b/ImageMagick-6/log.xml new file mode 100644 index 00000000..8a290992 --- /dev/null +++ b/ImageMagick-6/log.xml @@ -0,0 +1,80 @@ + + + + + + + + + +]> + + + + + + + + + diff --git a/ImageMagick-6/magic.xml b/ImageMagick-6/magic.xml new file mode 100644 index 00000000..7f17731b --- /dev/null +++ b/ImageMagick-6/magic.xml @@ -0,0 +1,23 @@ + + + + + + +]> + + + + + + + diff --git a/ImageMagick-6/mime.xml b/ImageMagick-6/mime.xml new file mode 100644 index 00000000..3b768df4 --- /dev/null +++ b/ImageMagick-6/mime.xml @@ -0,0 +1,1146 @@ + + + + + + + + + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/policy.xml b/ImageMagick-6/policy.xml new file mode 100644 index 00000000..808fcf60 --- /dev/null +++ b/ImageMagick-6/policy.xml @@ -0,0 +1,99 @@ + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/quantization-table.xml b/ImageMagick-6/quantization-table.xml new file mode 100644 index 00000000..fb718749 --- /dev/null +++ b/ImageMagick-6/quantization-table.xml @@ -0,0 +1,68 @@ + + + + + + + + + + + + + + +]> + + + + Luma Quantization Table + + 16, 16, 16, 18, 25, 37, 56, 85, + 16, 17, 20, 27, 34, 40, 53, 75, + 16, 20, 24, 31, 43, 62, 91, 135, + 18, 27, 31, 40, 53, 74, 106, 156, + 25, 34, 43, 53, 69, 94, 131, 189, + 37, 40, 62, 74, 94, 124, 169, 238, + 56, 53, 91, 106, 131, 169, 226, 311, + 85, 75, 135, 156, 189, 238, 311, 418 + +
+ +
+ diff --git a/ImageMagick-6/thresholds.xml b/ImageMagick-6/thresholds.xml new file mode 100644 index 00000000..02b96a85 --- /dev/null +++ b/ImageMagick-6/thresholds.xml @@ -0,0 +1,336 @@ + + + + + + + + + +]> + + + + + + Threshold 1x1 (non-dither) + + 1 + + + + + Checkerboard 2x1 (dither) + + 1 2 + 2 1 + + + + + + Ordered 2x2 (dispersed) + + 1 3 + 4 2 + + + + + Ordered 3x3 (dispersed) + + 3 7 4 + 6 1 9 + 2 8 5 + + + + + + Ordered 4x4 (dispersed) + + 1 9 3 11 + 13 5 15 7 + 4 12 2 10 + 16 8 14 6 + + + + + + Ordered 8x8 (dispersed) + + 1 49 13 61 4 52 16 64 + 33 17 45 29 36 20 48 32 + 9 57 5 53 12 60 8 56 + 41 25 37 21 44 28 40 24 + 3 51 15 63 2 50 14 62 + 35 19 47 31 34 18 46 30 + 11 59 7 55 10 58 6 54 + 43 27 39 23 42 26 38 22 + + + + + + Halftone 4x4 (angled) + + 4 2 7 5 + 3 1 8 6 + 7 5 4 2 + 8 6 3 1 + + + + + Halftone 6x6 (angled) + + 14 13 10 8 2 3 + 16 18 12 7 1 4 + 15 17 11 9 6 5 + 8 2 3 14 13 10 + 7 1 4 16 18 12 + 9 6 5 15 17 11 + + + + + Halftone 8x8 (angled) + + 13 7 8 14 17 21 22 18 + 6 1 3 9 28 31 29 23 + 5 2 4 10 27 32 30 24 + 16 12 11 15 20 26 25 19 + 17 21 22 18 13 7 8 14 + 28 31 29 23 6 1 3 9 + 27 32 30 24 5 2 4 10 + 20 26 25 19 16 12 11 15 + + + + + + Halftone 4x4 (orthogonal) + + 7 13 11 4 + 12 16 14 8 + 10 15 6 2 + 5 9 3 1 + + + + + Halftone 6x6 (orthogonal) + + 7 17 27 14 9 4 + 21 29 33 31 18 11 + 24 32 36 34 25 22 + 19 30 35 28 20 10 + 8 15 26 16 6 2 + 5 13 23 12 3 1 + + + + + Halftone 8x8 (orthogonal) + + 7 21 33 43 36 19 9 4 + 16 27 51 55 49 29 14 11 + 31 47 57 61 59 45 35 23 + 41 53 60 64 62 52 40 38 + 37 44 58 63 56 46 30 22 + 15 28 48 54 50 26 17 10 + 8 18 34 42 32 20 6 2 + 5 13 25 39 24 12 3 1 + + + + + + Halftone 16x16 (orthogonal) + + 4 12 24 44 72 100 136 152 150 134 98 70 42 23 11 3 + 7 16 32 52 76 104 144 160 158 142 102 74 50 31 15 6 + 19 27 40 60 92 132 168 180 178 166 130 90 58 39 26 18 + 36 48 56 80 124 176 188 204 203 187 175 122 79 55 47 35 + 64 68 84 116 164 200 212 224 223 211 199 162 114 83 67 63 + 88 96 112 156 192 216 232 240 239 231 214 190 154 111 95 87 + 108 120 148 184 208 228 244 252 251 243 226 206 182 147 119 107 + 128 140 172 196 219 235 247 256 255 246 234 218 194 171 139 127 + 126 138 170 195 220 236 248 253 254 245 233 217 193 169 137 125 + 106 118 146 183 207 227 242 249 250 241 225 205 181 145 117 105 + 86 94 110 155 191 215 229 238 237 230 213 189 153 109 93 85 + 62 66 82 115 163 198 210 221 222 209 197 161 113 81 65 61 + 34 46 54 78 123 174 186 202 201 185 173 121 77 53 45 33 + 20 28 37 59 91 131 167 179 177 165 129 89 57 38 25 17 + 8 13 29 51 75 103 143 159 157 141 101 73 49 30 14 5 + 1 9 21 43 71 99 135 151 149 133 97 69 41 22 10 2 + + + + + + + Circles 5x5 (black) + + 1 21 16 15 4 + 5 17 20 19 14 + 6 21 25 24 12 + 7 18 22 23 11 + 2 8 9 10 3 + + + + + + Circles 5x5 (white) + + 25 21 10 11 22 + 20 9 6 7 12 + 19 5 1 2 13 + 18 8 4 3 14 + 24 17 16 15 23 + + + + + Circles 6x6 (black) + + 1 5 14 13 12 4 + 6 22 28 27 21 11 + 15 29 35 34 26 20 + 16 30 36 33 25 19 + 7 23 31 32 24 10 + 2 8 17 18 9 3 + + + + + Circles 6x6 (white) + + 36 32 23 24 25 33 + 31 15 9 10 16 26 + 22 8 2 3 11 17 + 21 7 1 4 12 18 + 30 14 6 5 13 27 + 35 29 20 19 28 34 + + + + + Circles 7x7 (black) + + 3 9 18 28 17 8 2 + 10 24 33 39 32 23 7 + 19 34 44 48 43 31 16 + 25 40 45 49 47 38 27 + 20 35 41 46 42 29 15 + 11 21 36 37 28 22 6 + 4 12 13 26 14 5 1 + + + + + + Circles 7x7 (white) + + 47 41 32 22 33 42 48 + 40 26 17 11 18 27 43 + 31 16 6 2 7 19 34 + 25 10 5 1 3 12 23 + 30 15 9 4 8 20 35 + 39 29 14 13 21 28 44 + 46 38 37 24 36 45 49 + + + + + + + diff --git a/ImageMagick-6/type-apple.xml b/ImageMagick-6/type-apple.xml new file mode 100644 index 00000000..57fe9d14 --- /dev/null +++ b/ImageMagick-6/type-apple.xml @@ -0,0 +1,1367 @@ + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/type-dejavu.xml b/ImageMagick-6/type-dejavu.xml new file mode 100644 index 00000000..29b3c204 --- /dev/null +++ b/ImageMagick-6/type-dejavu.xml @@ -0,0 +1,58 @@ + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/type-ghostscript.xml b/ImageMagick-6/type-ghostscript.xml new file mode 100644 index 00000000..b5162310 --- /dev/null +++ b/ImageMagick-6/type-ghostscript.xml @@ -0,0 +1,50 @@ + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/type-urw-base35.xml b/ImageMagick-6/type-urw-base35.xml new file mode 100644 index 00000000..1ddd50db --- /dev/null +++ b/ImageMagick-6/type-urw-base35.xml @@ -0,0 +1,50 @@ + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/type-windows.xml b/ImageMagick-6/type-windows.xml new file mode 100644 index 00000000..621eec42 --- /dev/null +++ b/ImageMagick-6/type-windows.xml @@ -0,0 +1,105 @@ + + + + + + + + + + + + + + + + +]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ImageMagick-6/type.xml b/ImageMagick-6/type.xml new file mode 100644 index 00000000..8ac74904 --- /dev/null +++ b/ImageMagick-6/type.xml @@ -0,0 +1,17 @@ + + + + + +]> + + + + diff --git a/NetworkManager/dispatcher.d/cloud-init-hook-network-manager b/NetworkManager/dispatcher.d/cloud-init-hook-network-manager new file mode 100755 index 00000000..67d9044a --- /dev/null +++ b/NetworkManager/dispatcher.d/cloud-init-hook-network-manager @@ -0,0 +1,26 @@ +#!/bin/sh +# This file is part of cloud-init. See LICENSE file for license information. + +# This script hooks into NetworkManager(8) via its scripts +# arguments are 'interface-name' and 'action' +# +is_azure() { + local dmi_path="/sys/class/dmi/id/board_vendor" vendor="" + if [ -e "$dmi_path" ] && read vendor < "$dmi_path"; then + [ "$vendor" = "Microsoft Corporation" ] && return 0 + fi + return 1 +} + +is_enabled() { + # only execute hooks if cloud-init is enabled and on azure + [ -e /run/cloud-init/enabled ] || return 1 + is_azure +} + +if is_enabled; then + case "$1:$2" in + *:up) exec cloud-init dhclient-hook up "$1";; + *:down) exec cloud-init dhclient-hook down "$1";; + esac +fi diff --git a/X11/Xsession.d/90gpg-agent b/X11/Xsession.d/90gpg-agent new file mode 100644 index 00000000..8b45b05d --- /dev/null +++ b/X11/Xsession.d/90gpg-agent @@ -0,0 +1,22 @@ +# On systems with systemd running, we expect the agent to be launched +# via systemd's user mode (see +# /usr/lib/systemd/user/gpg-agent.{socket,service} and +# systemd.unit(5)). This allows systemd to clean up the agent +# automatically at logout. + +# If systemd is absent from your system, or you do not permit it to +# run in user mode, then you may need to manually launch gpg-agent +# from your session initialization with something like "gpgconf +# --launch gpg-agent" + +# Nonetheless, ssh and older versions of gpg require environment +# variables to be set in order to find the agent, so we will set those +# here. + +agent_sock=$(gpgconf --list-dirs agent-socket) +export GPG_AGENT_INFO=${agent_sock}:0:1 +if [ -n "$(gpgconf --list-options gpg-agent | \ + awk -F: '/^enable-ssh-support:/{ print $10 }')" ]; then + export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket) +fi + diff --git a/adduser.conf b/adduser.conf new file mode 100644 index 00000000..d045994f --- /dev/null +++ b/adduser.conf @@ -0,0 +1,85 @@ +# /etc/adduser.conf: `adduser' configuration. +# See adduser(8) and adduser.conf(5) for full documentation. + +# The DSHELL variable specifies the default login shell on your +# system. +DSHELL=/bin/bash + +# The DHOME variable specifies the directory containing users' home +# directories. +DHOME=/home + +# If GROUPHOMES is "yes", then the home directories will be created as +# /home/groupname/user. +GROUPHOMES=no + +# If LETTERHOMES is "yes", then the created home directories will have +# an extra directory - the first letter of the user name. For example: +# /home/u/user. +LETTERHOMES=no + +# The SKEL variable specifies the directory containing "skeletal" user +# files; in other words, files such as a sample .profile that will be +# copied to the new user's home directory when it is created. +SKEL=/etc/skel + +# FIRST_SYSTEM_[GU]ID to LAST_SYSTEM_[GU]ID inclusive is the range for UIDs +# for dynamically allocated administrative and system accounts/groups. +# Please note that system software, such as the users allocated by the base-passwd +# package, may assume that UIDs less than 100 are unallocated. +FIRST_SYSTEM_UID=100 +LAST_SYSTEM_UID=999 + +FIRST_SYSTEM_GID=100 +LAST_SYSTEM_GID=999 + +# FIRST_[GU]ID to LAST_[GU]ID inclusive is the range of UIDs of dynamically +# allocated user accounts/groups. +FIRST_UID=1000 +LAST_UID=59999 + +FIRST_GID=1000 +LAST_GID=59999 + +# The USERGROUPS variable can be either "yes" or "no". If "yes" each +# created user will be given their own group to use as a default. If +# "no", each created user will be placed in the group whose gid is +# USERS_GID (see below). +USERGROUPS=yes + +# If USERGROUPS is "no", then USERS_GID should be the GID of the group +# `users' (or the equivalent group) on your system. +USERS_GID=100 + +# If DIR_MODE is set, directories will be created with the specified +# mode. Otherwise the default mode 0755 will be used. +DIR_MODE=0755 + +# If SETGID_HOME is "yes" home directories for users with their own +# group the setgid bit will be set. This was the default for +# versions << 3.13 of adduser. Because it has some bad side effects we +# no longer do this per default. If you want it nevertheless you can +# still set it here. +SETGID_HOME=no + +# If QUOTAUSER is set, a default quota will be set from that user with +# `edquota -p QUOTAUSER newuser' +QUOTAUSER="" + +# If SKEL_IGNORE_REGEX is set, adduser will ignore files matching this +# regular expression when creating a new home directory +SKEL_IGNORE_REGEX="dpkg-(old|new|dist|save)" + +# Set this if you want the --add_extra_groups option to adduser to add +# new users to other groups. +# This is the list of groups that new non-system users will be added to +# Default: +#EXTRA_GROUPS="dialout cdrom floppy audio video plugdev users" + +# If ADD_EXTRA_GROUPS is set to something non-zero, the EXTRA_GROUPS +# option above will be default behavior for adding new, non-system users +#ADD_EXTRA_GROUPS=1 + + +# check user and group names also against this regular expression. +#NAME_REGEX="^[a-z][-a-z0-9_]*\$" diff --git a/alternatives/README b/alternatives/README new file mode 100644 index 00000000..4c4d2156 --- /dev/null +++ b/alternatives/README @@ -0,0 +1,2 @@ +Please read the update-alternatives(1) man page for information on this +directory and its contents. diff --git a/alternatives/arptables b/alternatives/arptables new file mode 120000 index 00000000..f8fcc7ba --- /dev/null +++ b/alternatives/arptables @@ -0,0 +1 @@ +/usr/sbin/arptables-nft \ No newline at end of file diff --git a/alternatives/arptables-restore b/alternatives/arptables-restore new file mode 120000 index 00000000..95e87dc8 --- /dev/null +++ b/alternatives/arptables-restore @@ -0,0 +1 @@ +/usr/sbin/arptables-nft-restore \ No newline at end of file diff --git a/alternatives/arptables-save b/alternatives/arptables-save new file mode 120000 index 00000000..9bb15960 --- /dev/null +++ b/alternatives/arptables-save @@ -0,0 +1 @@ +/usr/sbin/arptables-nft-save \ No newline at end of file diff --git a/alternatives/awk b/alternatives/awk new file mode 120000 index 00000000..19ba657e --- /dev/null +++ b/alternatives/awk @@ -0,0 +1 @@ +/usr/bin/gawk \ No newline at end of file diff --git a/alternatives/awk.1.gz b/alternatives/awk.1.gz new file mode 120000 index 00000000..134262bc --- /dev/null +++ b/alternatives/awk.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/gawk.1.gz \ No newline at end of file diff --git a/alternatives/builtins.7.gz b/alternatives/builtins.7.gz new file mode 120000 index 00000000..96d1b740 --- /dev/null +++ b/alternatives/builtins.7.gz @@ -0,0 +1 @@ +/usr/share/man/man7/bash-builtins.7.gz \ No newline at end of file diff --git a/alternatives/ebtables b/alternatives/ebtables new file mode 120000 index 00000000..8d5f660c --- /dev/null +++ b/alternatives/ebtables @@ -0,0 +1 @@ +/usr/sbin/ebtables-nft \ No newline at end of file diff --git a/alternatives/ebtables-restore b/alternatives/ebtables-restore new file mode 120000 index 00000000..c2e5813b --- /dev/null +++ b/alternatives/ebtables-restore @@ -0,0 +1 @@ +/usr/sbin/ebtables-nft-restore \ No newline at end of file diff --git a/alternatives/ebtables-save b/alternatives/ebtables-save new file mode 120000 index 00000000..600f8c2d --- /dev/null +++ b/alternatives/ebtables-save @@ -0,0 +1 @@ +/usr/sbin/ebtables-nft-save \ No newline at end of file diff --git a/alternatives/editor b/alternatives/editor new file mode 120000 index 00000000..7a06612b --- /dev/null +++ b/alternatives/editor @@ -0,0 +1 @@ +/bin/nano \ No newline at end of file diff --git a/alternatives/editor.1.gz b/alternatives/editor.1.gz new file mode 120000 index 00000000..bb2d082c --- /dev/null +++ b/alternatives/editor.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/nano.1.gz \ No newline at end of file diff --git a/alternatives/ex b/alternatives/ex new file mode 120000 index 00000000..0d516727 --- /dev/null +++ b/alternatives/ex @@ -0,0 +1 @@ +/usr/bin/vim.tiny \ No newline at end of file diff --git a/alternatives/ex.1.gz b/alternatives/ex.1.gz new file mode 120000 index 00000000..e02a6af1 --- /dev/null +++ b/alternatives/ex.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ex.da.1.gz b/alternatives/ex.da.1.gz new file mode 120000 index 00000000..c90068fa --- /dev/null +++ b/alternatives/ex.da.1.gz @@ -0,0 +1 @@ +/usr/share/man/da/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ex.de.1.gz b/alternatives/ex.de.1.gz new file mode 120000 index 00000000..d89833a7 --- /dev/null +++ b/alternatives/ex.de.1.gz @@ -0,0 +1 @@ +/usr/share/man/de/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ex.fr.1.gz b/alternatives/ex.fr.1.gz new file mode 120000 index 00000000..af52858f --- /dev/null +++ b/alternatives/ex.fr.1.gz @@ -0,0 +1 @@ +/usr/share/man/fr/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ex.it.1.gz b/alternatives/ex.it.1.gz new file mode 120000 index 00000000..4498a3d4 --- /dev/null +++ b/alternatives/ex.it.1.gz @@ -0,0 +1 @@ +/usr/share/man/it/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ex.ja.1.gz b/alternatives/ex.ja.1.gz new file mode 120000 index 00000000..071acfbb --- /dev/null +++ b/alternatives/ex.ja.1.gz @@ -0,0 +1 @@ +/usr/share/man/ja/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ex.pl.1.gz b/alternatives/ex.pl.1.gz new file mode 120000 index 00000000..345590a8 --- /dev/null +++ b/alternatives/ex.pl.1.gz @@ -0,0 +1 @@ +/usr/share/man/pl/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ex.ru.1.gz b/alternatives/ex.ru.1.gz new file mode 120000 index 00000000..ea9aa167 --- /dev/null +++ b/alternatives/ex.ru.1.gz @@ -0,0 +1 @@ +/usr/share/man/ru/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/ip6tables b/alternatives/ip6tables new file mode 120000 index 00000000..4c913e2d --- /dev/null +++ b/alternatives/ip6tables @@ -0,0 +1 @@ +/usr/sbin/ip6tables-nft \ No newline at end of file diff --git a/alternatives/ip6tables-restore b/alternatives/ip6tables-restore new file mode 120000 index 00000000..46918a9c --- /dev/null +++ b/alternatives/ip6tables-restore @@ -0,0 +1 @@ +/usr/sbin/ip6tables-nft-restore \ No newline at end of file diff --git a/alternatives/ip6tables-save b/alternatives/ip6tables-save new file mode 120000 index 00000000..04525f05 --- /dev/null +++ b/alternatives/ip6tables-save @@ -0,0 +1 @@ +/usr/sbin/ip6tables-nft-save \ No newline at end of file diff --git a/alternatives/iptables b/alternatives/iptables new file mode 120000 index 00000000..c55fd508 --- /dev/null +++ b/alternatives/iptables @@ -0,0 +1 @@ +/usr/sbin/iptables-nft \ No newline at end of file diff --git a/alternatives/iptables-restore b/alternatives/iptables-restore new file mode 120000 index 00000000..9553657e --- /dev/null +++ b/alternatives/iptables-restore @@ -0,0 +1 @@ +/usr/sbin/iptables-nft-restore \ No newline at end of file diff --git a/alternatives/iptables-save b/alternatives/iptables-save new file mode 120000 index 00000000..051d68bd --- /dev/null +++ b/alternatives/iptables-save @@ -0,0 +1 @@ +/usr/sbin/iptables-nft-save \ No newline at end of file diff --git a/alternatives/jsondiff b/alternatives/jsondiff new file mode 120000 index 00000000..0ecae1af --- /dev/null +++ b/alternatives/jsondiff @@ -0,0 +1 @@ +/usr/bin/json-patch-jsondiff \ No newline at end of file diff --git a/alternatives/jsonpatch b/alternatives/jsonpatch new file mode 120000 index 00000000..eeba9366 --- /dev/null +++ b/alternatives/jsonpatch @@ -0,0 +1 @@ +/usr/bin/python3-jsonpatch \ No newline at end of file diff --git a/alternatives/jsonpointer b/alternatives/jsonpointer new file mode 120000 index 00000000..3697e907 --- /dev/null +++ b/alternatives/jsonpointer @@ -0,0 +1 @@ +/usr/bin/python3-jsonpointer \ No newline at end of file diff --git a/alternatives/jsonschema b/alternatives/jsonschema new file mode 120000 index 00000000..959b7e5b --- /dev/null +++ b/alternatives/jsonschema @@ -0,0 +1 @@ +/usr/bin/python3-jsonschema \ No newline at end of file diff --git a/alternatives/lft b/alternatives/lft new file mode 120000 index 00000000..cbc60061 --- /dev/null +++ b/alternatives/lft @@ -0,0 +1 @@ +/usr/bin/lft.db \ No newline at end of file diff --git a/alternatives/lft.1.gz b/alternatives/lft.1.gz new file mode 120000 index 00000000..c1cf08c3 --- /dev/null +++ b/alternatives/lft.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/lft.db.1.gz \ No newline at end of file diff --git a/alternatives/lzcat b/alternatives/lzcat new file mode 120000 index 00000000..1482e0d3 --- /dev/null +++ b/alternatives/lzcat @@ -0,0 +1 @@ +/usr/bin/xzcat \ No newline at end of file diff --git a/alternatives/lzcat.1.gz b/alternatives/lzcat.1.gz new file mode 120000 index 00000000..c0785451 --- /dev/null +++ b/alternatives/lzcat.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzcat.1.gz \ No newline at end of file diff --git a/alternatives/lzcmp b/alternatives/lzcmp new file mode 120000 index 00000000..5cdef995 --- /dev/null +++ b/alternatives/lzcmp @@ -0,0 +1 @@ +/usr/bin/xzcmp \ No newline at end of file diff --git a/alternatives/lzcmp.1.gz b/alternatives/lzcmp.1.gz new file mode 120000 index 00000000..f0bafbe6 --- /dev/null +++ b/alternatives/lzcmp.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzcmp.1.gz \ No newline at end of file diff --git a/alternatives/lzdiff b/alternatives/lzdiff new file mode 120000 index 00000000..0e429214 --- /dev/null +++ b/alternatives/lzdiff @@ -0,0 +1 @@ +/usr/bin/xzdiff \ No newline at end of file diff --git a/alternatives/lzdiff.1.gz b/alternatives/lzdiff.1.gz new file mode 120000 index 00000000..5687b0a0 --- /dev/null +++ b/alternatives/lzdiff.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzdiff.1.gz \ No newline at end of file diff --git a/alternatives/lzegrep b/alternatives/lzegrep new file mode 120000 index 00000000..5fee0249 --- /dev/null +++ b/alternatives/lzegrep @@ -0,0 +1 @@ +/usr/bin/xzegrep \ No newline at end of file diff --git a/alternatives/lzegrep.1.gz b/alternatives/lzegrep.1.gz new file mode 120000 index 00000000..c9ad6de9 --- /dev/null +++ b/alternatives/lzegrep.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzegrep.1.gz \ No newline at end of file diff --git a/alternatives/lzfgrep b/alternatives/lzfgrep new file mode 120000 index 00000000..1b64c1bc --- /dev/null +++ b/alternatives/lzfgrep @@ -0,0 +1 @@ +/usr/bin/xzfgrep \ No newline at end of file diff --git a/alternatives/lzfgrep.1.gz b/alternatives/lzfgrep.1.gz new file mode 120000 index 00000000..b292ba91 --- /dev/null +++ b/alternatives/lzfgrep.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzfgrep.1.gz \ No newline at end of file diff --git a/alternatives/lzgrep b/alternatives/lzgrep new file mode 120000 index 00000000..05ef59bb --- /dev/null +++ b/alternatives/lzgrep @@ -0,0 +1 @@ +/usr/bin/xzgrep \ No newline at end of file diff --git a/alternatives/lzgrep.1.gz b/alternatives/lzgrep.1.gz new file mode 120000 index 00000000..8ccd2c57 --- /dev/null +++ b/alternatives/lzgrep.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzgrep.1.gz \ No newline at end of file diff --git a/alternatives/lzless b/alternatives/lzless new file mode 120000 index 00000000..54157364 --- /dev/null +++ b/alternatives/lzless @@ -0,0 +1 @@ +/usr/bin/xzless \ No newline at end of file diff --git a/alternatives/lzless.1.gz b/alternatives/lzless.1.gz new file mode 120000 index 00000000..bc81750d --- /dev/null +++ b/alternatives/lzless.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzless.1.gz \ No newline at end of file diff --git a/alternatives/lzma b/alternatives/lzma new file mode 120000 index 00000000..cdc9bb5f --- /dev/null +++ b/alternatives/lzma @@ -0,0 +1 @@ +/usr/bin/xz \ No newline at end of file diff --git a/alternatives/lzma.1.gz b/alternatives/lzma.1.gz new file mode 120000 index 00000000..16e4bccf --- /dev/null +++ b/alternatives/lzma.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xz.1.gz \ No newline at end of file diff --git a/alternatives/lzmore b/alternatives/lzmore new file mode 120000 index 00000000..1fad3616 --- /dev/null +++ b/alternatives/lzmore @@ -0,0 +1 @@ +/usr/bin/xzmore \ No newline at end of file diff --git a/alternatives/lzmore.1.gz b/alternatives/lzmore.1.gz new file mode 120000 index 00000000..e79dfa46 --- /dev/null +++ b/alternatives/lzmore.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/xzmore.1.gz \ No newline at end of file diff --git a/alternatives/mt b/alternatives/mt new file mode 120000 index 00000000..46c25966 --- /dev/null +++ b/alternatives/mt @@ -0,0 +1 @@ +/bin/mt-gnu \ No newline at end of file diff --git a/alternatives/mt.1.gz b/alternatives/mt.1.gz new file mode 120000 index 00000000..cac0e182 --- /dev/null +++ b/alternatives/mt.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/mt-gnu.1.gz \ No newline at end of file diff --git a/alternatives/my.cnf b/alternatives/my.cnf new file mode 120000 index 00000000..c0fe3dd7 --- /dev/null +++ b/alternatives/my.cnf @@ -0,0 +1 @@ +/etc/mysql/mariadb.cnf \ No newline at end of file diff --git a/alternatives/nawk b/alternatives/nawk new file mode 120000 index 00000000..19ba657e --- /dev/null +++ b/alternatives/nawk @@ -0,0 +1 @@ +/usr/bin/gawk \ No newline at end of file diff --git a/alternatives/nawk.1.gz b/alternatives/nawk.1.gz new file mode 120000 index 00000000..134262bc --- /dev/null +++ b/alternatives/nawk.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/gawk.1.gz \ No newline at end of file diff --git a/alternatives/nc b/alternatives/nc new file mode 120000 index 00000000..242a4185 --- /dev/null +++ b/alternatives/nc @@ -0,0 +1 @@ +/bin/nc.traditional \ No newline at end of file diff --git a/alternatives/nc.1.gz b/alternatives/nc.1.gz new file mode 120000 index 00000000..c8fdfa9a --- /dev/null +++ b/alternatives/nc.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/nc.traditional.1.gz \ No newline at end of file diff --git a/alternatives/netcat b/alternatives/netcat new file mode 120000 index 00000000..242a4185 --- /dev/null +++ b/alternatives/netcat @@ -0,0 +1 @@ +/bin/nc.traditional \ No newline at end of file diff --git a/alternatives/netcat.1.gz b/alternatives/netcat.1.gz new file mode 120000 index 00000000..c8fdfa9a --- /dev/null +++ b/alternatives/netcat.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/nc.traditional.1.gz \ No newline at end of file diff --git a/alternatives/open b/alternatives/open new file mode 120000 index 00000000..2fcedcf8 --- /dev/null +++ b/alternatives/open @@ -0,0 +1 @@ +/usr/bin/run-mailcap \ No newline at end of file diff --git a/alternatives/open.1.gz b/alternatives/open.1.gz new file mode 120000 index 00000000..b80da438 --- /dev/null +++ b/alternatives/open.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/run-mailcap.1.gz \ No newline at end of file diff --git a/alternatives/pager b/alternatives/pager new file mode 120000 index 00000000..a967155b --- /dev/null +++ b/alternatives/pager @@ -0,0 +1 @@ +/usr/bin/less \ No newline at end of file diff --git a/alternatives/pager.1.gz b/alternatives/pager.1.gz new file mode 120000 index 00000000..c1430af1 --- /dev/null +++ b/alternatives/pager.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/less.1.gz \ No newline at end of file diff --git a/alternatives/pico b/alternatives/pico new file mode 120000 index 00000000..7a06612b --- /dev/null +++ b/alternatives/pico @@ -0,0 +1 @@ +/bin/nano \ No newline at end of file diff --git a/alternatives/pico.1.gz b/alternatives/pico.1.gz new file mode 120000 index 00000000..bb2d082c --- /dev/null +++ b/alternatives/pico.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/nano.1.gz \ No newline at end of file diff --git a/alternatives/pinentry b/alternatives/pinentry new file mode 120000 index 00000000..01990a3f --- /dev/null +++ b/alternatives/pinentry @@ -0,0 +1 @@ +/usr/bin/pinentry-curses \ No newline at end of file diff --git a/alternatives/pinentry.1.gz b/alternatives/pinentry.1.gz new file mode 120000 index 00000000..8e9ab4f2 --- /dev/null +++ b/alternatives/pinentry.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/pinentry-curses.1.gz \ No newline at end of file diff --git a/alternatives/rcp b/alternatives/rcp new file mode 120000 index 00000000..594df9eb --- /dev/null +++ b/alternatives/rcp @@ -0,0 +1 @@ +/usr/bin/scp \ No newline at end of file diff --git a/alternatives/rcp.1.gz b/alternatives/rcp.1.gz new file mode 120000 index 00000000..63bfff3f --- /dev/null +++ b/alternatives/rcp.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/scp.1.gz \ No newline at end of file diff --git a/alternatives/rlogin b/alternatives/rlogin new file mode 120000 index 00000000..8db89a86 --- /dev/null +++ b/alternatives/rlogin @@ -0,0 +1 @@ +/usr/bin/slogin \ No newline at end of file diff --git a/alternatives/rlogin.1.gz b/alternatives/rlogin.1.gz new file mode 120000 index 00000000..be0c6db9 --- /dev/null +++ b/alternatives/rlogin.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/slogin.1.gz \ No newline at end of file diff --git a/alternatives/rmt b/alternatives/rmt new file mode 120000 index 00000000..82958a9a --- /dev/null +++ b/alternatives/rmt @@ -0,0 +1 @@ +/usr/sbin/rmt-tar \ No newline at end of file diff --git a/alternatives/rmt.8.gz b/alternatives/rmt.8.gz new file mode 120000 index 00000000..8c87e219 --- /dev/null +++ b/alternatives/rmt.8.gz @@ -0,0 +1 @@ +/usr/share/man/man8/rmt-tar.8.gz \ No newline at end of file diff --git a/alternatives/rsh b/alternatives/rsh new file mode 120000 index 00000000..50a1cff7 --- /dev/null +++ b/alternatives/rsh @@ -0,0 +1 @@ +/usr/bin/ssh \ No newline at end of file diff --git a/alternatives/rsh.1.gz b/alternatives/rsh.1.gz new file mode 120000 index 00000000..b3b36c07 --- /dev/null +++ b/alternatives/rsh.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/ssh.1.gz \ No newline at end of file diff --git a/alternatives/rview b/alternatives/rview new file mode 120000 index 00000000..0d516727 --- /dev/null +++ b/alternatives/rview @@ -0,0 +1 @@ +/usr/bin/vim.tiny \ No newline at end of file diff --git a/alternatives/tcptraceroute b/alternatives/tcptraceroute new file mode 120000 index 00000000..c828cd9e --- /dev/null +++ b/alternatives/tcptraceroute @@ -0,0 +1 @@ +/usr/sbin/tcptraceroute.db \ No newline at end of file diff --git a/alternatives/tcptraceroute.8.gz b/alternatives/tcptraceroute.8.gz new file mode 120000 index 00000000..815a50c2 --- /dev/null +++ b/alternatives/tcptraceroute.8.gz @@ -0,0 +1 @@ +/usr/share/man/man8/tcptraceroute.db.8.gz \ No newline at end of file diff --git a/alternatives/telnet b/alternatives/telnet new file mode 120000 index 00000000..9276cede --- /dev/null +++ b/alternatives/telnet @@ -0,0 +1 @@ +/usr/bin/telnet.netkit \ No newline at end of file diff --git a/alternatives/telnet.1.gz b/alternatives/telnet.1.gz new file mode 120000 index 00000000..9cd371e7 --- /dev/null +++ b/alternatives/telnet.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/telnet.netkit.1.gz \ No newline at end of file diff --git a/alternatives/traceproto b/alternatives/traceproto new file mode 120000 index 00000000..d6973c9c --- /dev/null +++ b/alternatives/traceproto @@ -0,0 +1 @@ +/usr/bin/traceproto.db \ No newline at end of file diff --git a/alternatives/traceproto.1.gz b/alternatives/traceproto.1.gz new file mode 120000 index 00000000..3353595c --- /dev/null +++ b/alternatives/traceproto.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/traceproto.db.1.gz \ No newline at end of file diff --git a/alternatives/traceroute b/alternatives/traceroute new file mode 120000 index 00000000..fd696326 --- /dev/null +++ b/alternatives/traceroute @@ -0,0 +1 @@ +/usr/bin/traceroute.db \ No newline at end of file diff --git a/alternatives/traceroute.1.gz b/alternatives/traceroute.1.gz new file mode 120000 index 00000000..e9586f92 --- /dev/null +++ b/alternatives/traceroute.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/traceroute.db.1.gz \ No newline at end of file diff --git a/alternatives/traceroute.sbin b/alternatives/traceroute.sbin new file mode 120000 index 00000000..fd696326 --- /dev/null +++ b/alternatives/traceroute.sbin @@ -0,0 +1 @@ +/usr/bin/traceroute.db \ No newline at end of file diff --git a/alternatives/traceroute6 b/alternatives/traceroute6 new file mode 120000 index 00000000..7958fcf4 --- /dev/null +++ b/alternatives/traceroute6 @@ -0,0 +1 @@ +/usr/bin/traceroute6.db \ No newline at end of file diff --git a/alternatives/traceroute6.1.gz b/alternatives/traceroute6.1.gz new file mode 120000 index 00000000..7977291e --- /dev/null +++ b/alternatives/traceroute6.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/traceroute6.db.1.gz \ No newline at end of file diff --git a/alternatives/unlzma b/alternatives/unlzma new file mode 120000 index 00000000..c730a4a2 --- /dev/null +++ b/alternatives/unlzma @@ -0,0 +1 @@ +/usr/bin/unxz \ No newline at end of file diff --git a/alternatives/unlzma.1.gz b/alternatives/unlzma.1.gz new file mode 120000 index 00000000..c772f41c --- /dev/null +++ b/alternatives/unlzma.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/unxz.1.gz \ No newline at end of file diff --git a/alternatives/vi b/alternatives/vi new file mode 120000 index 00000000..0d516727 --- /dev/null +++ b/alternatives/vi @@ -0,0 +1 @@ +/usr/bin/vim.tiny \ No newline at end of file diff --git a/alternatives/vi.1.gz b/alternatives/vi.1.gz new file mode 120000 index 00000000..e02a6af1 --- /dev/null +++ b/alternatives/vi.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/vi.da.1.gz b/alternatives/vi.da.1.gz new file mode 120000 index 00000000..c90068fa --- /dev/null +++ b/alternatives/vi.da.1.gz @@ -0,0 +1 @@ +/usr/share/man/da/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/vi.de.1.gz b/alternatives/vi.de.1.gz new file mode 120000 index 00000000..d89833a7 --- /dev/null +++ b/alternatives/vi.de.1.gz @@ -0,0 +1 @@ +/usr/share/man/de/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/vi.fr.1.gz b/alternatives/vi.fr.1.gz new file mode 120000 index 00000000..af52858f --- /dev/null +++ b/alternatives/vi.fr.1.gz @@ -0,0 +1 @@ +/usr/share/man/fr/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/vi.it.1.gz b/alternatives/vi.it.1.gz new file mode 120000 index 00000000..4498a3d4 --- /dev/null +++ b/alternatives/vi.it.1.gz @@ -0,0 +1 @@ +/usr/share/man/it/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/vi.ja.1.gz b/alternatives/vi.ja.1.gz new file mode 120000 index 00000000..071acfbb --- /dev/null +++ b/alternatives/vi.ja.1.gz @@ -0,0 +1 @@ +/usr/share/man/ja/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/vi.pl.1.gz b/alternatives/vi.pl.1.gz new file mode 120000 index 00000000..345590a8 --- /dev/null +++ b/alternatives/vi.pl.1.gz @@ -0,0 +1 @@ +/usr/share/man/pl/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/vi.ru.1.gz b/alternatives/vi.ru.1.gz new file mode 120000 index 00000000..ea9aa167 --- /dev/null +++ b/alternatives/vi.ru.1.gz @@ -0,0 +1 @@ +/usr/share/man/ru/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view b/alternatives/view new file mode 120000 index 00000000..0d516727 --- /dev/null +++ b/alternatives/view @@ -0,0 +1 @@ +/usr/bin/vim.tiny \ No newline at end of file diff --git a/alternatives/view.1.gz b/alternatives/view.1.gz new file mode 120000 index 00000000..e02a6af1 --- /dev/null +++ b/alternatives/view.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view.da.1.gz b/alternatives/view.da.1.gz new file mode 120000 index 00000000..c90068fa --- /dev/null +++ b/alternatives/view.da.1.gz @@ -0,0 +1 @@ +/usr/share/man/da/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view.de.1.gz b/alternatives/view.de.1.gz new file mode 120000 index 00000000..d89833a7 --- /dev/null +++ b/alternatives/view.de.1.gz @@ -0,0 +1 @@ +/usr/share/man/de/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view.fr.1.gz b/alternatives/view.fr.1.gz new file mode 120000 index 00000000..af52858f --- /dev/null +++ b/alternatives/view.fr.1.gz @@ -0,0 +1 @@ +/usr/share/man/fr/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view.it.1.gz b/alternatives/view.it.1.gz new file mode 120000 index 00000000..4498a3d4 --- /dev/null +++ b/alternatives/view.it.1.gz @@ -0,0 +1 @@ +/usr/share/man/it/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view.ja.1.gz b/alternatives/view.ja.1.gz new file mode 120000 index 00000000..071acfbb --- /dev/null +++ b/alternatives/view.ja.1.gz @@ -0,0 +1 @@ +/usr/share/man/ja/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view.pl.1.gz b/alternatives/view.pl.1.gz new file mode 120000 index 00000000..345590a8 --- /dev/null +++ b/alternatives/view.pl.1.gz @@ -0,0 +1 @@ +/usr/share/man/pl/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/view.ru.1.gz b/alternatives/view.ru.1.gz new file mode 120000 index 00000000..ea9aa167 --- /dev/null +++ b/alternatives/view.ru.1.gz @@ -0,0 +1 @@ +/usr/share/man/ru/man1/vim.1.gz \ No newline at end of file diff --git a/alternatives/write b/alternatives/write new file mode 120000 index 00000000..84860897 --- /dev/null +++ b/alternatives/write @@ -0,0 +1 @@ +/usr/bin/write.ul \ No newline at end of file diff --git a/alternatives/write.1.gz b/alternatives/write.1.gz new file mode 120000 index 00000000..170e75f2 --- /dev/null +++ b/alternatives/write.1.gz @@ -0,0 +1 @@ +/usr/share/man/man1/write.ul.1.gz \ No newline at end of file diff --git a/amavis/README.l10n b/amavis/README.l10n new file mode 100644 index 00000000..0b8c1a3b --- /dev/null +++ b/amavis/README.l10n @@ -0,0 +1,21 @@ +$Id: README.l10n 742 2005-12-26 17:15:22Z hmh $ + +First of all, read /usr/share/doc/amavisd-new/README.customize.gz + +Amavisd-new is UTF8-aware, and it will do character-set conversion when dealing +with DSN templates. The full unicode codespace is available, if used with the +proper encodings... and you have to use the proper encodings if you don't want +your DSNs to be flagged as more charset-challenged SPAM by other systems. + +ALWAYS respect the charset when adding l10n files. + +Amavisd-new does charset conversion twice: one when reading the text files with +localized templates (to internal perl UTF8), and another when writing the email +notification (from internal perl UTF8 to $hdr_encoding and $bdy_encoding). + +Headers will be RFC2047-encoded if they have any codepoints not allowed by +RFC2822 after the charset conversions. The body text charset encoding is +inserted in the proper MIME header. + +More details are available in /usr/share/doc/amavisd-new/RELEASE_NOTES.gz + diff --git a/amavis/conf.d/01-debian b/amavis/conf.d/01-debian new file mode 100644 index 00000000..764d8d48 --- /dev/null +++ b/amavis/conf.d/01-debian @@ -0,0 +1,47 @@ +use strict; + +# ADMINISTRATORS: +# Debian suggests that any changes you need to do that should never +# be "updated" by the Debian package should be made in another file, +# overriding the settings in this file. +# +# The package will *not* overwrite your settings, but by keeping +# them separate, you will make the task of merging changes on these +# configuration files much simpler... + +# see /usr/share/doc/amavisd-new/examples/amavisd.conf-default for +# a list of all variables with their defaults; +# see /usr/share/doc/amavisd-new/examples/amavisd.conf-sample for +# a traditional-style commented file +# [note: the above files were not converted to Debian settings!] +# +# for more details see documentation in /usr/share/doc/amavisd-new +# and at http://www.ijs.si/software/amavisd/amavisd-new-docs.html + + +# SETTINGS RARELY MODIFIED BY THE LOCAL ADMIN + +$ENV{PATH} = $path = '/usr/local/sbin:/usr/local/bin:/usr/sbin:/sbin:/usr/bin:/bin'; +$file = 'file'; +$gzip = 'gzip'; +$bzip2 = 'bzip2'; +$lzop = 'lzop'; +$rpm2cpio = ['rpm2cpio.pl','rpm2cpio']; +$cabextract = 'cabextract'; +$uncompress = ['uncompress', 'gzip -d', 'zcat']; +#$unfreeze = ['unfreeze', 'freeze -d', 'melt', 'fcat']; #disabled (non-free, no security support) +$unfreeze = undef; +$arc = ['nomarch', 'arc']; +$unarj = ['arj', 'unarj']; +#$unrar = ['rar', 'unrar']; #disabled (non-free, no security support) +$unrar = ['unrar-free']; +$zoo = 'zoo'; +$lha = 'lha'; +$lha = undef; +$pax = 'pax'; +$cpio = 'cpio'; +$ar = 'ar'; +$ripole = 'ripole'; +$dspam = 'dspam'; + +1; # ensure a defined return diff --git a/amavis/conf.d/05-domain_id b/amavis/conf.d/05-domain_id new file mode 100644 index 00000000..e1174c00 --- /dev/null +++ b/amavis/conf.d/05-domain_id @@ -0,0 +1,19 @@ +use strict; + +# $mydomain is used just for convenience in the config files and it is not +# used internally by amavisd-new except in the default X_HEADER_LINE (which +# Debian overrides by default anyway). + +chomp($mydomain = `head -n 1 /etc/mailname`); + +# amavisd-new needs to know which email domains are to be considered local +# to the administrative domain. Only emails to "local" domains are subject +# to certain functionality, such as the addition of spam tags. +# +# Default local domains to $mydomain and all subdomains. Remember to +# override or redefine this if $mydomain is changed later in the config +# sequence. + +@local_domains_acl = ( ".$mydomain" ); + +1; # ensure a defined return diff --git a/amavis/conf.d/05-node_id b/amavis/conf.d/05-node_id new file mode 100644 index 00000000..4d2d37d1 --- /dev/null +++ b/amavis/conf.d/05-node_id @@ -0,0 +1,13 @@ +use strict; + +# $myhostname is used by amavisd-new for node identification, and it is +# important to get it right (e.g. for ESMTP EHLO, loop detection, and so on). + +chomp($myhostname = `hostname --fqdn`); + +# To manually set $myhostname, edit the following line with the correct Fully +# Qualified Domain Name (FQDN) and remove the # at the beginning of the line. +# +#$myhostname = "mail.example.com"; + +1; # ensure a defined return diff --git a/amavis/conf.d/15-av_scanners b/amavis/conf.d/15-av_scanners new file mode 100644 index 00000000..59ac2f3d --- /dev/null +++ b/amavis/conf.d/15-av_scanners @@ -0,0 +1,473 @@ +use strict; + +## +## AV Scanners (Debian version) +## + +@av_scanners = ( + +# ### http://www.clanfield.info/sophie/ (http://www.vanja.com/tools/sophie/) +# ['Sophie', +# \&ask_daemon, ["{}/\n", '/var/run/sophie'], +# qr/(?x)^ 0+ ( : | [\000\r\n]* $)/m, qr/(?x)^ 1 ( : | [\000\r\n]* $)/m, +# qr/(?x)^ [-+]? \d+ : (.*?) [\000\r\n]* $/m ], + +# ### http://www.csupomona.edu/~henson/www/projects/SAVI-Perl/ +# ['Sophos SAVI', \&sophos_savi ], + +### http://www.clamav.net/ + ['ClamAV-clamd', + \&ask_daemon, ["CONTSCAN {}\n", "/var/run/clamav/clamd.ctl"], + qr/\bOK$/m, qr/\bFOUND$/m, + qr/^.*?: (?!Infected Archive)(.*) FOUND$/m ], +# NOTE: run clamd under the same user as amavisd, or run it under its own +# uid such as clamav, add user clamav to the amavis group, and then add +# AllowSupplementaryGroups to clamd.conf; +# NOTE: match socket name (LocalSocket) in clamav.conf to the socket name in +# this entry; when running chrooted one may prefer socket "$MYHOME/clamd". + +# ### http://www.openantivirus.org/ +# ['OpenAntiVirus ScannerDaemon (OAV)', +# \&ask_daemon, ["SCAN {}\n", '127.0.0.1:8127'], +# qr/^OK/m, qr/^FOUND: /m, qr/^FOUND: (.+)/m ], + +# ### http://www.vanja.com/tools/trophie/ +# ['Trophie', +# \&ask_daemon, ["{}/\n", '/var/run/trophie'], +# qr/(?x)^ 0+ ( : | [\000\r\n]* $)/m, qr/(?x)^ 1 ( : | [\000\r\n]* $)/m, +# qr/(?x)^ [-+]? \d+ : (.*?) [\000\r\n]* $/m ], + +# ### http://www.grisoft.com/ +# ['AVG Anti-Virus', +# \&ask_daemon, ["SCAN {}\n", '127.0.0.1:55555'], +# qr/^200/m, qr/^403/m, qr/^403 .*?: ([^\r\n]+)/m ], + +# ### http://www.f-prot.com/ +# ['F-Prot fpscand', # F-PROT Antivirus for BSD/Linux/Solaris, version 6 +# \&ask_daemon, +# ["SCAN FILE {}/*\n", '127.0.0.1:10200'], +# qr/^(0|8|64) /m, +# qr/^([1235679]|1[01345]) |<[^>:]*(?i)(infected|suspicious|unwanted)/m, +# qr/(?i)<[^>:]*(?:infected|suspicious|unwanted)[^>:]*: ([^>]*)>/m ], + +# ### http://www.f-prot.com/ +# ['F-Prot f-protd', # old version +# \&ask_daemon, +# ["GET {}/*?-dumb%20-archive%20-packed HTTP/1.0\r\n\r\n", +# ['127.0.0.1:10200', '127.0.0.1:10201', '127.0.0.1:10202', +# '127.0.0.1:10203', '127.0.0.1:10204'] ], +# qr/(?i)]*>clean<\/summary>/m, +# qr/(?i)]*>infected<\/summary>/m, +# qr/(?i)(.+)<\/name>/m ], + +# ### http://www.sald.com/, http://www.dials.ru/english/, http://www.drweb.ru/ +# ['DrWebD', \&ask_daemon, # DrWebD 4.31 or later +# [pack('N',1). # DRWEBD_SCAN_CMD +# pack('N',0x00280001). # DONT_CHANGEMAIL, IS_MAIL, RETURN_VIRUSES +# pack('N', # path length +# length("$TEMPBASE/amavis-yyyymmddTHHMMSS-xxxxx/parts/pxxx")). +# '{}/*'. # path +# pack('N',0). # content size +# pack('N',0), +# '/var/drweb/run/drwebd.sock', +# # '/var/amavis/var/run/drwebd.sock', # suitable for chroot +# # '/usr/local/drweb/run/drwebd.sock', # FreeBSD drweb ports default +# # '127.0.0.1:3000', # or over an inet socket +# ], +# qr/\A\x00[\x10\x11][\x00\x10]\x00/sm, # IS_CLEAN,EVAL_KEY; SKIPPED +# qr/\A\x00[\x00\x01][\x00\x10][\x20\x40\x80]/sm,# KNOWN_V,UNKNOWN_V,V._MODIF +# qr/\A.{12}(?:infected with )?([^\x00]+)\x00/sm, +# ], +# # NOTE: If using amavis-milter, change length to: +# # length("$TEMPBASE/amavis-milter-xxxxxxxxxxxxxx/parts/pxxx"). + + ### http://www.kaspersky.com/ (kav4mailservers) + ['KasperskyLab AVP - aveclient', + ['/usr/local/kav/bin/aveclient','/usr/local/share/kav/bin/aveclient', + '/opt/kav/5.5/kav4mailservers/bin/aveclient','aveclient'], + '-p /var/run/aveserver -s {}/*', + [0,3,6,8], qr/\b(INFECTED|SUSPICION|SUSPICIOUS)\b/m, + qr/(?:INFECTED|WARNING|SUSPICION|SUSPICIOUS) (.+)/m, + ], + # NOTE: one may prefer [0],[2,3,4,5], depending on how suspicious, + # currupted or protected archives are to be handled + + ### http://www.kaspersky.com/ + ['KasperskyLab AntiViral Toolkit Pro (AVP)', ['avp'], + '-* -P -B -Y -O- {}', [0,3,6,8], [2,4], # any use for -A -K ? + qr/infected: (.+)/m, + sub {chdir('/opt/AVP') or die "Can't chdir to AVP: $!"}, + sub {chdir($TEMPBASE) or die "Can't chdir back to $TEMPBASE $!"}, + ], + + ### The kavdaemon and AVPDaemonClient have been removed from Kasperky + ### products and replaced by aveserver and aveclient + ['KasperskyLab AVPDaemonClient', + [ '/opt/AVP/kavdaemon', 'kavdaemon', + '/opt/AVP/AvpDaemonClient', 'AvpDaemonClient', + '/opt/AVP/AvpTeamDream', 'AvpTeamDream', + '/opt/AVP/avpdc', 'avpdc' ], + "-f=$TEMPBASE {}", [0,8], [3,4,5,6], qr/infected: ([^\r\n]+)/m ], + # change the startup-script in /etc/init.d/kavd to: + # DPARMS="-* -Y -dl -f=/var/amavis /var/amavis" + # (or perhaps: DPARMS="-I0 -Y -* /var/amavis" ) + # adjusting /var/amavis above to match your $TEMPBASE. + # The '-f=/var/amavis' is needed if not running it as root, so it + # can find, read, and write its pid file, etc., see 'man kavdaemon'. + # defUnix.prf: there must be an entry "*/var/amavis" (or whatever + # directory $TEMPBASE specifies) in the 'Names=' section. + # cd /opt/AVP/DaemonClients; configure; cd Sample; make + # cp AvpDaemonClient /opt/AVP/ + # su - vscan -c "${PREFIX}/kavdaemon ${DPARMS}" + + ### http://www.centralcommand.com/ + ['CentralCommand Vexira (new) vascan', + ['vascan','/usr/lib/Vexira/vascan'], + "-a s --timeout=60 --temp=$TEMPBASE -y $QUARANTINEDIR ". + "--log=/var/log/vascan.log {}", + [0,3], [1,2,5], + qr/(?x)^\s* (?:virus|iworm|macro|mutant|sequence|trojan)\ found:\ ( [^\]\s']+ )\ \.\.\.\ /m ], + # Adjust the path of the binary and the virus database as needed. + # 'vascan' does not allow to have the temp directory to be the same as + # the quarantine directory, and the quarantine option can not be disabled. + # If $QUARANTINEDIR is not used, then another directory must be specified + # to appease 'vascan'. Move status 3 to the second list if password + # protected files are to be considered infected. + + ### http://www.avira.com/ + ### Avira AntiVir (formerly H+BEDV) or (old) CentralCommand Vexira Antivirus + ['Avira AntiVir', ['antivir','vexira'], + '--allfiles -noboot -nombr -rs -s -z {}', [0], qr/ALERT:|VIRUS:/m, + qr/(?x)^\s* (?: ALERT: \s* (?: \[ | [^']* ' ) | + (?i) VIRUS:\ .*?\ virus\ '?) ( [^\]\s']+ )/m ], + # NOTE: if you only have a demo version, remove -z and add 214, as in: + # '--allfiles -noboot -nombr -rs -s {}', [0,214], qr/ALERT:|VIRUS:/, + + ### http://www.commandsoftware.com/ + ['Command AntiVirus for Linux', 'csav', + '-all -archive -packed {}', [50], [51,52,53], + qr/Infection: (.+)/m ], + + ### http://www.symantec.com/ + ['Symantec CarrierScan via Symantec CommandLineScanner', + 'cscmdline', '-a scan -i 1 -v -s 127.0.0.1:7777 {}', + qr/^Files Infected:\s+0$/m, qr/^Infected\b/m, + qr/^(?:Info|Virus Name):\s+(.+)/m ], + + ### http://www.symantec.com/ + ['Symantec AntiVirus Scan Engine', + 'savsecls', '-server 127.0.0.1:7777 -mode scanrepair -details -verbose {}', + [0], qr/^Infected\b/m, + qr/^(?:Info|Virus Name):\s+(.+)/m ], + # NOTE: check options and patterns to see which entry better applies + +# ### http://www.f-secure.com/products/anti-virus/ version 4.65 +# ['F-Secure Antivirus for Linux servers', +# ['/opt/f-secure/fsav/bin/fsav', 'fsav'], +# '--delete=no --disinf=no --rename=no --archive=yes --auto=yes '. +# '--dumb=yes --list=no --mime=yes {}', [0], [3,6,8], +# qr/(?:infection|Infected|Suspected): (.+)/m ], + + ### http://www.f-secure.com/products/anti-virus/ version 5.52 + ['F-Secure Antivirus for Linux servers', + ['/opt/f-secure/fsav/bin/fsav', 'fsav'], + '--virus-action1=report --archive=yes --auto=yes '. + '--dumb=yes --list=no --mime=yes {}', [0], [3,4,6,8], + qr/(?:infection|Infected|Suspected|Riskware): (.+)/m ], + # NOTE: internal archive handling may be switched off by '--archive=no' + # to prevent fsav from exiting with status 9 on broken archives + +# ### http://www.avast.com/ +# ['avast! Antivirus daemon', +# \&ask_daemon, # greets with 220, terminate with QUIT +# ["SCAN {}\015\012QUIT\015\012", '/var/run/avast4/mailscanner.sock'], +# qr/\t\[\+\]/m, qr/\t\[L\]\t/m, qr/\t\[L\]\t([^[ \t\015\012]+)/m ], + +# ### http://www.avast.com/ +# ['avast! Antivirus - Client/Server Version', 'avastlite', +# '-a /var/run/avast4/mailscanner.sock -n {}', [0], [1], +# qr/\t\[L\]\t([^[ \t\015\012]+)/m ], + + ['CAI InoculateIT', 'inocucmd', # retired product + '-sec -nex {}', [0], [100], + qr/was infected by virus (.+)/m ], + # see: http://www.flatmtn.com/computer/Linux-Antivirus_CAI.html + + ### http://www3.ca.com/Solutions/Product.asp?ID=156 (ex InoculateIT) + ['CAI eTrust Antivirus', 'etrust-wrapper', + '-arc -nex -spm h {}', [0], [101], + qr/is infected by virus: (.+)/m ], + # NOTE: requires suid wrapper around inocmd32; consider flag: -mod reviewer + # see http://marc.theaimsgroup.com/?l=amavis-user&m=109229779912783 + + ### http://mks.com.pl/english.html + ['MkS_Vir for Linux (beta)', ['mks32','mks'], + '-s {}/*', [0], [1,2], + qr/--[ \t]*(.+)/m ], + + ### http://mks.com.pl/english.html + ['MkS_Vir daemon', 'mksscan', + '-s -q {}', [0], [1..7], + qr/^... (\S+)/m ], + +# ### http://www.nod32.com/, version v2.52 (old) +# ['ESET NOD32 for Linux Mail servers', +# ['/opt/eset/nod32/bin/nod32cli', 'nod32cli'], +# '--subdir --files -z --sfx --rtp --adware --unsafe --pattern --heur '. +# '-w -a --action-on-infected=accept --action-on-uncleanable=accept '. +# '--action-on-notscanned=accept {}', +# [0,3], [1,2], qr/virus="([^"]+)"/m ], + +# ### http://www.eset.com/, version v2.7 (old) +# ['ESET NOD32 Linux Mail Server - command line interface', +# ['/usr/bin/nod32cli', '/opt/eset/nod32/bin/nod32cli', 'nod32cli'], +# '--subdir {}', [0,3], [1,2], qr/virus="([^"]+)"/m ], + +# ### http://www.eset.com/, version 2.71.12 +# ['ESET Software ESETS Command Line Interface', +# ['/usr/bin/esets_cli', 'esets_cli'], +# '--subdir {}', [0], [1,2,3], qr/virus="([^"]+)"/m ], + + ### http://www.eset.com/, version 3.0 + ['ESET Software ESETS Command Line Interface', + ['/usr/bin/esets_cli', 'esets_cli'], + '--subdir {}', [0], [2,3], + qr/:\s*action="(?!accepted)[^"]*"\n.*:\s*virus="([^"]*)"/m ], + + ## http://www.nod32.com/, NOD32LFS version 2.5 and above + ['ESET NOD32 for Linux File servers', + ['/opt/eset/nod32/sbin/nod32','nod32'], + '--files -z --mail --sfx --rtp --adware --unsafe --pattern --heur '. + '-w -a --action=1 -b {}', + [0], [1,10], qr/^object=.*, virus="(.*?)",/m ], + +# Experimental, based on posting from Rado Dibarbora (Dibo) on 2002-05-31 +# ['ESET Software NOD32 Client/Server (NOD32SS)', +# \&ask_daemon2, # greets with 200, persistent, terminate with QUIT +# ["SCAN {}/*\r\n", '127.0.0.1:8448' ], +# qr/^200 File OK/m, qr/^201 /m, qr/^201 (.+)/m ], + + ### http://www.norman.com/products_nvc.shtml + ['Norman Virus Control v5 / Linux', 'nvcc', + '-c -l:0 -s -u -temp:$TEMPBASE {}', [0,10,11], [1,2,14], + qr/(?i).* virus in .* -> \'(.+)\'/m ], + + ### http://www.pandasoftware.com/ + ['Panda CommandLineSecure 9 for Linux', + ['/opt/pavcl/usr/bin/pavcl','pavcl'], + '-auto -aex -heu -cmp -nbr -nor -nos -eng -nob {}', + qr/Number of files infected[ .]*: 0+(?!\d)/m, + qr/Number of files infected[ .]*: 0*[1-9]/m, + qr/Found virus :\s*(\S+)/m ], + # NOTE: for efficiency, start the Panda in resident mode with 'pavcl -tsr' + # before starting amavisd - the bases are then loaded only once at startup. + # To reload bases in a signature update script: + # /opt/pavcl/usr/bin/pavcl -tsr -ulr; /opt/pavcl/usr/bin/pavcl -tsr + # Please review other options of pavcl, for example: + # -nomalw, -nojoke, -nodial, -nohackt, -nospyw, -nocookies + +# ### http://www.pandasoftware.com/ +# ['Panda Antivirus for Linux', ['pavcl'], +# '-TSR -aut -aex -heu -cmp -nbr -nor -nso -eng {}', +# [0], [0x10, 0x30, 0x50, 0x70, 0x90, 0xB0, 0xD0, 0xF0], +# qr/Found virus :\s*(\S+)/m ], + +# GeCAD AV technology is acquired by Microsoft; RAV has been discontinued. +# Check your RAV license terms before fiddling with the following two lines! +# ['GeCAD RAV AntiVirus 8', 'ravav', +# '--all --archive --mail {}', [1], [2,3,4,5], qr/Infected: (.+)/m ], +# # NOTE: the command line switches changed with scan engine 8.5 ! +# # (btw, assigning stdin to /dev/null causes RAV to fail) + + ### http://www.nai.com/ + ['NAI McAfee AntiVirus (uvscan)', 'uvscan', + '--secure -rv --mime --summary --noboot - {}', [0], [13], + qr/(?x) Found (?: + \ the\ (.+)\ (?:virus|trojan) | + \ (?:virus|trojan)\ or\ variant\ ([^ ]+) | + :\ (.+)\ NOT\ a\ virus)/m, + # sub {$ENV{LD_PRELOAD}='/lib/libc.so.6'}, + # sub {delete $ENV{LD_PRELOAD}}, + ], + # NOTE1: with RH9: force the dynamic linker to look at /lib/libc.so.6 before + # anything else by setting environment variable LD_PRELOAD=/lib/libc.so.6 + # and then clear it when finished to avoid confusing anything else. + # NOTE2: to treat encrypted files as viruses replace the [13] with: + # qr/^\s{5,}(Found|is password-protected|.*(virus|trojan))/ + + ### http://www.virusbuster.hu/en/ + ['VirusBuster', ['vbuster', 'vbengcl'], + "{} -ss -i '*' -log=$MYHOME/vbuster.log", [0], [1], + qr/: '(.*)' - Virus/m ], + # VirusBuster Ltd. does not support the daemon version for the workstation + # engine (vbuster-eng-1.12-linux-i386-libc6.tgz) any longer. The names of + # binaries, some parameters AND return codes have changed (from 3 to 1). + # See also the new Vexira entry 'vascan' which is possibly related. + +# ### http://www.virusbuster.hu/en/ +# ['VirusBuster (Client + Daemon)', 'vbengd', +# '-f -log scandir {}', [0], [3], +# qr/Virus found = (.*);/m ], +# # HINT: for an infected file it always returns 3, +# # although the man-page tells a different story + + ### http://www.cyber.com/ + ['CyberSoft VFind', 'vfind', + '--vexit {}/*', [0], [23], qr/##==>>>> VIRUS ID: CVDL (.+)/m, + # sub {$ENV{VSTK_HOME}='/usr/lib/vstk'}, + ], + + ### http://www.avast.com/ + ['avast! Antivirus', ['/usr/bin/avastcmd','avastcmd'], + '-a -i -n -t=A {}', [0], [1], qr/\binfected by:\s+([^ \t\n\[\]]+)/m ], + + ### http://www.ikarus-software.com/ + ['Ikarus AntiVirus for Linux', 'ikarus', + '{}', [0], [40], qr/Signature (.+) found/m ], + + ### http://www.bitdefender.com/ + ['BitDefender', 'bdscan', # new version + '--action=ignore --no-list {}', qr/^Infected files *:0+(?!\d)/m, + qr/^(?:Infected files|Identified viruses|Suspect files) *:0*[1-9]/m, + qr/(?:suspected|infected): (.*)(?:\033|$)/m ], + + ### http://www.bitdefender.com/ + ['BitDefender', 'bdc', # old version + '--arc --mail {}', qr/^Infected files *:0+(?!\d)/m, + qr/^(?:Infected files|Identified viruses|Suspect files) *:0*[1-9]/m, + qr/(?:suspected|infected): (.*)(?:\033|$)/m ], + # consider also: --all --nowarn --alev=15 --flev=15. The --all argument may + # not apply to your version of bdc, check documentation and see 'bdc --help' + + ### ArcaVir for Linux and Unix http://www.arcabit.pl/ + ['ArcaVir for Linux', ['arcacmd','arcacmd.static'], + '-v 1 -summary 0 -s {}', [0], [1,2], + qr/(?:VIR|WIR):[ \t]*(.+)/m ], + +# ['File::Scan', sub {Amavis::AV::ask_av(sub{ +# use File::Scan; my($fn)=@_; +# my($f)=File::Scan->new(max_txt_size=>0, max_bin_size=>0); +# my($vname) = $f->scan($fn); +# $f->error ? (2,"Error: ".$f->error) +# : ($vname ne '') ? (1,"$vname FOUND") : (0,"Clean")}, @_) }, +# ["{}/*"], [0], [1], qr/^(.*) FOUND$/m ], + +# ### fully-fledged checker for JPEG marker segments of invalid length +# ['check-jpeg', +# sub { use JpegTester (); Amavis::AV::ask_av(\&JpegTester::test_jpeg, @_) }, +# ["{}/*"], undef, [1], qr/^(bad jpeg: .*)$/m ], +# # NOTE: place file JpegTester.pm somewhere where Perl can find it, +# # for example in /usr/local/lib/perl5/site_perl + +# ### example: simpleminded checker for JPEG marker segments with +# ### invalid length (only checks first 32k, which is not thorough enough) +# ['check-jpeg-simple', +# sub { Amavis::AV::ask_av(sub { +# my($f)=@_; local(*FF,$_,$1,$2); my(@r)=(0,'not jpeg'); +# open(FF,$f) or die "jpeg: open err $f: $!"; +# binmode(FF) or die "jpeg: binmode err $f: $!"; +# defined read(FF,$_,32000) or die "jpeg: read err $f: $!"; +# close(FF) or die "jpeg: close err $f: $!"; +# if (/^\xff\xd8\xff/) { +# @r=(0,'jpeg ok'); +# while (!/\G(?:\xff\xd9|\z)/gc) { # EOI or eof +# if (/\G\xff+(?=\xff|\z)/gc) {} # fill-bytes before marker +# elsif (/\G\xff([\x01\xd0-\xd8])/gc) {} # TEM, RSTi, SOI +# elsif (/\G\xff([^\x00\xff])(..)/gcs) { # marker segment start +# my($n)=unpack("n",$2)-2; +# $n=32766 if $n>32766; # Perl regexp limit +# if ($n<0) {@r=(1,"bad jpeg: len=$n, pos=".pos); last} +# elsif (/\G.{$n}/gcs) {} # ok +# elsif (/\G.{0,$n}\z/gcs) {last} # truncated +# else {@r=(1,"bad jpeg: unexpected, pos=".pos); last} +# } +# elsif (/\G[^\xff]+/gc) {} # ECS +# elsif (/\G(?:\xff\x00)+/gc) {} # ECS +# else {@r=(2,"bad jpeg: unexpected char, pos=".pos); last} +# } +# }; @r}, @_) }, +# ["{}/*"], undef, [1], qr/^(bad jpeg: .*)$/m ], + +# ### an example/testing/template virus scanner (external), wastes 3 seconds +# ['wasteful sleeper example', +# '/bin/sleep', '3', # calls external program +# undef, undef, qr/no such/m ], + +# ### an example/testing/template virus scanner (internal), does nothing +# ['null', +# sub {}, ["{}"], # supplies its own subroutine, no external program +# undef, undef, qr/no such/m ], + +); + + +# If no virus scanners from the @av_scanners list produce 'clean' nor +# 'infected' status (i.e. they all fail to run or the list is empty), +# then _all_ scanners from the @av_scanners_backup list are tried +# (again, subject to $first_infected_stops_scan). When there are both +# daemonized and equivalent or similar command-line scanners available, +# it is customary to place slower command-line scanners in the +# @av_scanners_backup list. The default choice is somewhat arbitrary, +# move entries from one list to another as desired, keeping main scanners +# in the primary list to avoid warnings. + +@av_scanners_backup = ( + + ### http://www.clamav.net/ - backs up clamd or Mail::ClamAV + ['ClamAV-clamscan', 'clamscan', + "--stdout --no-summary -r --tempdir=$TEMPBASE {}", + [0], qr/:.*\sFOUND$/m, qr/^.*?: (?!Infected Archive)(.*) FOUND$/m ], + + ### http://www.f-prot.com/ - backs up F-Prot Daemon, V6 + ['F-PROT Antivirus for UNIX', ['fpscan'], + '--report --mount --adware {}', # consider: --applications -s 4 -u 3 -z 10 + [0,8,64], [1,2,3, 4+1,4+2,4+3, 8+1,8+2,8+3, 12+1,12+2,12+3], + qr/^\[Found\s+[^\]]*\]\s+<([^ \t(>]*)/m ], + + ### http://www.f-prot.com/ - backs up F-Prot Daemon (old) + ['FRISK F-Prot Antivirus', ['f-prot','f-prot.sh'], + '-dumb -archive -packed {}', [0,8], [3,6], # or: [0], [3,6,8], + qr/(?:Infection:|security risk named) (.+)|\s+contains\s+(.+)$/m ], + + ### http://www.trendmicro.com/ - backs up Trophie + ['Trend Micro FileScanner', ['/etc/iscan/vscan','vscan'], + '-za -a {}', [0], qr/Found virus/m, qr/Found virus (.+) in/m ], + + ### http://www.sald.com/, http://drweb.imshop.de/ - backs up DrWebD + ['drweb - DrWeb Antivirus', # security LHA hole in Dr.Web 4.33 and earlier + ['/usr/local/drweb/drweb', '/opt/drweb/drweb', 'drweb'], + '-path={} -al -go -ot -cn -upn -ok-', + [0,32], [1,9,33], qr' infected (?:with|by)(?: virus)? (.*)$'m ], + + ### http://www.kaspersky.com/ + ['Kaspersky Antivirus v5.5', + ['/opt/kaspersky/kav4fs/bin/kav4fs-kavscanner', + '/opt/kav/5.5/kav4unix/bin/kavscanner', + '/opt/kav/5.5/kav4mailservers/bin/kavscanner', 'kavscanner'], + '-i0 -xn -xp -mn -R -ePASBME {}/*', [0,10,15], [5,20,21,25], + qr/(?:INFECTED|WARNING|SUSPICION|SUSPICIOUS) (.*)/m, +# sub {chdir('/opt/kav/bin') or die "Can't chdir to kav: $!"}, +# sub {chdir($TEMPBASE) or die "Can't chdir back to $TEMPBASE $!"}, + ], + +# Commented out because the name 'sweep' clashes with Debian and FreeBSD +# package/port of an audio editor. Make sure the correct 'sweep' is found +# in the path when enabling. +# +# ### http://www.sophos.com/ - backs up Sophie or SAVI-Perl +# ['Sophos Anti Virus (sweep)', 'sweep', +# '-nb -f -all -rec -ss -sc -archive -cab -mime -oe -tnef '. +# '--no-reset-atime {}', +# [0,2], qr/Virus .*? found/m, +# qr/^>>> Virus(?: fragment)? '?(.*?)'? found/m, +# ], +# # other options to consider: -idedir=/usr/local/sav + +# Always succeeds and considers mail clean. +# Potentially useful when all other scanners fail and it is desirable +# to let mail continue to flow with no virus checking (when uncommented). +# ['always-clean', sub {0}], + +); + +1; # ensure a defined return diff --git a/amavis/conf.d/15-content_filter_mode b/amavis/conf.d/15-content_filter_mode new file mode 100644 index 00000000..57c62c85 --- /dev/null +++ b/amavis/conf.d/15-content_filter_mode @@ -0,0 +1,27 @@ +use strict; + +# You can modify this file to re-enable SPAM checking through spamassassin +# and to re-enable antivirus checking. + +# +# Default antivirus checking mode +# Please note, that anti-virus checking is DISABLED by +# default. +# If You wish to enable it, please uncomment the following lines: + + +#@bypass_virus_checks_maps = ( +# \%bypass_virus_checks, \@bypass_virus_checks_acl, \$bypass_virus_checks_re); + + +# +# Default SPAM checking mode +# Please note, that anti-spam checking is DISABLED by +# default. +# If You wish to enable it, please uncomment the following lines: + + +#@bypass_spam_checks_maps = ( +# \%bypass_spam_checks, \@bypass_spam_checks_acl, \$bypass_spam_checks_re); + +1; # ensure a defined return diff --git a/amavis/conf.d/20-debian_defaults b/amavis/conf.d/20-debian_defaults new file mode 100644 index 00000000..6016b55b --- /dev/null +++ b/amavis/conf.d/20-debian_defaults @@ -0,0 +1,212 @@ +use strict; + +# ADMINISTRATORS: +# Debian suggests that any changes you need to do that should never +# be "updated" by the Debian package should be made in another file, +# overriding the settings in this file. +# +# The package will *not* overwrite your settings, but by keeping +# them separate, you will make the task of merging changes on these +# configuration files much simpler... + +# see /usr/share/doc/amavisd-new/examples/amavisd.conf-default for +# a list of all variables with their defaults; +# see /usr/share/doc/amavisd-new/examples/amavisd.conf-sample for +# a traditional-style commented file +# [note: the above files were not converted to Debian settings!] +# +# for more details see documentation in /usr/share/doc/amavisd-new +# and at http://www.ijs.si/software/amavisd/amavisd-new-docs.html + +$QUARANTINEDIR = "$MYHOME/virusmails"; +$quarantine_subdir_levels = 1; # enable quarantine dir hashing + +$log_recip_templ = undef; # disable by-recipient level-0 log entries +$DO_SYSLOG = 1; # log via syslogd (preferred) +$syslog_ident = 'amavis'; # syslog ident tag, prepended to all messages +$syslog_facility = 'mail'; +$syslog_priority = 'debug'; # switch to info to drop debug output, etc + +$enable_db = 1; # enable use of BerkeleyDB/libdb (SNMP and nanny) +$enable_global_cache = 1; # enable use of libdb-based cache if $enable_db=1 + +$inet_socket_port = 10024; # default listening socket + +$sa_spam_subject_tag = '***SPAM*** '; +$sa_tag_level_deflt = 2.0; # add spam info headers if at, or above that level +$sa_tag2_level_deflt = 6.31; # add 'spam detected' headers at that level +$sa_kill_level_deflt = 6.31; # triggers spam evasive actions +$sa_dsn_cutoff_level = 10; # spam level beyond which a DSN is not sent + +$sa_mail_body_size_limit = 200*1024; # don't waste time on SA if mail is larger +$sa_local_tests_only = 0; # only tests which do not require internet access? + +# Quota limits to avoid bombs (like 42.zip) + +$MAXLEVELS = 14; +$MAXFILES = 1500; +$MIN_EXPANSION_QUOTA = 100*1024; # bytes +$MAX_EXPANSION_QUOTA = 300*1024*1024; # bytes + +# You should: +# Use D_DISCARD to discard data (viruses) +# Use D_BOUNCE to generate local bounces by amavisd-new +# Use D_REJECT to generate local or remote bounces by the calling MTA +# Use D_PASS to deliver the message +# +# Whatever you do, *NEVER* use D_REJECT if you have other MTAs *forwarding* +# mail to your account. Use D_BOUNCE instead, otherwise you are delegating +# the bounce work to your friendly forwarders, which might not like it at all. +# +# On dual-MTA setups, one can often D_REJECT, as this just makes your own +# MTA generate the bounce message. Test it first. +# +# Bouncing viruses is stupid, always discard them after you are sure the AV +# is working correctly. Bouncing real SPAM is also useless, if you cannot +# D_REJECT it (and don't D_REJECT mail coming from your forwarders!). + +$final_virus_destiny = D_DISCARD; # (data not lost, see virus quarantine) +$final_banned_destiny = D_BOUNCE; # D_REJECT when front-end MTA +$final_spam_destiny = D_BOUNCE; +$final_bad_header_destiny = D_PASS; # False-positive prone (for spam) + +$enable_dkim_verification = 0; #disabled to prevent warning + +$virus_admin = "postmaster\@$mydomain"; # due to D_DISCARD default + +# Set to empty ("") to add no header +$X_HEADER_LINE = "Debian $myproduct_name at $mydomain"; + +# REMAINING IMPORTANT VARIABLES ARE LISTED HERE BECAUSE OF LONGER ASSIGNMENTS + +# +# DO NOT SEND VIRUS NOTIFICATIONS TO OUTSIDE OF YOUR DOMAIN. EVER. +# +# These days, almost all viruses fake the envelope sender and mail headers. +# Therefore, "virus notifications" became nothing but undesired, aggravating +# SPAM. This holds true even inside one's domain. We disable them all by +# default, except for the EICAR test pattern. +# + +@viruses_that_fake_sender_maps = (new_RE( + [qr'\bEICAR\b'i => 0], # av test pattern name + [qr/.*/ => 1], # true for everything else +)); + +@keep_decoded_original_maps = (new_RE( +# qr'^MAIL$', # retain full original message for virus checking (can be slow) + qr'^MAIL-UNDECIPHERABLE$', # recheck full mail if it contains undecipherables + qr'^(ASCII(?! cpio)|text|uuencoded|xxencoded|binhex)'i, +# qr'^Zip archive data', # don't trust Archive::Zip +)); + + +# for $banned_namepath_re, a new-style of banned table, see amavisd.conf-sample + +$banned_filename_re = new_RE( +# qr'^UNDECIPHERABLE$', # is or contains any undecipherable components + + # block certain double extensions anywhere in the base name + qr'\.[^./]*\.(exe|vbs|pif|scr|bat|cmd|com|cpl|dll)\.?$'i, + + qr'\{[0-9a-f]{8}(-[0-9a-f]{4}){3}-[0-9a-f]{12}\}?$'i, # Windows Class ID CLSID, strict + + qr'^application/x-msdownload$'i, # block these MIME types + qr'^application/x-msdos-program$'i, + qr'^application/hta$'i, + +# qr'^application/x-msmetafile$'i, # Windows Metafile MIME type +# qr'^\.wmf$', # Windows Metafile file(1) type + +# qr'^message/partial$'i, qr'^message/external-body$'i, # rfc2046 MIME types + +# [ qr'^\.(Z|gz|bz2)$' => 0 ], # allow any in Unix-compressed +# [ qr'^\.(rpm|cpio|tar)$' => 0 ], # allow any in Unix-type archives +# [ qr'^\.(zip|rar|arc|arj|zoo)$'=> 0 ], # allow any within such archives +# [ qr'^application/x-zip-compressed$'i => 0], # allow any within such archives + + qr'.\.(exe|vbs|pif|scr|bat|cmd|com|cpl)$'i, # banned extension - basic +# qr'.\.(ade|adp|app|bas|bat|chm|cmd|com|cpl|crt|emf|exe|fxp|grp|hlp|hta| +# inf|ins|isp|js|jse|lnk|mda|mdb|mde|mdw|mdt|mdz|msc|msi|msp|mst| +# ops|pcd|pif|prg|reg|scr|sct|shb|shs|vb|vbe|vbs| +# wmf|wsc|wsf|wsh)$'ix, # banned ext - long + +# qr'.\.(mim|b64|bhx|hqx|xxe|uu|uue)$'i, # banned extension - WinZip vulnerab. + + qr'^\.(exe-ms)$', # banned file(1) types +# qr'^\.(exe|lha|tnef|cab|dll)$', # banned file(1) types +); +# See http://support.microsoft.com/default.aspx?scid=kb;EN-US;q262631 +# and http://www.cknow.com/vtutor/vtextensions.htm + + +# ENVELOPE SENDER SOFT-WHITELISTING / SOFT-BLACKLISTING + +@score_sender_maps = ({ # a by-recipient hash lookup table, + # results from all matching recipient tables are summed + +# ## per-recipient personal tables (NOTE: positive: black, negative: white) +# 'user1@example.com' => [{'bla-mobile.press@example.com' => 10.0}], +# 'user3@example.com' => [{'.ebay.com' => -3.0}], +# 'user4@example.com' => [{'cleargreen@cleargreen.com' => -7.0, +# '.cleargreen.com' => -5.0}], + + ## site-wide opinions about senders (the '.' matches any recipient) + '.' => [ # the _first_ matching sender determines the score boost + + new_RE( # regexp-type lookup table, just happens to be all soft-blacklist + [qr'^(bulkmail|offers|cheapbenefits|earnmoney|foryou)@'i => 5.0], + [qr'^(greatcasino|investments|lose_weight_today|market\.alert)@'i=> 5.0], + [qr'^(money2you|MyGreenCard|new\.tld\.registry|opt-out|opt-in)@'i=> 5.0], + [qr'^(optin|saveonlsmoking2002k|specialoffer|specialoffers)@'i => 5.0], + [qr'^(stockalert|stopsnoring|wantsome|workathome|yesitsfree)@'i => 5.0], + [qr'^(your_friend|greatoffers)@'i => 5.0], + [qr'^(inkjetplanet|marketopt|MakeMoney)\d*@'i => 5.0], + ), + +# read_hash("/var/amavis/sender_scores_sitewide"), + +# This are some examples for whitelists, since envelope senders can be forged +# they are not enabled by default. + { # a hash-type lookup table (associative array) + #'nobody@cert.org' => -3.0, + #'cert-advisory@us-cert.gov' => -3.0, + #'owner-alert@iss.net' => -3.0, + #'slashdot@slashdot.org' => -3.0, + #'securityfocus.com' => -3.0, + #'ntbugtraq@listserv.ntbugtraq.com' => -3.0, + #'security-alerts@linuxsecurity.com' => -3.0, + #'mailman-announce-admin@python.org' => -3.0, + #'amavis-user-admin@lists.sourceforge.net'=> -3.0, + #'amavis-user-bounces@lists.sourceforge.net' => -3.0, + #'spamassassin.apache.org' => -3.0, + #'notification-return@lists.sophos.com' => -3.0, + #'owner-postfix-users@postfix.org' => -3.0, + #'owner-postfix-announce@postfix.org' => -3.0, + #'owner-sendmail-announce@lists.sendmail.org' => -3.0, + #'sendmail-announce-request@lists.sendmail.org' => -3.0, + #'donotreply@sendmail.org' => -3.0, + #'ca+envelope@sendmail.org' => -3.0, + #'noreply@freshmeat.net' => -3.0, + #'owner-technews@postel.acm.org' => -3.0, + #'ietf-123-owner@loki.ietf.org' => -3.0, + #'cvs-commits-list-admin@gnome.org' => -3.0, + #'rt-users-admin@lists.fsck.com' => -3.0, + #'clp-request@comp.nus.edu.sg' => -3.0, + #'surveys-errors@lists.nua.ie' => -3.0, + #'emailnews@genomeweb.com' => -5.0, + #'yahoo-dev-null@yahoo-inc.com' => -3.0, + #'returns.groups.yahoo.com' => -3.0, + #'clusternews@linuxnetworx.com' => -3.0, + #lc('lvs-users-admin@LinuxVirtualServer.org') => -3.0, + #lc('owner-textbreakingnews@CNNIMAIL12.CNN.COM') => -5.0, + + # soft-blacklisting (positive score) + #'sender@example.net' => 3.0, + #'.example.net' => 1.0, + + }, + ], # end of site-wide tables +}); + +1; # ensure a defined return diff --git a/amavis/conf.d/25-amavis_helpers b/amavis/conf.d/25-amavis_helpers new file mode 100644 index 00000000..ef399e41 --- /dev/null +++ b/amavis/conf.d/25-amavis_helpers @@ -0,0 +1,23 @@ +use strict; + +## +## Functionality required for amavis helpers like +## amavis-release. +## + +# Enable required AM.PDP protocol socket. +# +# this is incompatible with the old helpers, but one can +# have multiple inet (not unix) sockets to overcome this +# issue. Refer to the amavisd-new documentation for more +# information + +$unix_socketname = "/var/lib/amavis/amavisd.sock"; + +$interface_policy{'SOCK'} = 'AM.PDP-SOCK'; +$policy_bank{'AM.PDP-SOCK'} = { + protocol => 'AM.PDP', + auth_required_release => 0, # don't require secret-id for release +}; + +1; # ensure a defined return diff --git a/amavis/conf.d/30-template_localization b/amavis/conf.d/30-template_localization new file mode 100644 index 00000000..b808bd71 --- /dev/null +++ b/amavis/conf.d/30-template_localization @@ -0,0 +1,42 @@ +use strict; + +# l10n (localization) of the AMaViSd-new DSN templates +# Override or change as necessary + +# Select notifications text encoding when Unicode-aware Perl is converting +# text from internal character representation to external encoding (charset +# in MIME terminology). Used as argument to Perl Encode::encode subroutine. +# +# to be used in RFC 2047-encoded header field bodies, e.g. in Subject: +#$hdr_encoding = 'iso-8859-1'; # (default: 'iso-8859-1') +# +# to be used in notification body text: its encoding and Content-type.charset +#$bdy_encoding = 'iso-8859-1'; # (default: 'iso-8859-1') + +# Default template texts for notifications may be overruled by directly +# assigning new text to template variables, or by reading template text +# from files. A second argument may be specified in a call to read_text(), +# specifying character encoding layer to be used when reading from the +# external file, e.g. 'utf8', 'iso-8859-1', or often just $bdy_encoding. +# Text will be converted to internal character representation by Perl 5.8.0 +# or later; second argument is ignored otherwise. See PerlIO::encoding, +# Encode::PerlIO and perluniintro man pages. +# +# $notify_sender_templ = read_text('/var/amavis/notify_sender.txt'); +# $notify_virus_sender_templ= read_text('/var/amavis/notify_virus_sender.txt'); +# $notify_virus_admin_templ = read_text('/var/amavis/notify_virus_admin.txt'); +# $notify_virus_recips_templ= read_text('/var/amavis/notify_virus_recips.txt'); +# $notify_spam_sender_templ = read_text('/var/amavis/notify_spam_sender.txt'); +# $notify_spam_admin_templ = read_text('/var/amavis/notify_spam_admin.txt'); + +# If notification template files are collectively available in some directory, +# you can use read_l10n_templates which calls read_text for each known +# template. Name the files as above, and include a file named "charset" with +# the charset used in the files. This is how Debian ships l10n templates. +# +# syntax: read_l10n_templates(); OR +# read_l10n_templates(, ); +# +read_l10n_templates('en_US', '/etc/amavis'); + +1; # ensure a defined return diff --git a/amavis/conf.d/50-user b/amavis/conf.d/50-user new file mode 100644 index 00000000..7ca6abf1 --- /dev/null +++ b/amavis/conf.d/50-user @@ -0,0 +1,73 @@ +use strict; + +## +## Die Kommunikation mit Amavis soll über einen Unix-Socket und über das AM.PDP-Prokoll erfolgen. +## amavisd-milter nimmt E-Mails von Postfix über die Milter-Schnittstelle bereit und übersetzt das Milter-Protokoll +## in das AM.PDP-Protokoll, da Amavis selbst kein Milter-Protokoll unterstützt. +## Postfix === Milter-Protokoll ===> Amavisd-Milter === AM.PDP-Protokoll ===> Amavis (und zurück) +## +$protocol = "AM.PDP"; +$unix_socketname = "/var/run/amavis/amavisd.sock"; +$inet_socket_port = undef; + + +## +## Policy-Bank für E-Mails von Mailclients +## E-Mails, die durch den Submission-Port für Mailclients in das Mailsystem gelangen, bekommen via Postfix-Option +## -o milter_macro_daemon_name=ORIGINATING eine "Markierung" mit "ORIGINATING". Amavis soll diese "Markierung" erkennen +## und in diesem Fall keine Untersuchung auf Spam durchführen. +## Lokale Absender (z.B. via mailx-Kommando) sind von der Spam-Untersuchung nicht betroffen, da Amavis sie automatisch als +## solche (Client 127.0.0.1) erkennt. +## + +$policy_bank{'ORIGINATING'} = { + originating => 1, + bypass_spam_checks_maps => [1] +}; + + +### +### Für welche Domains ist der Mailserver zuständig? +### => Datenbank befragen +### + +@local_domains_maps = ( [] ); + +@lookup_sql_dsn = ( ['DBI:mysql:database=postfixdb;host=127.0.0.1;port=3306', 'postfix', 'e9EEBSJCxPHw'], ); + +$sql_select_policy = 'SELECT "Y" as local, 1 as id FROM domains WHERE CONCAT("@",domain) IN (%k)'; +$sql_select_white_black_list = undef; + + +## +## DKIM-Verifizierung aktivieren +## Amavis prüft DKIM-Signaturen eingehender E-Mails (falls vorhanden). +## Ist die Signatur in Ordnung, wird der Spam-Score nach unten korrigiert. +## + +$enable_dkim_verification = 1; + +### +### Spamassassin settings +### + +### Spam-Checks aktivieren +@bypass_spam_checks_maps = (\%bypass_spam_checks, \@bypass_spam_checks_acl, \$bypass_spam_checks_re); +$sa_tag_level_deflt = -999; # Informationen zu Spam-Score ab diesem Level (hier: immer) in den Header schreiben +$sa_tag2_level_deflt = 5.0; # Ab diesem Level E-Mails als Spam markieren +$sa_kill_level_deflt = 5.9; # Ab diesem Level E-Mails nicht annehmen, sondern Aktion in "final_spam_destiny" auslösen (REJECT) + +$sa_spam_subject_tag = undef; # Kein ***SPAM*** in den Betreff schreiben, falls Spam +$spam_quarantine_to = undef; # Spam nicht in die Quarantäne verschieben +$final_spam_destiny = D_REJECT; # Aktion, wenn kill_level erreicht wurde: E-Mail nicht annehmen und REJECT auslösen + + +### +### Falls Benachrichtigungsmails an User geschickt werden sollen (z.B. bei geblockter Mail) +### + +$notify_method = 'smtp:[127.0.0.1]:25'; + + +#------------ Do not modify anything below this line ------------- +1; # ensure a defined return diff --git a/amavis/en_US/charset b/amavis/en_US/charset new file mode 100644 index 00000000..fd23d723 --- /dev/null +++ b/amavis/en_US/charset @@ -0,0 +1,4 @@ +# This is charset for en_US messages. +# If you are creating new messages, use 'iconv -l' to get possible encodings. +ascii # or iso-8859-1 +ignored lines after first one diff --git a/amavis/en_US/template-auto-response.txt b/amavis/en_US/template-auto-response.txt new file mode 100644 index 00000000..5b50bafe --- /dev/null +++ b/amavis/en_US/template-auto-response.txt @@ -0,0 +1,23 @@ +# +# ============================================================================= +# This is a template for the plain text part of an auto response (e.g. +# vacation, out-of-office), see RFC 3834. +# +From: %f +Date: %d +To: [? %#T |undisclosed-recipients:;|[%T|, ]] +[? %#C |#|Cc: [%C|, ]] +Reply-To: postmaster@%h +Message-ID: +Auto-Submitted: auto-replied +[:wrap|76||\t|Subject: Auto: autoresponse to: %s] +[? %m |#|In-Reply-To: %m] +Precedence: junk + +This is an auto-response to a message \ +[? %a |\nreceived on %d,|received from\nIP address \[%a\] on %d,] +envelope sender: %s +(author) From: [:rfc2822_from] +[? %j |#|[:wrap|78|| |Subject: %j]] +[?[:dkim|author]|#| +A first-party DKIM or DomainKeys signature is valid, d=[:dkim|author].] diff --git a/amavis/en_US/template-dsn.txt b/amavis/en_US/template-dsn.txt new file mode 100644 index 00000000..561d1631 --- /dev/null +++ b/amavis/en_US/template-dsn.txt @@ -0,0 +1,134 @@ +# +# ============================================================================= +# This is a template for (neutral: non-virus, non-spam, non-banned) +# DELIVERY STATUS NOTIFICATIONS to sender. +# For syntax and customization instructions see README.customize. +# The From, To and Date header fields will be provided automatically. +# Long header fields will be automatically wrapped by the program. +# +Subject: [?%#D|Undeliverable mail|Delivery status notification]\ +[? [:ccat|major] |||, MTA-BLOCKED\ +|, OVERSIZED message\ +|, invalid header section[=explain_badh|1]\ +[?[:ccat|minor]||: bad MIME|: unencoded 8-bit character\ +|: improper use of control char|: all-whitespace header line\ +|: header line longer than 998 characters|: header field syntax error\ +|: missing required header field|: duplicate header field|]\ +|, UNSOLICITED BULK EMAIL apparently from you\ +|, UNSOLICITED BULK EMAIL apparently from you\ +|, contents UNCHECKED\ +|, BANNED contents type (%F)\ +|, VIRUS in message apparently from you (%V)\ +] +Message-ID: + +[? %#D |#|Your message WAS SUCCESSFULLY RELAYED to:[\n %D] +[~[:dsn_notify]|["\\bSUCCESS\\b"]|\ +and you explicitly requested a delivery status notification on success.\n]\ +] +[? %#N |#|The message WAS NOT relayed to:[\n %N] +] +[:wrap|78|||This [?%#D|nondelivery|delivery] report was \ +generated by the program amavisd-new at host %h. \ +Our internal reference code for your message is %n/%i] + +# ccat_min 0: other, 1: bad MIME, 2: 8-bit char, 3: NUL/CR, +# 4: empty, 5: long, 6: syntax, 7: missing, 8: multiple +[? [:explain_badh] ||[? [:ccat|minor] +|INVALID HEADER +|INVALID HEADER: BAD MIME HEADER SECTION OR BAD MIME STRUCTURE +|INVALID HEADER: INVALID 8-BIT CHARACTERS IN HEADER SECTION +|INVALID HEADER: INVALID CONTROL CHARACTERS IN HEADER SECTION +|INVALID HEADER: FOLDED HEADER FIELD LINE MADE UP ENTIRELY OF WHITESPACE +|INVALID HEADER: HEADER LINE LONGER THAN RFC 5322 LIMIT OF 998 CHARACTERS +|INVALID HEADER: HEADER FIELD SYNTAX ERROR +|INVALID HEADER: MISSING REQUIRED HEADER FIELD +|INVALID HEADER: DUPLICATE HEADER FIELD +|INVALID HEADER +] +[[:wrap|78| | |%X]\n] +]\ +# +[:wrap|78|| |Return-Path: %s[?[:dkim|envsender]|| (OK)]] +[:wrap|78|| |From: [:header_field|From|100][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|\ +[:wrap|78|| |Sender: [:header_field|Sender|100]\ +[?[:dkim|sender]|| (dkim:SENDER)]]] +[? %m |#|[:wrap|78|| |Message-ID: %m]] +[? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +[? %#X|#|[? [:useragent] |#|[:wrap|78|| |[:useragent]]]] +[? %j |#|[:wrap|78|| |Subject: [:header_field|Subject|100]]] + +# ccat_min 0: other, 1: bad MIME, 2: 8-bit char, 3: NUL/CR, +# 4: empty, 5: long, 6: syntax, 7: missing, 8: multiple +[? [:explain_badh] ||[? [:ccat|minor] +|# 0: other +|# 1: bad MIME +|# 2: 8-bit char +WHAT IS AN INVALID CHARACTER IN A MAIL HEADER SECTION? + + The RFC 5322 document specifies rules for forming internet messages. + It does not allow the use of characters with codes above 127 to be + used directly (non-encoded) in a mail header section. + + If such characters (e.g. with diacritics) from ISO Latin or other + alphabets need to be included in a header section, these characters + need to be properly encoded according to RFC 2047. Such encoding + is often done transparently by mail reader (MUA), but if automatic + encoding is not available (e.g. by some older MUA) it is a user's + responsibility to avoid using such characters in a header section, + or to encode them manually. Typically the offending header fields + in this category are 'Subject', 'Organization', and comment fields + or display names in e-mail addresses of 'From', 'To' or 'Cc'. + + Sometimes such invalid header fields are inserted automatically + by some MUA, MTA, content filter, or other mail handling service. + If this is the case, such service needs to be fixed or properly + configured. Typically the offending header fields in this category + are 'Date', 'Received', 'X-Mailer', 'X-Priority', 'X-Scanned', etc. + + If you don't know how to fix or avoid the problem, please report it + to _your_ postmaster or system manager. +# +[~[:useragent]|^X-Mailer:\\s*Microsoft Outlook Express 6\\.00|[" + If using Microsoft Outlook Express as your MUA, make sure its + settings under: + Tools -> Options -> Send -> Mail Sending Format -> Plain & HTML + are: "MIME format" MUST BE selected, + and "Allow 8-bit characters in headers" MUST NOT be enabled! +"]]# +|# 3: NUL/CR +IMPROPER USE OF CONTROL CHARACTER IN A MESSAGE HEADER SECTION + + The RFC 5322 document specifies rules for forming internet messages. + It does not allow the use of control characters NUL and bare CR + to be used directly in a mail header section. +|# 4: empty +IMPROPERLY FOLDED HEADER FIELD LINE MADE UP ENTIRELY OF WHITESPACE + + The RFC 5322 document specifies rules for forming internet messages. + In section '3.2.2. Folding white space and comments' it explicitly + prohibits folding of header fields in such a way that any line of a + folded header field is made up entirely of white-space characters + (control characters SP and HTAB) and nothing else. +|# 5: long +HEADER LINE LONGER THAN RFC 5322 LIMIT OF 998 CHARACTERS + + The RFC 5322 document specifies rules for forming internet messages. + Section '2.1.1. Line Length Limits' prohibits each line of a header + section to be more than 998 characters in length (excluding the CRLF). +|# 6: syntax +|# 7: missing +MISSING REQUIRED HEADER FIELD + + The RFC 5322 document specifies rules for forming internet messages. + Section '3.6. Field Definitions' specifies that certain header fields + are required (origination date field and the "From:" originator field). +|# 8: multiple +DUPLICATE HEADER FIELD + + The RFC 5322 document specifies rules for forming internet messages. + Section '3.6. Field Definitions' specifies that certain header fields + must not occur more than once in a message header section. +|# other +]]# diff --git a/amavis/en_US/template-problem-feedback.txt b/amavis/en_US/template-problem-feedback.txt new file mode 100644 index 00000000..2f6b14e3 --- /dev/null +++ b/amavis/en_US/template-problem-feedback.txt @@ -0,0 +1,37 @@ +# +# ============================================================================= +# This is a template for the plain text part of a problem/feedback report, +# with either the original message included in-line, or attached, +# or the message is structured as a FEEDBACK REPORT NOTIFICATIONS format. +# See RFC 5965 - "An Extensible Format for Email Feedback Reports". +# +From: %f +Date: %d +Subject: Fw: %j +To: [? %#T |undisclosed-recipients:;|[%T|, ]] +[? %#C |#|Cc: [%C|, ]] +Message-ID: +#Auto-Submitted: auto-generated + +This is an e-mail [:feedback_type] report for a message \ +[? %a |\nreceived on %d,|received from\nIP address [:client_addr_port] on %d,] + +[:wrap|78|| |Return-Path: %s] +[:wrap|78|| |From: [:header_field|From][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|[:wrap|78|| |Sender: [:header_field|Sender]]] +[? %m |#|[:wrap|78|| |Message-ID: %m]] +[? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +[? %j |#|[:wrap|78|| |Subject: [:header_field|Subject|100]]] +[?[:dkim|author]|#| +A first-party DKIM or DomainKeys signature is valid, d=[:dkim|author].] + +Reporting-MTA: %h +Our internal reference code for the message is %n/%i + +[~[:report_format]|["^(arf|attach|dsn)$"]|["\ +A complete original message is attached. +[~[:report_format]|["^arf$"]|\ +For more information on the ARF format please see RFC 5965. +]"]|["\ +A complete original message in its pristine form follows: +"]]# diff --git a/amavis/en_US/template-release-quarantine.txt b/amavis/en_US/template-release-quarantine.txt new file mode 100644 index 00000000..affd42e4 --- /dev/null +++ b/amavis/en_US/template-release-quarantine.txt @@ -0,0 +1,45 @@ +# +# ============================================================================= +# This is a template for the plain text part of a RELEASE FROM A QUARANTINE, +# applicable if a chosen release format is 'attach' (not 'resend'). +# +From: %f +Date: %d +Subject: \[released message\] %j +To: [? %#T |undisclosed-recipients:;|[%T|, ]] +[? %#C |#|Cc: [%C|, ]] +Message-ID: + +Please find attached a message which was held in a quarantine, +and has now been released. + +[:wrap|78|| |Return-Path: %s[?[:dkim|envsender]|| (OK)]] +[:wrap|78|| |From: [:header_field|From][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|\ +[:wrap|78|| |Sender: [:header_field|Sender]\ +[?[:dkim|sender]|| (dkim:SENDER)]]] +# [? %m |#|[:wrap|78|| |Message-ID: %m]] +# [? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +# [? [:useragent] |#|[:wrap|78|| |[:useragent]]] +[? %j |#|[:wrap|78|| |Subject: %j]] + +Our internal reference code for the message is %n/%i +# +[~[:report_format]|["^attach$"]|["[? [:attachment_password] |#| + +Contents of the attached mail message may pose a threat to your computer or +could be a social engineering deception, so it should be handled cautiously. +To prevent undesired automatic opening, the attached original mail message +has been wrapped in a password-protected ZIP archive. + +Here is the password that allows opening of the attached archive: + + [:attachment_password] + +Note that the attachment is not strongly encrypted and the password +is not a strong secret (being displayed in this non-encrypted text), +so this attachment is not suitable for guarding a secret contents. +The sole purpose of this password protection it to prevent undesired +accidental or automatic opening of a message, either by some filtering +software, a virus scanner, or by a mail reader. +]"]|]# diff --git a/amavis/en_US/template-spam-admin.txt b/amavis/en_US/template-spam-admin.txt new file mode 100644 index 00000000..317acc33 --- /dev/null +++ b/amavis/en_US/template-spam-admin.txt @@ -0,0 +1,39 @@ +# +# ============================================================================= +# This is a template for spam ADMINISTRATOR NOTIFICATIONS. +# For syntax and customization instructions see README.customize. +# Long header fields will be automatically wrapped by the program. +# +From: %f +Date: %d +Subject: Spam FROM [?%l||LOCAL ][?%a||[:client_addr_port] ]%s +To: [? %#T |undisclosed-recipients:;|[%T|, ]] +[? %#C |#|Cc: [%C|, ]] +Message-ID: + +Content type: [:ccat|name|main]# +[? [:ccat|is_blocked_by_nonmain] ||, blocked for [:ccat|name]] +Internal reference code for the message is %n/%i + +[? %a |#|[:wrap|78|| |First upstream SMTP client IP address: \[%a\] %g]] +[? %e |#|[:wrap|78|| |According to a 'Received:' trace,\ + the message apparently originated at: \[%e\], %t]] + +[:wrap|78|| |Return-Path: %s[?[:dkim|envsender]|| (OK)]] +[:wrap|78|| |From: [:header_field|From][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|\ +[:wrap|78|| |Sender: [:header_field|Sender]\ +[?[:dkim|sender]|| (dkim:SENDER)]]] +[? %m |#|[:wrap|78|| |Message-ID: %m]] +[? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +[? [:useragent] |#|[:wrap|78|| |[:useragent]]] +[? %j |#|[:wrap|78|| |Subject: %j]] +[? %q |Not quarantined.|The message has been quarantined as: %q] + +[? %#D |#|The message WILL BE relayed to:[\n%D] +] +[? %#N |#|The message WAS NOT relayed to:[\n%N] +] +Spam scanner report: +[%A +]\ diff --git a/amavis/en_US/template-spam-sender.txt b/amavis/en_US/template-spam-sender.txt new file mode 100644 index 00000000..5d91afee --- /dev/null +++ b/amavis/en_US/template-spam-sender.txt @@ -0,0 +1,48 @@ +# +# ============================================================================= +# This is a template for spam SENDER NOTIFICATIONS. +# For syntax and customization instructions see README.customize. +# The From, To and Date header fields will be provided automatically. +# Long header fields will be automatically wrapped by the program. +# +Subject: Considered UNSOLICITED BULK EMAIL, apparently from you +[? %m |#|In-Reply-To: %m] +Message-ID: + +A message from %s[ +to: %R] + +was considered unsolicited bulk e-mail (UBE). + +Our internal reference code for your message is %n/%i + +The message carried your return address, so it was either a genuine mail +from you, or a sender address was faked and your e-mail address abused +by third party, in which case we apologize for undesired notification. + +We do try to minimize backscatter for more prominent cases of UBE and +for infected mail, but for less obvious cases some balance between +losing genuine mail and sending undesired backscatter is sought, +and there can be some collateral damage on either side. + +[? %a |#|[:wrap|78|| |First upstream SMTP client IP address: \[%a\] %g]] +[? %e |#|[:wrap|78|| |According to a 'Received:' trace,\ + the message apparently originated at: \[%e\], %t]] + +[:wrap|78|| |Return-Path: %s[?[:dkim|envsender]|| (OK)]] +[:wrap|78|| |From: [:header_field|From|100][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|\ +[:wrap|78|| |Sender: [:header_field|Sender|100]\ +[?[:dkim|sender]|| (dkim:SENDER)]]] +[? %m |#|[:wrap|78|| |Message-ID: %m]] +[? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +# [? [:useragent] |#|[:wrap|78|| |[:useragent]]] +[? %j |#|[:wrap|78|| |Subject: [:header_field|Subject|100]]] +[? %#X |#|\n[[:wrap|78|| |%X]\n]] + +[? %#D |Delivery of the email was stopped! +]# +# +# Spam scanner report: +# [%A +# ]\ diff --git a/amavis/en_US/template-virus-admin.txt b/amavis/en_US/template-virus-admin.txt new file mode 100644 index 00000000..559b6d05 --- /dev/null +++ b/amavis/en_US/template-virus-admin.txt @@ -0,0 +1,54 @@ +# +# ============================================================================= +# This is a template for non-spam (e.g. VIRUS,...) ADMINISTRATOR NOTIFICATIONS. +# For syntax and customization instructions see README.customize. +# Long header fields will be automatically wrapped by the program. +# +From: %f +Date: %d +Subject: [? [:ccat|major] |Clean mail|Clean mail|MTA-blocked mail|\ +OVERSIZED mail|INVALID HEADER in mail|Spammy|Spam|UNCHECKED contents in mail|\ +BANNED contents (%F) in mail|VIRUS (%V) in mail]\ + FROM [?%l||LOCAL ][?%a||[:client_addr_port] ]%s +To: [? %#T |undisclosed-recipients:;|[%T|, ]] +[? %#C |#|Cc: [%C|, ]] +Message-ID: + +[? %#V |No viruses were found. +|A virus was found: %V +|Two viruses were found:\n %V +|%#V viruses were found:\n %V +] +[? %#F |#|[:wrap|78|| |Banned [?%#F|names|name|names]: %F]] +[? %#X |#|Bad header:[\n[:wrap|78| | |%X]]] +[? %#W |#\ +|Scanner detecting a virus: %W +|Scanners detecting a virus: %W +] +Content type: [:ccat|name|main]# +[? [:ccat|is_blocked_by_nonmain] ||, blocked for [:ccat|name]] +Internal reference code for the message is %n/%i + +[? %a |#|[:wrap|78|| |First upstream SMTP client IP address: \[%a\] %g]] +[? %e |#|[:wrap|78|| |According to a 'Received:' trace,\ + the message apparently originated at: \[%e\], %t]] + +[:wrap|78|| |Return-Path: %s[?[:dkim|envsender]|| (OK)]] +[:wrap|78|| |From: [:header_field|From][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|\ +[:wrap|78|| |Sender: [:header_field|Sender]\ +[?[:dkim|sender]|| (dkim:SENDER)]]] +[? %m |#|[:wrap|78|| |Message-ID: %m]] +[? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +[? %j |#|[:wrap|78|| |Subject: %j]] +[? %q |Not quarantined.|The message has been quarantined as: %q] + +[? %#S |Notification to sender will not be mailed. + +]# +[? %#D |#|The message WILL BE relayed to:[\n%D] +] +[? %#N |#|The message WAS NOT relayed to:[\n%N] +] +[? %#V |#|[? %#v |#|Virus scanner output:[\n %v] +]] diff --git a/amavis/en_US/template-virus-recipient.txt b/amavis/en_US/template-virus-recipient.txt new file mode 100644 index 00000000..f8e579a8 --- /dev/null +++ b/amavis/en_US/template-virus-recipient.txt @@ -0,0 +1,46 @@ +# +# ============================================================================= +# This is a template for VIRUS/BANNED/BAD-HEADER RECIPIENTS NOTIFICATIONS. +# For syntax and customization instructions see README.customize. +# Long header fields will be automatically wrapped by the program. +# +From: %f +Date: %d +Subject: [? [:ccat|major] |Clean mail|Clean mail|MTA-blocked mail|\ +OVERSIZED mail|INVALID HEADER in mail|Spammy|Spam|UNCHECKED contents in mail|\ +BANNED contents (%F) in mail|VIRUS (%V) in mail] TO YOU from %s +[? [:header_field|To] |To: undisclosed-recipients:;|To: [:header_field|To]] +[? [:header_field|Cc] |#|Cc: [:header_field|Cc]] +Message-ID: + +[? %#V |[? %#F ||BANNED CONTENTS ALERT]|VIRUS ALERT] + +Our content checker found +[? %#V |#|[:wrap|78| | |[?%#V|viruses|virus|viruses]: %V]] +[? %#F |#|[:wrap|78| | |banned [?%#F|names|name|names]: %F]] +[? %#X |#|[[:wrap|78| | |%X]\n]] + +in an email to you [? %#V |from:|from probably faked sender:] + %o +[? %#V |#|claiming to be: %s] + +Content type: [:ccat|name|main]# +[? [:ccat|is_blocked_by_nonmain] ||, blocked for [:ccat|name]] +Our internal reference code for your message is %n/%i + +[? %a |#|[:wrap|78|| |First upstream SMTP client IP address: \[%a\] %g]] +[? %e |#|[:wrap|78|| |According to a 'Received:' trace,\ + the message apparently originated at: \[%e\], %t]] + +[:wrap|78|| |Return-Path: %s[?[:dkim|envsender]|| (OK)]] +[:wrap|78|| |From: [:header_field|From][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|\ +[:wrap|78|| |Sender: [:header_field|Sender]\ +[?[:dkim|sender]|| (dkim:SENDER)]]] +[? %m |#|[:wrap|78|| |Message-ID: %m]] +[? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +[? [:useragent] |#|[:wrap|78|| |[:useragent]]] +[? %j |#|[:wrap|78|| |Subject: %j]] +[? %q |Not quarantined.|The message has been quarantined as: %q] + +Please contact your system administrator for details. diff --git a/amavis/en_US/template-virus-sender.txt b/amavis/en_US/template-virus-sender.txt new file mode 100644 index 00000000..5f254c8d --- /dev/null +++ b/amavis/en_US/template-virus-sender.txt @@ -0,0 +1,91 @@ +# +# ============================================================================= +# This is a template for VIRUS/BANNED SENDER NOTIFICATIONS. +# For syntax and customization instructions see README.customize. +# The From, To and Date header fields will be provided automatically. +# Long header fields will be automatically wrapped by the program. +# +Subject: [? [:ccat|major] +|Clean message from you\ +|Clean message from you\ +|Clean message from you (MTA blocked)\ +|OVERSIZED message from you\ +|BAD-HEADER in message from you\ +|Spam claiming to be from you\ +|Spam claiming to be from you\ +|A message with UNCHECKED contents from you\ +|BANNED contents from you (%F)\ +|VIRUS in message apparently from you (%V)\ +] +[? %m |#|In-Reply-To: %m] +Message-ID: + +[? [:ccat|major] |Clean|Clean|MTA-BLOCKED|OVERSIZED|INVALID HEADER|\ +Spammy|Spam|UNCHECKED contents|BANNED CONTENTS ALERT|VIRUS ALERT] + +Our content checker found +[? %#V |#|[:wrap|78| | |[? %#V |viruses|virus|viruses]: %V]] +[? %#F |#|[:wrap|78| | |banned [? %#F |names|name|names]: %F]] +[? %#X |#|[[:wrap|78| | |%X]\n]] + +in email presumably from you %s +to the following [? %#R |recipients|recipient|recipients]:[ +-> %R] + +Our internal reference code for your message is %n/%i + +[? %a |#|[:wrap|78|| |First upstream SMTP client IP address: \[%a\] %g]] +[? %e |#|[:wrap|78|| |According to a 'Received:' trace,\ + the message apparently originated at: \[%e\], %t]] + +[:wrap|78|| |Return-Path: %s[?[:dkim|envsender]|| (OK)]] +[:wrap|78|| |From: [:header_field|From|100][?[:dkim|author]|| (dkim:AUTHOR)]] +[? [:header_field|Sender]|#|\ +[:wrap|78|| |Sender: [:header_field|Sender|100]\ +[?[:dkim|sender]|| (dkim:SENDER)]]] +[? %m |#|[:wrap|78|| |Message-ID: %m]] +[? %r |#|[:wrap|78|| |Resent-Message-ID: %r]] +[? %j |#|[:wrap|78|| |Subject: [:header_field|Subject|100]]] + +[? %#D |Delivery of the email was stopped! + +]# +[? %#V ||Please check your system for viruses, +or ask your system administrator to do so. + +]# +[? %#V |[? %#F ||# +The message [?%#D|has been blocked|triggered this warning] because it contains a component +(as a MIME part or nested within) with declared name +or MIME type or contents type violating our access policy. + +To transfer contents that may be considered risky or unwanted +by site policies, or simply too large for mailing, please consider +publishing your content on the web, and only sending an URL of the +document to the recipient. + +Depending on the recipient and sender site policies, with a little +effort it might still be possible to send any contents (including +viruses) using one of the following methods: + +- encrypted using pgp, gpg or other encryption methods; + +- wrapped in a password-protected or scrambled container or archive + (e.g.: zip -e, arj -g, arc g, rar -p, or other methods) + +Note that if the contents is not intended to be secret, the +encryption key or password may be included in the same message +for recipient's convenience. + +We are sorry for inconvenience if the contents was not malicious. + +The purpose of these restrictions is to cut the most common propagation +methods used by viruses and other malware. These often exploit automatic +mechanisms and security holes in more popular mail readers (Microsoft +mail readers and browsers are a common target). By requiring an explicit +and decisive action from the recipient to decode mail, the danger of +automatic malware propagation is largely reduced. +# +# Details of our mail restrictions policy are available at ... + +]]# diff --git a/apache2/conf-available/javascript-common.conf b/apache2/conf-available/javascript-common.conf new file mode 100644 index 00000000..7e5dbd3e --- /dev/null +++ b/apache2/conf-available/javascript-common.conf @@ -0,0 +1,5 @@ +Alias /javascript /usr/share/javascript/ + + + Options FollowSymLinks MultiViews + diff --git a/apparmor.d/abstractions/X b/apparmor.d/abstractions/X new file mode 100644 index 00000000..be444fcf --- /dev/null +++ b/apparmor.d/abstractions/X @@ -0,0 +1,62 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009-2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + #include + + + # .ICEauthority files required for X authentication, per user + owner @{HOME}/.ICEauthority r, + owner @{run}/user/*/ICEauthority r, + + # .Xauthority files required for X connections, per user + owner @{HOME}/.Xauthority r, + owner @{HOME}/.local/share/sddm/.Xauthority r, + owner /{,var/}run/gdm{,3}/*/database r, + owner /{,var/}run/lightdm/authority/[0-9]* r, + owner /{,var/}run/lightdm/*/xauthority r, + owner /{,var/}run/user/*/gdm/Xauthority r, + owner /{,var/}run/user/*/X11/Xauthority r, + owner /{,var/}run/user/*/xauth_* r, + + # the unix socket to use to connect to the display + /tmp/.X11-unix/* rw, + unix (connect, receive, send) + type=stream + peer=(addr="@/tmp/.X11-unix/X[0-9]*"), + unix (connect, receive, send) + type=stream + peer=(addr="@/tmp/.ICE-unix/[0-9]*"), + + /usr/include/X11/ r, + /usr/include/X11/** r, + + # The X tree changes and is large -- grant read access to the whole thing + /usr/X11R6/** r, + /usr/share/X11/ r, + /usr/share/X11/** r, + /usr/X11R6/**.so* mr, + + # EGL + /usr/lib/@{multiarch}/egl/*.so* mr, + + # Xcompose + owner @{HOME}/.XCompose r, + /var/cache/libx11/compose/* r, + deny /var/cache/libx11/compose/* wlk, + + # mouse themes + /etc/X11/cursors/ r, + /etc/X11/cursors/** r, + + # Xwayland + owner /run/user/*/.mutter-Xwaylandauth.* r, + diff --git a/apparmor.d/abstractions/apache2-common b/apparmor.d/abstractions/apache2-common new file mode 100644 index 00000000..850dd89c --- /dev/null +++ b/apparmor.d/abstractions/apache2-common @@ -0,0 +1,34 @@ +# vim:syntax=apparmor + +# This file contains basic permissions for Apache and every vHost + + #include + + # Allow unconfined processes to send us signals by default + signal (receive) peer=unconfined, + # Allow apache to send us signals by default + signal (receive) peer=apache2, + # Allow other hats to signal by default + signal peer=apache2//*, + # Allow us to signal ourselves + signal peer=@{profile_name}, + + # Apache + network inet stream, + network inet6 stream, + # apache manual, error pages and icons + /usr/share/apache2/** r, + + # changehat itself + @{PROC}/@{pid}/attr/current rw, + + # htaccess files - for what ever it is worth + /**/.htaccess r, + + /dev/urandom r, + + # sasl-auth + /run/saslauthd/mux rw, + + # OCSP stapling + /var/log/apache2/stapling-cache rw, diff --git a/apparmor.d/abstractions/apparmor_api/change_profile b/apparmor.d/abstractions/apparmor_api/change_profile new file mode 100644 index 00000000..30f6b704 --- /dev/null +++ b/apparmor.d/abstractions/apparmor_api/change_profile @@ -0,0 +1,11 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +#include + +@{PROC}/@{tid}/attr/{current,exec} w, diff --git a/apparmor.d/abstractions/apparmor_api/examine b/apparmor.d/abstractions/apparmor_api/examine new file mode 100644 index 00000000..2f2ea15a --- /dev/null +++ b/apparmor.d/abstractions/apparmor_api/examine @@ -0,0 +1,12 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# Make sure to include at least tunables/proc and tunables/kernelvars +# when using this abstraction, if not tunables/global. + +@{PROC}/@{pids}/attr/{current,prev,exec} r, diff --git a/apparmor.d/abstractions/apparmor_api/find_mountpoint b/apparmor.d/abstractions/apparmor_api/find_mountpoint new file mode 100644 index 00000000..b8ac54d1 --- /dev/null +++ b/apparmor.d/abstractions/apparmor_api/find_mountpoint @@ -0,0 +1,14 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +#permissions needed for aa_find_mountpoint + +# Make sure to include at least tunables/proc and tunables/kernelvars +# when using this abstraction, if not tunables/global. + +@{PROC}/@{pids}/mounts r, diff --git a/apparmor.d/abstractions/apparmor_api/introspect b/apparmor.d/abstractions/apparmor_api/introspect new file mode 100644 index 00000000..e110c849 --- /dev/null +++ b/apparmor.d/abstractions/apparmor_api/introspect @@ -0,0 +1,12 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# Make sure to include at least tunables/proc and tunables/kernelvars +# when using this abstraction, if not tunables/global. + +@{PROC}/@{tid}/attr/{current,prev,exec} r, diff --git a/apparmor.d/abstractions/apparmor_api/is_enabled b/apparmor.d/abstractions/apparmor_api/is_enabled new file mode 100644 index 00000000..a637d3ce --- /dev/null +++ b/apparmor.d/abstractions/apparmor_api/is_enabled @@ -0,0 +1,17 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# permissions needed for aa_is_enabled + +# Make sure to include tunables/apparmorfs and tunables/global +# when using this abstraction + +#include +@{sys}/module/apparmor/parameters/enabled r, + +# TODO: add alternate apparmorfs interface for enabled diff --git a/apparmor.d/abstractions/aspell b/apparmor.d/abstractions/aspell new file mode 100644 index 00000000..95476892 --- /dev/null +++ b/apparmor.d/abstractions/aspell @@ -0,0 +1,13 @@ +# vim:syntax=apparmor +# aspell permissions + + # per-user settings and dictionaries + owner @{HOME}/.aspell.*.{pws,prepl} rwk, + + # system libraries and dictionaries + /usr/lib/aspell/ r, + /usr/lib/aspell/* r, + /usr/lib/aspell/*.so m, + /usr/share/aspell/ r, + /usr/share/aspell/* r, + /var/lib/aspell/* r, diff --git a/apparmor.d/abstractions/audio b/apparmor.d/abstractions/audio new file mode 100644 index 00000000..f4dbaac3 --- /dev/null +++ b/apparmor.d/abstractions/audio @@ -0,0 +1,83 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + + +/dev/admmidi* rw, +/dev/adsp* rw, +/dev/aload* rw, +/dev/amidi* rw, +/dev/audio* rw, +/dev/dmfm* rw, +/dev/dmmidi* rw, +/dev/dsp* rw, +/dev/midi* rw, +/dev/mixer* rw, +/dev/mpu401data rw, +/dev/mpu401stat rw, +/dev/patmgr* rw, +/dev/phone* rw, +/dev/radio* rw, +/dev/rmidi* rw, +/dev/sequencer rw, +/dev/sequencer2 rw, +/dev/smpte* rw, + +/dev/snd/* rw, +/dev/sound/* rw, + +@{PROC}/asound/** rw, + +/usr/share/alsa/** r, +/usr/share/sounds/** r, + +owner @{HOME}/.esd_auth r, +/etc/asound.conf r, +owner @{HOME}/.asoundrc r, +/etc/esound/esd.conf r, + +# libao +/etc/libao.conf r, +owner @{HOME}/.libao r, + +# libcanberra +owner @{HOME}/.cache/event-sound-cache.* rwk, + +# pulse +/etc/pulse/ r, +/etc/pulse/** r, +/{run,dev}/shm/ r, +owner /{run,dev}/shm/pulse-shm* rwk, +owner @{HOME}/.pulse-cookie rwk, +owner @{HOME}/.pulse/ rw, +owner @{HOME}/.pulse/* rwk, +owner /{,var/}run/user/*/pulse/ rw, +owner /{,var/}run/user/*/pulse/{native,pid} rwk, +owner @{HOME}/.config/pulse/*.conf r, +owner @{HOME}/.config/pulse/client.conf.d/{,*.conf} r, +owner @{HOME}/.config/pulse/cookie rwk, +owner /tmp/pulse-*/ rw, +owner /tmp/pulse-*/* rw, + +# libgnome2 +/etc/sound/ r, +/etc/sound/** r, + +# openal +/etc/alsa/conf.d/{,*} r, +/etc/openal/alsoft.conf r, +owner @{HOME}/.alsoftrc r, +/usr/{,local/}share/openal/hrtf/{,**} r, +owner @{HOME}/.local/share/openal/hrtf/{,**} r, + +# wildmidi +/etc/wildmidi/wildmidi.cfg r, diff --git a/apparmor.d/abstractions/authentication b/apparmor.d/abstractions/authentication new file mode 100644 index 00000000..75771ecd --- /dev/null +++ b/apparmor.d/abstractions/authentication @@ -0,0 +1,52 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009-2012 Canonical Ltd +# Copyright (C) 2019 Christian Boltz +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + + + # Some services need to perform authentication of users + # Such authentication almost certainly needs access to the local users + # databases containing passwords, PAM configuration files, PAM libraries + /{usr/,}etc/nologin r, + /{usr/,}etc/pam.d/* r, + /{usr/,}etc/securetty r, + /{usr/,}etc/security/* r, + /{usr/,}etc/shadow r, + /{usr/,}etc/gshadow r, + /{usr/,}etc/pwdb.conf r, + + /{usr/,}lib{,32,64}/security/pam_filter/* mr, + /{usr/,}lib{,32,64}/security/pam_*.so mr, + /{usr/,}lib{,32,64}/security/ r, + /{usr/,}lib/@{multiarch}/security/pam_filter/* mr, + /{usr/,}lib/@{multiarch}/security/pam_*.so mr, + /{usr/,}lib/@{multiarch}/security/ r, + + # kerberos + #include + # SuSE's pwdutils are different: + /{usr/,}etc/default/passwd r, + /{usr/,}etc/login.defs r, + + # nis + #include + + # winbind + #include + + # likewise + #include + + # smbpass + #include + + # p11-kit (PKCS#11 modules configuration) + #include diff --git a/apparmor.d/abstractions/base b/apparmor.d/abstractions/base new file mode 100644 index 00000000..1dc77a30 --- /dev/null +++ b/apparmor.d/abstractions/base @@ -0,0 +1,168 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009-2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + + + # (Note that the ldd profile has inlined this file; if you make + # modifications here, please consider including them in the ldd + # profile as well.) + + # The __canary_death_handler function writes a time-stamped log + # message to /dev/log for logging by syslogd. So, /dev/log, timezones, + # and localisations of date should be available EVERYWHERE, so + # StackGuard, FormatGuard, etc., alerts can be properly logged. + /dev/log w, + /dev/random r, + /dev/urandom r, + # Allow access to the uuidd daemon (this daemon is a thin wrapper around + # time and getrandom()/{,u}random and, when available, runs under an + # unprivilged, dedicated user). + /run/uuidd/request r, + /etc/locale/** r, + /etc/locale.alias r, + /etc/localtime r, + /etc/writable/localtime r, + /usr/share/locale-bundle/** r, + /usr/share/locale-langpack/** r, + /usr/share/locale/** r, + /usr/share/**/locale/** r, + /usr/share/zoneinfo/ r, + /usr/share/zoneinfo/** r, + /usr/share/X11/locale/** r, + /run/systemd/journal/dev-log w, + # systemd native journal API (see sd_journal_print(4)) + /run/systemd/journal/socket w, + # Nested containers and anything using systemd-cat need this. 'r' shouldn't + # be required but applications fail without it. journald doesn't leak + # anything when reading so this is ok. + /run/systemd/journal/stdout rw, + + /usr/lib{,32,64}/locale/** mr, + /usr/lib{,32,64}/gconv/*.so mr, + /usr/lib{,32,64}/gconv/gconv-modules* mr, + /usr/lib/@{multiarch}/gconv/*.so mr, + /usr/lib/@{multiarch}/gconv/gconv-modules* mr, + + # used by glibc when binding to ephemeral ports + /etc/bindresvport.blacklist r, + + # ld.so.cache and ld are used to load shared libraries; they are best + # available everywhere + /etc/ld.so.cache mr, + /etc/ld.so.conf r, + /etc/ld.so.conf.d/{,*.conf} r, + /etc/ld.so.preload r, + /{usr/,}lib{,32,64}/ld{,32,64}-*.so mr, + /{usr/,}lib/@{multiarch}/ld{,32,64}-*.so mr, + /{usr/,}lib/tls/i686/{cmov,nosegneg}/ld-*.so mr, + /{usr/,}lib/i386-linux-gnu/tls/i686/{cmov,nosegneg}/ld-*.so mr, + /opt/*-linux-uclibc/lib/ld-uClibc*so* mr, + + # we might as well allow everything to use common libraries + /{usr/,}lib{,32,64}/** r, + /{usr/,}lib{,32,64}/**.so* mr, + /{usr/,}lib/@{multiarch}/** r, + /{usr/,}lib/@{multiarch}/**.so* mr, + /{usr/,}lib/tls/i686/{cmov,nosegneg}/*.so* mr, + /{usr/,}lib/i386-linux-gnu/tls/i686/{cmov,nosegneg}/*.so* mr, + + # /dev/null is pretty harmless and frequently used + /dev/null rw, + # as is /dev/zero + /dev/zero rw, + # recent glibc uses /dev/full in preference to /dev/null for programs + # that don't have open fds at exec() + /dev/full rw, + + # Sometimes used to determine kernel/user interfaces to use + @{PROC}/sys/kernel/version r, + # Depending on which glibc routine uses this file, base may not be the + # best place -- but many profiles require it, and it is quite harmless. + @{PROC}/sys/kernel/ngroups_max r, + + # glibc's sysconf(3) routine to determine free memory, etc + @{PROC}/meminfo r, + @{PROC}/stat r, + @{PROC}/cpuinfo r, + @{sys}/devices/system/cpu/ r, + @{sys}/devices/system/cpu/online r, + + # glibc's *printf protections read the maps file + @{PROC}/@{pid}/{maps,auxv,status} r, + + # libgcrypt reads some flags from /proc + @{PROC}/sys/crypto/* r, + + # some applications will display license information + /usr/share/common-licenses/** r, + + # glibc statvfs + @{PROC}/filesystems r, + + # glibc malloc (man 5 proc) + @{PROC}/sys/vm/overcommit_memory r, + + # Allow determining the highest valid capability of the running kernel + @{PROC}/sys/kernel/cap_last_cap r, + + # Allow other processes to read our /proc entries, futexes, perf tracing and + # kcmp for now (they will need 'read' in the first place). Administrators can + # override with: + # deny ptrace (readby) ... + ptrace (readby), + + # Allow other processes to trace us by default (they will need 'trace' in + # the first place). Administrators can override with: + # deny ptrace (tracedby) ... + ptrace (tracedby), + + # Allow us to ptrace read ourselves + ptrace (read) peer=@{profile_name}, + + # Allow unconfined processes to send us signals by default + signal (receive) peer=unconfined, + + # Allow us to signal ourselves + signal peer=@{profile_name}, + + # Checking for PID existence is quite common so add it by default for now + signal (receive, send) set=("exists"), + + # Allow us to create and use abstract and anonymous sockets + unix peer=(label=@{profile_name}), + + # Allow unconfined processes to us via unix sockets + unix (receive) peer=(label=unconfined), + + # Allow us to create abstract and anonymous sockets + unix (create), + + # Allow us to getattr, getopt, setop and shutdown on unix sockets + unix (getattr, getopt, setopt, shutdown), + + # Workaround https://launchpad.net/bugs/359338 until upstream handles stacked + # filesystems generally. This does not appreciably decrease security with + # Ubuntu profiles because the user is expected to have access to files owned + # by him/her. Exceptions to this are explicit in the profiles. While this rule + # grants access to those exceptions, the intended privacy is maintained due to + # the encrypted contents of the files in this directory. Files in this + # directory will also use filename encryption by default, so the files are + # further protected. Also, with the use of 'owner', this rule properly + # prevents access to the files from processes running under a different uid. + + # encrypted ~/.Private and old-style encrypted $HOME + owner @{HOME}/.Private/ r, + owner @{HOME}/.Private/** mrixwlk, + # new-style encrypted $HOME + owner @{HOMEDIRS}/.ecryptfs/*/.Private/ r, + owner @{HOMEDIRS}/.ecryptfs/*/.Private/** mrixwlk, + diff --git a/apparmor.d/abstractions/bash b/apparmor.d/abstractions/bash new file mode 100644 index 00000000..e8dcd75c --- /dev/null +++ b/apparmor.d/abstractions/bash @@ -0,0 +1,44 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # user-specific bash files + @{HOMEDIRS} r, + @{HOME}/.bashrc r, + @{HOME}/.profile r, + @{HOME}/.bash_profile r, + @{HOME}/.bash_history rw, + + # system-wide bash configuration + /etc/profile.dos r, + /etc/profile r, + /etc/profile.d/ r, + /etc/profile.d/* r, + /etc/bashrc r, + /etc/bash.bashrc r, + /etc/bash.bashrc.local r, + /etc/bash_completion r, + /etc/bash_completion.d/ r, + /etc/bash_completion.d/* r, + + # bash relies on system-wide readline configuration + /etc/inputrc r, + + # bash inspects filesystems at startup + /etc/mtab r, + @{PROC}/@{pid}/mounts r, + @{PROC}/filesystems r, + + # probably readline wants to know terminal capabilities + /usr/share/terminfo/** r, + + # run out of /etc/bash.bashrc + /etc/DIR_COLORS r, + /{usr/,}bin/ls mix, + /usr/bin/dircolors mix, diff --git a/apparmor.d/abstractions/consoles b/apparmor.d/abstractions/consoles new file mode 100644 index 00000000..d6c30be8 --- /dev/null +++ b/apparmor.d/abstractions/consoles @@ -0,0 +1,23 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2005 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + + + # there are three common ways to refer to consoles + /dev/console rw, + /dev/tty rw, + # this next entry is a tad unfortunate; /dev/tty will always be + # associated with the controlling terminal by the kernel, but if a + # program uses the /dev/pts/ interface, it actually has access to + # -all- xterm, sshd, etc, terminals on the system. + /dev/pts/[0-9]* rw, + /dev/pts/ r, + diff --git a/apparmor.d/abstractions/cups-client b/apparmor.d/abstractions/cups-client new file mode 100644 index 00000000..f38ac097 --- /dev/null +++ b/apparmor.d/abstractions/cups-client @@ -0,0 +1,18 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009-2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # discoverable system configuration for non-local cupsd + /etc/cups/client.conf r, + # client should be able to talk the local cupsd + /{,var/}run/cups/cups.sock rw, + # client should be able to read user-specified cups configuration + owner @{HOME}/.cups/client.conf r, + owner @{HOME}/.cups/lpoptions r, diff --git a/apparmor.d/abstractions/dbus b/apparmor.d/abstractions/dbus new file mode 100644 index 00000000..c670fc2d --- /dev/null +++ b/apparmor.d/abstractions/dbus @@ -0,0 +1,16 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009-2013 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # This abstraction grants full system bus access. Consider using the + # dbus-strict abstraction for fine-grained bus mediation. + + #include + dbus bus=system, diff --git a/apparmor.d/abstractions/dbus-accessibility b/apparmor.d/abstractions/dbus-accessibility new file mode 100644 index 00000000..40a33084 --- /dev/null +++ b/apparmor.d/abstractions/dbus-accessibility @@ -0,0 +1,16 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2013 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # This abstraction grants full accessibility bus access. Consider using the + # dbus-accessibility-strict abstraction for fine-grained bus mediation. + + #include + dbus bus=accessibility, diff --git a/apparmor.d/abstractions/dbus-accessibility-strict b/apparmor.d/abstractions/dbus-accessibility-strict new file mode 100644 index 00000000..a853ce20 --- /dev/null +++ b/apparmor.d/abstractions/dbus-accessibility-strict @@ -0,0 +1,17 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2013 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + dbus send + bus=accessibility + path=/org/freedesktop/DBus + interface=org.freedesktop.DBus + member={Hello,AddMatch,RemoveMatch,GetNameOwner,NameHasOwner,StartServiceByName} + peer=(name=org.freedesktop.DBus), diff --git a/apparmor.d/abstractions/dbus-network-manager-strict b/apparmor.d/abstractions/dbus-network-manager-strict new file mode 100644 index 00000000..889a9a85 --- /dev/null +++ b/apparmor.d/abstractions/dbus-network-manager-strict @@ -0,0 +1,45 @@ +# vim:syntax=apparmor + + dbus send + bus=system + path=/org/freedesktop/NetworkManager + interface=org.freedesktop.DBus.Properties + member=GetAll + peer=(name=org.freedesktop.NetworkManager), + + dbus send + bus=system + path=/org/freedesktop/NetworkManager + interface=org.freedesktop.NetworkManager + member=GetDevices + peer=(name=org.freedesktop.NetworkManager), + + dbus send + bus=system + path=/org/freedesktop/NetworkManager/ActiveConnection/[0-9]* + interface=org.freedesktop.DBus.Properties + member=GetAll + peer=(name=org.freedesktop.NetworkManager), + + dbus send + bus=system + path=/org/freedesktop/NetworkManager/Devices/[0-9]* + interface=org.freedesktop.DBus.Properties + member=GetAll + peer=(name=org.freedesktop.NetworkManager), + + dbus send + bus=system + path=/org/freedesktop/NetworkManager/Settings + interface=org.freedesktop.NetworkManager.Settings + member={GetDevices,ListConnections} + peer=(name=org.freedesktop.NetworkManager), + + dbus send + bus=system + path=/org/freedesktop/NetworkManager/Settings/[0-9]* + interface=org.freedesktop.NetworkManager.Settings.Connection + member=GetSettings + peer=(name=org.freedesktop.NetworkManager), + + #include if exists diff --git a/apparmor.d/abstractions/dbus-session b/apparmor.d/abstractions/dbus-session new file mode 100644 index 00000000..eb1ed91e --- /dev/null +++ b/apparmor.d/abstractions/dbus-session @@ -0,0 +1,17 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2011-2013 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # This abstraction grants full session bus access. Consider using the + # dbus-session-strict abstraction for fine-grained bus mediation. + + #include + /usr/bin/dbus-launch ix, + dbus bus=session, diff --git a/apparmor.d/abstractions/dbus-session-strict b/apparmor.d/abstractions/dbus-session-strict new file mode 100644 index 00000000..1600554a --- /dev/null +++ b/apparmor.d/abstractions/dbus-session-strict @@ -0,0 +1,29 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2011-2013 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # unique per-machine identifier + /etc/machine-id r, + /var/lib/dbus/machine-id r, + owner /run/user/*/bus rw, + + unix (connect, receive, send) + type=stream + peer=(addr="@/tmp/dbus-*"), + + # dbus with systemd and --enable-user-session + owner /run/user/[0-9]*/bus rw, + + dbus send + bus=session + path=/org/freedesktop/DBus + interface=org.freedesktop.DBus + member={Hello,AddMatch,RemoveMatch,GetNameOwner,NameHasOwner,StartServiceByName} + peer=(name=org.freedesktop.DBus), diff --git a/apparmor.d/abstractions/dbus-strict b/apparmor.d/abstractions/dbus-strict new file mode 100644 index 00000000..01a426e4 --- /dev/null +++ b/apparmor.d/abstractions/dbus-strict @@ -0,0 +1,19 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009-2013 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /{,var/}run/dbus/system_bus_socket rw, + + dbus send + bus=system + path=/org/freedesktop/DBus + interface=org.freedesktop.DBus + member={Hello,AddMatch,RemoveMatch,GetNameOwner,NameHasOwner,StartServiceByName} + peer=(name=org.freedesktop.DBus), diff --git a/apparmor.d/abstractions/dconf b/apparmor.d/abstractions/dconf new file mode 100644 index 00000000..7ef69783 --- /dev/null +++ b/apparmor.d/abstractions/dconf @@ -0,0 +1,8 @@ +# vim:syntax=apparmor + +# permissions for querying dconf settings; granting write access should +# be specified in a specific application's profile. + + /etc/dconf/** r, + owner /{,var/}run/user/*/dconf/user r, + owner @{HOME}/.config/dconf/user r, diff --git a/apparmor.d/abstractions/dovecot-common b/apparmor.d/abstractions/dovecot-common new file mode 100644 index 00000000..e1681d9a --- /dev/null +++ b/apparmor.d/abstractions/dovecot-common @@ -0,0 +1,19 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2014 Canonical, Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ +# used with dovecot/* + + capability setgid, + + deny capability block_suspend, + + # dovecot's master can send us signals + signal receive peer=dovecot, + + /{var/,}run/dovecot/config rw, diff --git a/apparmor.d/abstractions/dri-common b/apparmor.d/abstractions/dri-common new file mode 100644 index 00000000..b5e0a5c5 --- /dev/null +++ b/apparmor.d/abstractions/dri-common @@ -0,0 +1,14 @@ +# vim:syntax=apparmor + +# This file contains common DRI-specific rules useful for GUI applications +# (needed by libdrm and similar). + + /usr/lib{,32,64}/dri/** mr, + /usr/lib/@{multiarch}/dri/** mr, + /usr/lib/fglrx/dri/** mr, + /dev/dri/ r, + /dev/dri/** rw, + /etc/drirc r, + /usr/share/drirc.d/{,*.conf} r, + owner @{HOME}/.drirc r, + diff --git a/apparmor.d/abstractions/dri-enumerate b/apparmor.d/abstractions/dri-enumerate new file mode 100644 index 00000000..e101be5c --- /dev/null +++ b/apparmor.d/abstractions/dri-enumerate @@ -0,0 +1,8 @@ +# vim:syntax=apparmor + +# This file contains common DRI-specific rules useful for GUI applications that +# needs to enumerate graphic devices (as with drmParsePciDeviceInfo() from +# libdrm). + + @{sys}/devices/pci[0-9]*/**/{device,subsystem_device,subsystem_vendor,uevent,vendor} r, + diff --git a/apparmor.d/abstractions/enchant b/apparmor.d/abstractions/enchant new file mode 100644 index 00000000..2a1bd05c --- /dev/null +++ b/apparmor.d/abstractions/enchant @@ -0,0 +1,59 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # abstraction for Enchant spellchecking frontend + + /usr/share/enchant/ r, + /usr/share/enchant/enchant.ordering r, + + /usr/share/enchant-2/ r, + /usr/share/enchant-2/enchant.ordering r, + + # aspell + #include + /var/lib/dictionaries-common/aspell/ r, + /var/lib/dictionaries-common/aspell/* r, + + # hspell + /usr/share/hspell/ r, + /usr/share/hspell/*.wgz.* r, + + # hunspell + /usr/share/hunspell/ r, + /usr/share/hunspell/* r, + + # ispell + /usr/lib/ispell/ r, + /usr/lib/ispell/*.hash r, + /usr/share/dict/ r, + /usr/share/dict/* r, + /var/lib/dictionaries-common/ r, + /var/lib/dictionaries-common/{ispell,wordlist}/ r, + /var/lib/dictionaries-common/{ispell,wordlist}/* r, + + # myspell + /usr/share/myspell/ r, + /usr/share/myspell/** r, + + # voikko + /usr/lib/voikko/ r, + /usr/lib/voikko/2/ r, + /usr/lib/voikko/2/mor-standard/ r, + /usr/lib/voikko/2/mor-standard/voikko* r, + + # zemberek + /usr/share/java/ r, + /usr/share/java/zemberek-[0-9]*.jar r, + /usr/share/java/zemberek-tr-[0-9]*.jar r, + + # per-user dictionaries + owner @{HOME}/.config/enchant/ rw, + owner @{HOME}/.config/enchant/* rwk, diff --git a/apparmor.d/abstractions/exo-open b/apparmor.d/abstractions/exo-open new file mode 100644 index 00000000..6b14afa5 --- /dev/null +++ b/apparmor.d/abstractions/exo-open @@ -0,0 +1,74 @@ +# vim:syntax=apparmor + +# This abstraction is designed to be used in a child profile to limit what +# confined application can invoke via exo-open helper. +# +# NOTE: most likely you want to use xdg-open abstraction instead for better +# portability across desktop environments, unless you are sure that confined +# application only uses /usr/bin/exo-open directly. +# +# Usage example: +# +# ``` +# profile foo /usr/bin/foo { +# ... +# /usr/bin/exo-open rPx -> foo//exo-open, +# ... +# } # end of main profile +# +# # out-of-line child profile +# profile foo//exo-open { +# #include +# +# # needed for ubuntu-* abstractions +# #include +# +# # Only allow to handle http[s]: and mailto: links +# #include +# #include +# +# # Add if accesibility access is considered as required +# # (for message boxe in case exo-open fails) +# #include +# +# # < add additional allowed applications here > +# } + + #include + #include # for alert messages + #include + #include + #include + + # Main executables + + /usr/bin/exo-open rix, + /usr/lib{32,64,/@{multiarch}}/xfce4/exo-[0-9]/exo-helper-[0-9] ix, + + # Other executables + + /{,usr/}bin/which rix, + + # Deny DBus + + # for GTK error message dialog, not required exo-open to work. + deny dbus send + bus=session + path=/org/gtk/vfs/mounttracker, + + # System files + + /etc/xdg/{,xdg-*/}xfce4/helpers.rc r, + /etc/xfce4/defaults.list r, # TODO: move into xfce4 abstraction? + /usr/share/sounds/freedesktop/** r, # for message box alert sound + /usr/share/xfce4/helpers/*.desktop r, + /usr/share/{xfce{,4},xubuntu}/applications/{,*.list} r, + + # User files + + owner @{PROC}/@{pid}/fd/ r, + owner @{HOME}/.config/xfce4/helpers.rc r, + owner @{HOME}/.local/share/xfce4/helpers/*.desktop r, + + # Include additions to the abstraction + #include if exists diff --git a/apparmor.d/abstractions/fcitx b/apparmor.d/abstractions/fcitx new file mode 100644 index 00000000..3d26cc95 --- /dev/null +++ b/apparmor.d/abstractions/fcitx @@ -0,0 +1,13 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2016 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + #include + dbus bus=fcitx, diff --git a/apparmor.d/abstractions/fcitx-strict b/apparmor.d/abstractions/fcitx-strict new file mode 100644 index 00000000..d7737341 --- /dev/null +++ b/apparmor.d/abstractions/fcitx-strict @@ -0,0 +1,21 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2016 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + #include + + dbus send + bus=fcitx + path=/org/freedesktop/DBus + interface=org.freedesktop.DBus + member={Hello,AddMatch,RemoveMatch,GetNameOwner,NameHasOwner,StartServiceByName} + peer=(name=org.freedesktop.DBus), + + owner @{HOME}/.config/fcitx/dbus/* r, diff --git a/apparmor.d/abstractions/fonts b/apparmor.d/abstractions/fonts new file mode 100644 index 00000000..5d7b173e --- /dev/null +++ b/apparmor.d/abstractions/fonts @@ -0,0 +1,61 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /usr/share/AbiSuite/fonts/** r, + + /usr/lib/xorg/modules/fonts/**.so* mr, + + /usr/share/fonts/{,**} r, + /usr/share/fonts-*/{,**} r, + + /etc/fonts/** r, + # Debian, openSUSE paths are different + /usr/share/{fontconfig,fonts-config,*-fonts}/conf.avail/{,**} r, + /usr/share/ghostscript/fonts/{,**} r, + + /opt/kde3/share/fonts/** r, + + /usr/lib{,32,64}/openoffice/share/fonts/** r, + + /var/cache/fonts/** r, + /var/cache/fontconfig/** mr, + /var/lib/defoma/** mr, + + /usr/share/a2ps/fonts/** r, + /usr/share/xfce/fonts/** r, + /usr/share/ghostscript/fonts/** r, + /usr/share/javascript/*/fonts/** r, + /usr/share/texmf/{,*/}fonts/** r, + /usr/share/texlive/texmf-dist/fonts/** r, + /var/lib/ghostscript/** r, + + owner @{HOME}/.fonts.conf r, + owner @{HOME}/.fonts/ r, + owner @{HOME}/.fonts/** r, + owner @{HOME}/.local/share/fonts/ r, + owner @{HOME}/.local/share/fonts/** r, + owner @{HOME}/.fonts.cache-2 mr, + owner @{HOME}/.{,cache/}fontconfig/ rw, + owner @{HOME}/.{,cache/}fontconfig/** mrl, + owner @{HOME}/.fonts.conf.d/ r, + owner @{HOME}/.fonts.conf.d/** r, + owner @{HOME}/.config/fontconfig/ r, + owner @{HOME}/.config/fontconfig/** r, + + /usr/local/share/fonts/ r, + /usr/local/share/fonts/** r, + + # poppler CMap tables + /usr/share/poppler/cMap/** r, + + # data files for LibThai + /usr/share/libthai/thbrk.tri r, diff --git a/apparmor.d/abstractions/freedesktop.org b/apparmor.d/abstractions/freedesktop.org new file mode 100644 index 00000000..ff974673 --- /dev/null +++ b/apparmor.d/abstractions/freedesktop.org @@ -0,0 +1,28 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # system configuration + @{system_share_dirs}/applications/{**,} r, + @{system_share_dirs}/icons/{**,} r, + @{system_share_dirs}/pixmaps/{**,} r, + + # this should probably go elsewhere + @{system_share_dirs}/mime/** r, + + # per-user configurations + owner @{HOME}/.icons/ r, + owner @{HOME}/.recently-used.xbel* rw, + owner @{HOME}/.local/share/recently-used.xbel* rw, + owner @{HOME}/.config/user-dirs.dirs r, + owner @{HOME}/.config/mimeapps.list r, + owner @{user_share_dirs}/applications/{**,} r, + owner @{user_share_dirs}/icons/{**,} r, + owner @{user_share_dirs}/mime/{**,} r, diff --git a/apparmor.d/abstractions/gio-open b/apparmor.d/abstractions/gio-open new file mode 100644 index 00000000..ec6b1873 --- /dev/null +++ b/apparmor.d/abstractions/gio-open @@ -0,0 +1,57 @@ +# vim:syntax=apparmor + +# This abstraction is designed to be used in a child profile to limit what +# confined application can invoke via gio helper. +# +# NOTE: most likely you want to use xdg-open abstraction instead for better +# portability across desktop environments, unless you are sure that confined +# application only uses /usr/bin/gio directly. +# +# Usage example: +# +# ``` +# profile foo /usr/bin/foo { +# ... +# /usr/bin/gio rPx -> foo//gio-open, +# ... +# } # end of main profile +# +# # out-of-line child profile +# profile foo//gio-open { +# #include +# +# # needed for ubuntu-* abstractions +# #include +# +# # Only allow to handle http[s]: and mailto: links +# #include +# #include +# +# # < add additional allowed applications here > +# } + + #include + #include + + # Main executables + + /usr/bin/gio rix, + /usr/bin/gio-launch-desktop ix, # for OpenSUSE + /usr/lib/@{multiarch}/glib-[0-9]*/gio-launch-desktop ix, + + # System files + + /etc/gnome/defaults.list r, + /usr/share/mime/* r, + /usr/share/{,*/}applications/{,**} r, + /var/cache/gio-[0-9]*.[0-9]*/gnome-mimeapps.list r, + /var/lib/snapd/desktop/applications/{,**} r, + + # User files + + owner @{HOME}/.config/mimeapps.list r, + owner @{HOME}/.local/share/applications/{,*.desktop} r, + owner @{PROC}/@{pid}/fd/ r, + + # Include additions to the abstraction + #include if exists diff --git a/apparmor.d/abstractions/gnome b/apparmor.d/abstractions/gnome new file mode 100644 index 00000000..5bb2fc26 --- /dev/null +++ b/apparmor.d/abstractions/gnome @@ -0,0 +1,111 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009-2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ +#include +#include +#include +#include +#include +#include +#include + + # systemwide gtk defaults + /etc/gnome/gtkrc* r, + /etc/gtk/* r, + /usr/lib{,32,64}/gtk/** mr, + /usr/lib/@{multiarch}/gtk/** mr, + /usr/lib{,32,64}/gtk-[0-9]*/** mr, + /usr/lib/@{multiarch}/gtk-[0-9]*/** mr, + /usr/share/themes/ r, + /usr/share/themes/** r, + /usr/share/gtk-3.0/settings.ini r, + + # for gnome 1 applications + /etc/orbitrc r, + + # gtk-2 needed some new rights + /etc/fonts/* r, + /etc/gtk-*/* r, + /etc/pango/* r, + /usr/lib{,32,64}/pango/** mr, + /usr/lib{,32,64}/gtk-*/** mr, + /usr/lib{,32,64}/gdk-pixbuf-*/** mr, + /usr/lib/@{multiarch}/pango/** mr, + /usr/lib/@{multiarch}/gtk-*/** mr, + /usr/lib/@{multiarch}/gdk-pixbuf-*/** mr, + + # per-user gtk configuration + owner @{HOME}/.config/gtk-3.0/ w, + owner @{HOME}/.config/gtk-3.0/* r, + owner @{HOME}/.gnome/Gnome r, + owner @{HOME}/.gtk r, + owner @{HOME}/.gtkrc r, + owner @{HOME}/.gtkrc-2.0 r, + owner @{HOME}/.gtk-bookmarks r, + owner @{HOME}/.themes/ r, + owner @{HOME}/.themes/** r, + owner @{user_share_dirs}/themes/ r, + owner @{user_share_dirs}/themes/** r, + + # for gtk file dialog + owner @{HOME}/.config/gtk-2.0/ w, + owner @{HOME}/.config/gtk-2.0/** r, + owner @{HOME}/.config/gtk-2.0/gtkfilechooser.ini* rw, + + # from evolution-mail + owner @{HOME}/.gconfd/lock/* r, + owner @{HOME}/.gnome/application-info r, + + # per-user font business + owner @{HOME}/.fonts.cache-* rwl, + + # GtkComposeTable + owner @{HOME}/.cache/gtk-3.0/** r, + + # icon caches + /var/cache/**/icon-theme.cache r, + /usr/share/**/icon-theme.cache r, + + # GLib schemas + /usr/{local/,}share/glib-[0-9]*/schemas/ r, + /usr/{local/,}share/glib-[0-9]*/schemas/** r, + + # gnome VFS modules + /etc/gnome-vfs-2.0/modules/ r, + /etc/gnome-vfs-2.0/modules/* r, + /usr/lib/gnome-vfs-2.0/modules/*.so mr, + /usr/lib/@{multiarch}/gnome-vfs-2.0/modules/*.so mr, + + # gvfs + /usr/share/gvfs/remote-volume-monitors/ r, + /usr/share/gvfs/remote-volume-monitors/* r, + @{PROC}/@{pid}/mounts r, + /run/mount/utab r, + + # printing + /etc/papersize r, + /etc/cups/lpoptions r, + /usr/share/cups/charmaps/** r, + + # holds MIT-MAGIC-COOKIE for gnome + owner /{,var/}run/gdm/auth*/database r, + + # mime-types + /etc/gnome/defaults.list r, + /etc/xdg/{,*-}mimeapps.list r, + /usr/share/gnome/applications/ r, + /usr/share/gnome/applications/mimeinfo.cache r, + + # Allow connecting to the GNOME vfs socket (still need corresponding DBus + # rules) + unix (send, receive, connect) + type=stream + peer=(addr="@/dbus-vfs-daemon/socket-*"), diff --git a/apparmor.d/abstractions/gnupg b/apparmor.d/abstractions/gnupg new file mode 100644 index 00000000..d04c920d --- /dev/null +++ b/apparmor.d/abstractions/gnupg @@ -0,0 +1,11 @@ +# vim:syntax=apparmor +# gnupg sub-process running permissions + + # user configurations + owner @{HOME}/.gnupg/options r, + owner @{HOME}/.gnupg/pubring.gpg r, + owner @{HOME}/.gnupg/pubring.kbx r, + owner @{HOME}/.gnupg/random_seed rw, + owner @{HOME}/.gnupg/secring.gpg r, + owner @{HOME}/.gnupg/so/*.x86_64 mr, + owner @{HOME}/.gnupg/trustdb.gpg rw, diff --git a/apparmor.d/abstractions/gvfs-open b/apparmor.d/abstractions/gvfs-open new file mode 100644 index 00000000..397423da --- /dev/null +++ b/apparmor.d/abstractions/gvfs-open @@ -0,0 +1,45 @@ +# vim:syntax=apparmor + +# This abstraction is designed to be used in a child profile to limit what +# confined application can invoke via gvfs-open helper. +# +# NOTE: most likely you want to use xdg-open abstraction instead for better +# portability across desktop environments, unless you are sure that confined +# application only uses /usr/bin/gvfs-open directly. +# +# Usage example: +# +# ``` +# profile foo /usr/bin/foo { +# ... +# /usr/bin/gvfs-open rPx -> foo//gvfs-open, +# ... +# } # end of main profile +# +# # out-of-line child profile +# profile foo//gvfs-open { +# #include +# +# # needed for ubuntu-* abstractions +# #include +# +# # Only allow to handle http[s]: and mailto: links +# #include +# #include +# +# # < add additional allowed applications here > +# } +# ``` + + #include + + # gvfs-open is deprecated, it launches gio open + #include + + # Main executables + + /usr/bin/gvfs-open r, + /{,usr/}bin/dash mr, + + # Include additions to the abstraction + #include if exists diff --git a/apparmor.d/abstractions/hosts_access b/apparmor.d/abstractions/hosts_access new file mode 100644 index 00000000..a4ffb022 --- /dev/null +++ b/apparmor.d/abstractions/hosts_access @@ -0,0 +1,13 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2020 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /etc/hosts.deny r, + /etc/hosts.allow r, diff --git a/apparmor.d/abstractions/ibus b/apparmor.d/abstractions/ibus new file mode 100644 index 00000000..a4431b99 --- /dev/null +++ b/apparmor.d/abstractions/ibus @@ -0,0 +1,29 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # abstraction for ibus input methods + owner @{HOME}/.config/ibus/ r, + owner @{HOME}/.config/ibus/bus/ rw, + owner @{HOME}/.config/ibus/bus/* rw, + + # abstract path in ibus < 1.5.22 uses /tmp + unix (connect, receive, send) + type=stream + peer=(addr="@/tmp/ibus/dbus-*"), + + # abstract path in ibus >= 1.5.22 uses $XDG_CACHE_HOME (ie, @{HOME}/.cache) + # This should use this, but due to LP: #1856738 we cannot + #unix (connect, receive, send) + # type=stream + # peer=(addr="@@{HOME}/.cache/ibus/dbus-*"), + unix (connect, receive, send) + type=stream + peer=(addr="@/home/*/.cache/ibus/dbus-*"), diff --git a/apparmor.d/abstractions/kde b/apparmor.d/abstractions/kde new file mode 100644 index 00000000..cad5c7db --- /dev/null +++ b/apparmor.d/abstractions/kde @@ -0,0 +1,77 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2009-2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +#include +#include +#include +#include +#include +#include +#include + +/etc/qt3/kstylerc r, +/etc/qt3/qt_plugins_3.3rc r, +/etc/qt3/qtrc r, +/etc/kderc r, +/etc/kde3/* r, +/etc/kde4rc r, +/etc/xdg/kdeglobals r, +/etc/xdg/Trolltech.conf r, +/usr/share/knotifications5/*.notifyrc r, # KNotification::sendEvent() +/usr/share/kubuntu-default-settings/kf5-settings/* r, + +owner @{HOME}/.DCOPserver_* r, +owner @{HOME}/.ICEauthority r, +owner @{HOME}/.fonts.* lrw, +owner @{HOME}/.kde{,4}/share/config/kdeglobals rw, +owner @{HOME}/.kde{,4}/share/config/*.lock rwl, +owner @{HOME}/.qt/** rw, +owner @{HOME}/.cache/ksycoca5_??_* r, # KDE System Configuration Cache +owner @{HOME}/.config/Trolltech.conf rwk, +owner @{HOME}/.config/baloofilerc r, # indexing options (excludes, etc), used by KFileWidget +owner @{HOME}/.config/dolphinrc r, # settings used by KFileWidget +owner @{HOME}/.config/kde.org/libphonon.conf r, # for KNotifications::sendEvent() +owner @{HOME}/.config/kdeglobals r, # global settings, used by Breeze style, etc. +owner @{HOME}/.config/klanguageoverridesrc r, # per-application languages, for KDEPrivate::initializeLanguages() from libKF5XmlGui.so +owner @{HOME}/.config/trashrc r, # Used by KFileWidget + +/usr/share/X11/XKeysymDB r, + +# kde3 +/usr/lib*/kde3/plugins/styles/ r, +/usr/lib*/kde3/plugins/styles/* mr, +/usr/lib*/kde3/lib*so* mr, +/usr/lib/@{multiarch}/kde3/plugins/styles/ r, +/usr/lib/@{multiarch}/kde3/plugins/styles/* mr, +/usr/lib/@{multiarch}/kde3/lib*so* mr, +/usr/lib*/qt3/lib*/lib*so* mr, +/usr/lib*/qt3/plugins/** mr, +/usr/lib/@{multiarch}/qt3/lib*/lib*so* mr, +/usr/lib/@{multiarch}/qt3/plugins/** mr, +/usr/lib*/libqt-mt*so* mr, +/usr/lib*/libqui*so* mr, +/usr/lib/@{multiarch}/libqt-mt*so* mr, +/usr/lib/@{multiarch}/libqui*so* mr, +/usr/share/qt3/lib*/libqt-mt*so* mr, +/usr/share/qt3/lib*/libqui*so* mr, + +# kde4 +/usr/lib*/kde4/plugins/*/*.so mr, +/usr/lib*/kde4/plugins/*/ r, +/usr/lib*/kde4/lib*so* mr, +/usr/lib/@{multiarch}/kde4/plugins/*/*.so mr, +/usr/lib/@{multiarch}/kde4/plugins/*/ r, +/usr/lib/@{multiarch}/kde4/lib*so* mr, +/usr/lib*/qt4/lib*/lib*so* mr, +/usr/lib*/qt4/plugins/** mr, +/usr/lib/@{multiarch}/qt4/lib*/lib*so* mr, +/usr/lib/@{multiarch}/qt4/plugins/** mr, +/usr/share/qt4/** r, diff --git a/apparmor.d/abstractions/kde-globals-write b/apparmor.d/abstractions/kde-globals-write new file mode 100644 index 00000000..5f878e84 --- /dev/null +++ b/apparmor.d/abstractions/kde-globals-write @@ -0,0 +1,10 @@ +# vim:syntax=apparmor +# Rules for changing KDE settings (for KFileDialog and other). + + # User files + + owner @{HOME}/.config/#[0-9]* rw, + owner @{HOME}/.config/kdeglobals rw, + owner @{HOME}/.config/kdeglobals.?????? rwl -> @{HOME}/.config/#[0-9]*, + owner @{HOME}/.config/kdeglobals.lock rwk, + diff --git a/apparmor.d/abstractions/kde-icon-cache-write b/apparmor.d/abstractions/kde-icon-cache-write new file mode 100644 index 00000000..d37fb3b8 --- /dev/null +++ b/apparmor.d/abstractions/kde-icon-cache-write @@ -0,0 +1,7 @@ +# vim:syntax=apparmor +# Rules for writing KDE icon cache + + # User files + + owner @{HOME}/.cache/icon-cache.kcache rw, # for KIconLoader + diff --git a/apparmor.d/abstractions/kde-language-write b/apparmor.d/abstractions/kde-language-write new file mode 100644 index 00000000..8e953992 --- /dev/null +++ b/apparmor.d/abstractions/kde-language-write @@ -0,0 +1,12 @@ +# vim:syntax=apparmor +# Rules for changing per-application language settings on KDE. Some KDE +# applications have "Help -> Switch Application Language..." option, that needs +# write access to language settings file. + + # User files + + owner @{HOME}/.config/#[0-9]* rw, + owner @{HOME}/.config/klanguageoverridesrc rw, + owner @{HOME}/.config/klanguageoverridesrc.?????? rwl -> @{HOME}/.config/#[0-9]*, + owner @{HOME}/.config/klanguageoverridesrc.lock rwk, + diff --git a/apparmor.d/abstractions/kde-open5 b/apparmor.d/abstractions/kde-open5 new file mode 100644 index 00000000..4fb651ea --- /dev/null +++ b/apparmor.d/abstractions/kde-open5 @@ -0,0 +1,104 @@ +# vim:syntax=apparmor + +# This abstraction is designed to be used in a child profile to limit what +# confined application can invoke via kde-open5 helper. +# +# NOTE: most likely you want to use xdg-open abstraction instead for better +# portability across desktop environments, unless you are sure that confined +# application only uses /usr/bin/kde-open5 directly. +# +# Usage example: +# +# ``` +# profile foo /usr/bin/foo { +# ... +# /usr/bin/kde-open5 rPx -> foo//kde-open5, +# ... +# } # end of main profile +# +# # out-of-line child profile +# profile foo//kde-open5 { +# #include +# +# # needed for ubuntu-* abstractions +# #include +# +# # Only allow to handle http[s]: and mailto: links +# #include +# #include +# +# # Add if accesibility access is considered as required +# # (for message boxe in case exo-open fails) +# #include +# +# # Add if audio support for message box is +# # considered as required. +# #include if exists +# +# # < add additional allowed applications here > +# } +# ``` + + #include # for alert messages + #include + #include + #include + #include + #include + #include + #include + #include # for IceProcessMessages () from libICE.so (called by libQtCore.so) + #include + #include + #include + #include + + # Main executables + + /usr/bin/kde-open5 rix, + /usr/lib/@{multiarch}/libexec/kf5/kioslave{,5} ix, + + # DBus + + dbus + bus=session + interface=org.kde.KLauncher + member=start_service_by_desktop_path + peer=(name=org.kde.klauncher5), + + # Denied system files + + deny /usr/lib/vlc/plugins/* w, # VLC backed tries to create plugins.dat.16109 + + # libpcre2 on openSUSE tries to mmap() shared memory on directory. + # see: https://lists.ubuntu.com/archives/apparmor/2019-January/011925.html + # AppArmor does not allow to distinguish "real" file vs shared memory one, + # so we deny this path to protect from loading exploits from /tmp. + deny /tmp/#[0-9]*[0-9] m, + + # System files + + /dev/tty r, + /etc/xdg/accept-languages.codes r, + /etc/xdg/menus/{,*/} r, + /usr/share/*fonts*/conf.avail/*.conf r, # for openSUSE, when showing error message box + /usr/share/ghostscript/fonts/ r, # for openSUSE, when showing error message box + /usr/share/hwdata/pnp.ids r, # for openSUSE, when showing error message box, for QXcbConnection::initializeScreens() from libQt5XcbQpa.so + /usr/share/icu/[0-9]*.[0-9]*/*.dat r, # for openSUSE + /usr/share/kservices5/{,**} r, # for KProtocolManager::defaultUserAgent() from libKF5KIOCore.so + /usr/share/mime/ r, + /usr/share/mime/generic-icons r, + /usr/share/plasma/look-and-feel/*/contents/defaults r, # TODO: move to kde abstraction? + /usr/share/sounds/ r, + @{PROC}/sys/kernel/core_pattern r, + @{PROC}/sys/kernel/random/boot_id r, + + # User files + + owner /tmp/xauth-[0-9]*-_[0-9] r, # for libQt5XcbQpa.so + owner /{,var/}run/user/[0-9]*/#[0-9]* rw, # for /run/user/1000/#13 + owner /{,var/}run/user/[0-9]*/kioclient*slave-socket lrw -> /{,var/}/run/user/[0-9]/#[0-9]*, # for KIO::Slave::holdSlave(QString const&, QUrl const&) () from libKF5KIOCore.so (not 100% sure) + owner @{HOME}/.cache/kio_http/ rw, + + # Include additions to the abstraction + #include if exists diff --git a/apparmor.d/abstractions/kerberosclient b/apparmor.d/abstractions/kerberosclient new file mode 100644 index 00000000..5b79e3d6 --- /dev/null +++ b/apparmor.d/abstractions/kerberosclient @@ -0,0 +1,34 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009-2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # files required by kerberos client programs + /usr/lib{,32,64}/krb5/plugins/libkrb5/ r, + /usr/lib{,32,64}/krb5/plugins/libkrb5/* mr, + /usr/lib/@{multiarch}/krb5/plugins/libkrb5/ r, + /usr/lib/@{multiarch}/krb5/plugins/libkrb5/* mr, + + /usr/lib{,32,64}/krb5/plugins/preauth/ r, + /usr/lib{,32,64}/krb5/plugins/preauth/* mr, + /usr/lib/@{multiarch}/krb5/plugins/preauth/ r, + /usr/lib/@{multiarch}/krb5/plugins/preauth/* mr, + + /etc/krb5.keytab rk, + /etc/krb5.conf r, + /etc/krb5.conf.d/ r, + /etc/krb5.conf.d/* r, + + # config files found via strings on libs + /etc/krb.conf r, + /etc/krb.realms r, + /etc/srvtab r, + + # credential caches + /tmp/krb5cc* r, diff --git a/apparmor.d/abstractions/ldapclient b/apparmor.d/abstractions/ldapclient new file mode 100644 index 00000000..0c527282 --- /dev/null +++ b/apparmor.d/abstractions/ldapclient @@ -0,0 +1,24 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2011 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # files required by LDAP clients (e.g. nss_ldap/pam_ldap) + /etc/ldap.conf r, + /etc/ldap.secret r, + /etc/openldap/* r, + /etc/openldap/cacerts/* r, + + # SASL plugins and config + /etc/sasl2/* r, + /usr/lib{,32,64}/sasl2/* r, + + # local LDAP name service daemon + /{,var/}run/nslcd/socket rw, + + #include diff --git a/apparmor.d/abstractions/libpam-systemd b/apparmor.d/abstractions/libpam-systemd new file mode 100644 index 00000000..76ee8693 --- /dev/null +++ b/apparmor.d/abstractions/libpam-systemd @@ -0,0 +1,19 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2015-2016 Simon Deziel +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +#include + + # libpam-systemd notifies systemd-logind about session logins/logouts + dbus send + bus=system + path=/org/freedesktop/login1 + interface=org.freedesktop.login1.Manager + member={CreateSession,ReleaseSession}, diff --git a/apparmor.d/abstractions/likewise b/apparmor.d/abstractions/likewise new file mode 100644 index 00000000..7482842a --- /dev/null +++ b/apparmor.d/abstractions/likewise @@ -0,0 +1,13 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /tmp/.lwidentity/pipe rw, + /var/lib/likewise-open/lwidentity_privileged/pipe rw, diff --git a/apparmor.d/abstractions/mdns b/apparmor.d/abstractions/mdns new file mode 100644 index 00000000..14c31b8c --- /dev/null +++ b/apparmor.d/abstractions/mdns @@ -0,0 +1,14 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # mdnsd + /etc/mdns.allow r, + /etc/nss_mdns.conf r, + /{,var/}run/mdnsd w, diff --git a/apparmor.d/abstractions/mesa b/apparmor.d/abstractions/mesa new file mode 100644 index 00000000..be699c77 --- /dev/null +++ b/apparmor.d/abstractions/mesa @@ -0,0 +1,17 @@ +# vim:syntax=apparmor +# Rules for Mesa implementation of the OpenGL API + + # System files + /dev/dri/ r, # libGLX_mesa.so calls drmGetDevice2() + + # Needed to check if the kernel supports the i915 perf interface + # (src/intel/perf/gen_perf.c, load_oa_metrics()) + @{PROC}/sys/dev/i915/perf_stream_paranoid r, + + # User files + owner @{HOME}/.cache/ w, # if user clears all caches + owner @{HOME}/.cache/mesa_shader_cache/ w, + owner @{HOME}/.cache/mesa_shader_cache/index rw, + owner @{HOME}/.cache/mesa_shader_cache/??/ w, + owner @{HOME}/.cache/mesa_shader_cache/??/* rwk, + diff --git a/apparmor.d/abstractions/mir b/apparmor.d/abstractions/mir new file mode 100644 index 00000000..16c57ec3 --- /dev/null +++ b/apparmor.d/abstractions/mir @@ -0,0 +1,17 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2015 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # mir libraries sometimes do not have a lib prefix + # see LP: #1422521 + /usr/lib/@{multiarch}/mir/*.so* mr, + /usr/lib/@{multiarch}/mir/**/*.so* mr, + + # unprivileged mir socket for clients diff --git a/apparmor.d/abstractions/mozc b/apparmor.d/abstractions/mozc new file mode 100644 index 00000000..f736bc26 --- /dev/null +++ b/apparmor.d/abstractions/mozc @@ -0,0 +1,12 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2016 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + unix (connect, receive, send) type=stream peer=(addr="@tmp/.mozc.*"), diff --git a/apparmor.d/abstractions/mysql b/apparmor.d/abstractions/mysql new file mode 100644 index 00000000..fed759bb --- /dev/null +++ b/apparmor.d/abstractions/mysql @@ -0,0 +1,15 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2013 Christian Boltz +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /var/lib/mysql{,d}/mysql{,d}.sock rw, + /{var/,}run/mysql{,d}/mysql{,d}.sock rw, + /usr/share/{mysql,mysql-community-server,mariadb}/charsets/ r, + /usr/share/{mysql,mysql-community-server,mariadb}/charsets/*.xml r, diff --git a/apparmor.d/abstractions/nameservice b/apparmor.d/abstractions/nameservice new file mode 100644 index 00000000..a78a874d --- /dev/null +++ b/apparmor.d/abstractions/nameservice @@ -0,0 +1,106 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009-2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # Many programs wish to perform nameservice-like operations, such as + # looking up users by name or id, groups by name or id, hosts by name + # or IP, etc. These operations may be performed through files, dns, + # NIS, NIS+, LDAP, hesiod, wins, etc. Allow them all here. + /etc/group r, + /etc/host.conf r, + /etc/hosts r, + /etc/nsswitch.conf r, + /etc/gai.conf r, + /etc/passwd r, + /etc/protocols r, + + # libtirpc (used for NIS/YP login) needs this + /etc/netconfig r, + + # When using libnss-extrausers, the passwd and group files are merged from + # an alternate path + /var/lib/extrausers/group r, + /var/lib/extrausers/passwd r, + + # NSS records from systemd-userdbd.service + @{run}/systemd/userdb/ r, + @{run}/systemd/userdb/io.systemd.{NameServiceSwitch,Multiplexer,DynamicUser,Home} r, + @{PROC}/sys/kernel/random/boot_id r, + + # When using sssd, the passwd and group files are stored in an alternate path + # and the nss plugin also needs to talk to a pipe + /var/lib/sss/mc/group r, + /var/lib/sss/mc/initgroups r, + /var/lib/sss/mc/passwd r, + /var/lib/sss/pipes/nss rw, + + /etc/resolv.conf r, + # On systems where /etc/resolv.conf is managed programmatically, it is + # a symlink to /{,var/}run/(whatever program is managing it)/resolv.conf. + /{,var/}run/{resolvconf,NetworkManager,systemd/resolve,connman,netconfig}/resolv.conf r, + /etc/resolvconf/run/resolv.conf r, + /{,var/}run/systemd/resolve/stub-resolv.conf r, + + /etc/samba/lmhosts r, + /etc/services r, + # db backend + /var/lib/misc/*.db r, + # The Name Service Cache Daemon can cache lookups, sometimes leading + # to vast speed increases when working with network-based lookups. + /{,var/}run/.nscd_socket rw, + /{,var/}run/nscd/socket rw, + /{var/db,var/cache,var/lib,var/run,run}/nscd/{passwd,group,services,hosts} r, + # nscd renames and unlinks files in it's operation that clients will + # have open + /{,var/}run/nscd/db* rmix, + + # The nss libraries are sometimes used in addition to PAM; make sure + # they are available + /{usr/,}lib{,32,64}/libnss_*.so* mr, + /{usr/,}lib/@{multiarch}/libnss_*.so* mr, + /etc/default/nss r, + + # avahi-daemon is used for mdns4 resolution + /{,var/}run/avahi-daemon/socket rw, + + # libnl-3-200 via libnss-gw-name + @{PROC}/@{pid}/net/psched r, + /etc/libnl-*/classid r, + + # nis + #include + + # ldap + #include + + # winbind + #include + + # likewise + #include + + # mdnsd + #include + + # kerberos + #include + + # TCP/UDP network access + network inet stream, + network inet6 stream, + network inet dgram, + network inet6 dgram, + + # TODO: adjust when support finer-grained netlink rules + # Netlink raw needed for nscd + network netlink raw, + + # interface details + @{PROC}/@{pid}/net/route r, diff --git a/apparmor.d/abstractions/nis b/apparmor.d/abstractions/nis new file mode 100644 index 00000000..690e6796 --- /dev/null +++ b/apparmor.d/abstractions/nis @@ -0,0 +1,15 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # NIS rules + /var/yp/binding/* r, + # portmapper may ask root processes to do nis/ldap at low ports + capability net_bind_service, + diff --git a/apparmor.d/abstractions/nvidia b/apparmor.d/abstractions/nvidia new file mode 100644 index 00000000..b01ef8b5 --- /dev/null +++ b/apparmor.d/abstractions/nvidia @@ -0,0 +1,28 @@ +# vim:syntax=apparmor +# nvidia access requirements + + # configuration queries + capability ipc_lock, + + /usr/share/nvidia/nvidia-application-profiles* r, + + # libvdpau config file for nvidia workarounds + /etc/vdpau_wrapper.cfg r, + + # device files + /dev/nvidiactl rw, + /dev/nvidia-modeset rw, + /dev/nvidia[0-9]* rw, + + @{PROC}/interrupts r, + @{PROC}/sys/vm/max_map_count r, + @{PROC}/driver/nvidia/params r, + @{PROC}/modules r, + + @{sys}/devices/system/memory/block_size_bytes r, + + owner @{HOME}/.nv/ w, + owner @{HOME}/.nv/GLCache/ rw, + owner @{HOME}/.nv/GLCache/** rwk, + + unix (send, receive) type=dgram peer=(addr="@nvidia[0-9a-f]*"), diff --git a/apparmor.d/abstractions/opencl b/apparmor.d/abstractions/opencl new file mode 100644 index 00000000..32a21b2a --- /dev/null +++ b/apparmor.d/abstractions/opencl @@ -0,0 +1,9 @@ +# vim:syntax=apparmor +# OpenCL access requirements + + # TODO: use conditionals to select allowed implementations + #include + #include + #include + #include + diff --git a/apparmor.d/abstractions/opencl-common b/apparmor.d/abstractions/opencl-common new file mode 100644 index 00000000..0ad3d559 --- /dev/null +++ b/apparmor.d/abstractions/opencl-common @@ -0,0 +1,10 @@ +# vim:syntax=apparmor +# implementation-independent OpenCL access requirements + + # System files + + /etc/OpenCL/** r, + @{sys}/bus/pci/devices/ r, # libpocl.so -> libhwlock.so, libnvidia-opencl.so, beignet/libcl.so -> libdrm_intel.so + @{sys}/devices/system/node/ r, # for clGetPlatformIDs() from libOpenCL.so + @{sys}/devices/system/node/node[0-9]*/meminfo r, # for clGetPlatformIDs() from libOpenCL.so + diff --git a/apparmor.d/abstractions/opencl-intel b/apparmor.d/abstractions/opencl-intel new file mode 100644 index 00000000..353eeca2 --- /dev/null +++ b/apparmor.d/abstractions/opencl-intel @@ -0,0 +1,17 @@ +# vim:syntax=apparmor +# OpenCL access requirements for Intel implementation + + #include + + # for libcl.so (libOpenCL.so -> beignet/libcl.so calls XOpenDisplay()) + #include + + # for libOpenCL.so -> beignet/libcl.so -> libpciaccess.so + #include + + # System files + + /dev/dri/card[0-9]* rw, # beignet/libcl.so + @{sys}/devices/pci[0-9]*/**/{class,config,resource,revision} r, # libcl.so -> libdrm_intel.so -> libpciaccess.so (move to dri-enumerate ?) + /usr/lib/@{multiarch}/beignet/** r, + diff --git a/apparmor.d/abstractions/opencl-mesa b/apparmor.d/abstractions/opencl-mesa new file mode 100644 index 00000000..9d7f82b2 --- /dev/null +++ b/apparmor.d/abstractions/opencl-mesa @@ -0,0 +1,20 @@ +# vim:syntax=apparmor +# OpenCL access requirements for Mesa implementation + + #include + + # Additional libraries + + /usr/lib/@{multiarch}/gallium-pipe/*.so mr, # libMesaOpenCL.so + /usr/lib{,64}/gallium-pipe/*.so mr, # libMesaOpenCL.so on openSUSE + + # System files + + /dev/dri/ r, # libMesaOpenCL.so -> libdrm.so + /dev/dri/render* rw, # libMesaOpenCL.so + /etc/drirc r, # libMesaOpenCL.so + + # User files + + owner @{HOME}/.cache/mesa_shader_cache/{,**} rw, # libMesaOpenCL.so -> pipe_nouveau.so + diff --git a/apparmor.d/abstractions/opencl-nvidia b/apparmor.d/abstractions/opencl-nvidia new file mode 100644 index 00000000..8a4764ec --- /dev/null +++ b/apparmor.d/abstractions/opencl-nvidia @@ -0,0 +1,30 @@ +# vim:syntax=apparmor +# OpenCL access requirements for NVIDIA implementation + + #include + #include + + # Executables + + # https://github.com/NVIDIA/nvidia-modprobe + # This setuid executable is used to create various device files and load the + # the nvidia kernel module. + /usr/bin/nvidia-modprobe Px -> nvidia_modprobe, + + # System files + + # libnvidia-opencl.so rules: + /dev/nvidia-uvm rw, + /dev/nvidia-uvm-tools rw, + @{sys}/devices/pci[0-9]*/**/config r, + @{sys}/devices/system/memory/block_size_bytes r, + /usr/share/nvidia/** r, + @{PROC}/devices r, + @{PROC}/sys/vm/mmap_min_addr r, + + # User files + + owner @{HOME}/.nv/ComputeCache/ w, + owner @{HOME}/.nv/ComputeCache/** rw, + owner @{HOME}/.nv/ComputeCache/index rwk, + diff --git a/apparmor.d/abstractions/opencl-pocl b/apparmor.d/abstractions/opencl-pocl new file mode 100644 index 00000000..054689ab --- /dev/null +++ b/apparmor.d/abstractions/opencl-pocl @@ -0,0 +1,76 @@ +# vim:syntax=apparmor +# OpenCL access requirements for POCL implementation + + #include + + # Executables + + /usr/bin/{,@{multiarch}-}ld.bfd Cx -> opencl_pocl_ld, + /usr/lib/llvm-[0-9]*.[0-9]*/bin/clang Cx -> opencl_pocl_clang, + + # System files + + / r, # libpocl.so -> libhwloc.so + @{sys}/bus/pci/slots/ r, # libpocl.so -> hwloc_topology_load() from libhwloc.so + @{sys}/bus/{cpu,node}/devices/ r, # libpocl.so -> libhwlock.so + @{sys}/class/net/ r, # libpocl.so -> hwloc_pci_traverse_lookuposdevices_cb() from libhwloc.so + @{sys}/devices/pci[0-9]*/**/ r, # for libpocl -> hwloc_linux_lookup_block_class() from libhwloc.so + @{sys}/devices/pci[0-9]*/**/block/*/dev r, # libpocl.so -> hwloc_linux_lookup_host_block_class() from libhwloc.so + @{sys}/devices/pci[0-9]*/**/{class,local_cpus} r, # libpocl.so -> libhwlock.so + @{sys}/devices/pci[0-9]*/*/net/*/address r, # libpocl.so -> hwloc_pci_traverse_lookuposdevices_cb() from libhwloc.so + @{sys}/devices/system/cpu/ r, # libpocl.so -> libnuma.so + @{sys}/devices/system/cpu/cpu[0-9]*/cache/index[0-9]*/* r, # libpocl.so -> libhwloc.so + @{sys}/devices/system/cpu/cpu[0-9]*/online r, # libpocl.so -> libhwlock.so + @{sys}/devices/system/cpu/cpu[0-9]*/topology/* r, # *_siblings, physical_package_id and lot's of others, for libpocl.so -> libhwloc.so + @{sys}/devices/system/cpu/cpufreq/policy[0-9]*/* r, # for clGetPlatformIDs() from libpocl.so + @{sys}/devices/system/cpu/possible r, # libpocl.so -> libhwloc.so + @{sys}/devices/virtual/dmi/id/{,*} r, # libpocl.so -> libhwloc.so + @{sys}/fs/cgroup/cpuset/cpuset.{cpus,mems} r, # libpocl.so -> libhwloc.so + @{sys}/kernel/mm/hugepages{/,/**} r, # libpocl.so -> libhwloc.so + /usr/share/pocl/** r, + /{,var/}run/udev/data/*:* r, # libpocl.so -> hwloc_linux_block_class_fillinfos() from libhwloc.so + + # User files + + owner @{HOME}/.cache/pocl/ w, + owner @{HOME}/.cache/pocl/kcache/ w, + owner @{HOME}/.cache/pocl/kcache/** rw, + owner @{HOME}/.cache/pocl/kcache/**.so mrw, # dangerous! + owner @{PROC}/@{pid}/{cgroup,cpuset,status} r, # libpocl.so -> libhwloc.so, status for libpocl.so -> libnuma.so + + # Child profiles + + profile opencl_pocl_ld { + #include + + # Main executables + + /usr/bin/{,@{multiarch}-}ld.bfd mr, + + # User files + + owner @{HOME}/.cache/pocl/kcache/tempfile*.so rw, + owner @{HOME}/.cache/pocl/kcache/**.so.o r, + } + + profile opencl_pocl_clang { + #include + + # Main executables + + /usr/lib/llvm-[0-9]*.[0-9]*/bin/clang mr, + + # Additional executables + + /usr/bin/{,@{multiarch}-}ld.bfd ix, # TODO: transfer to opencl_ld child profile? + + # System files + + /etc/debian-version r, + /etc/lsb-release r, + + # User files + + owner @{HOME}/.cache/pocl/kcache/*/*/*/*/*.so{,.o} rw, + } + diff --git a/apparmor.d/abstractions/openssl b/apparmor.d/abstractions/openssl new file mode 100644 index 00000000..697da7ae --- /dev/null +++ b/apparmor.d/abstractions/openssl @@ -0,0 +1,14 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2011 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /etc/ssl/openssl.cnf r, + /usr/share/ssl/openssl.cnf r, + @{PROC}/sys/crypto/fips_enabled r, + diff --git a/apparmor.d/abstractions/orbit2 b/apparmor.d/abstractions/orbit2 new file mode 100644 index 00000000..b8df9df6 --- /dev/null +++ b/apparmor.d/abstractions/orbit2 @@ -0,0 +1,5 @@ +# vim:syntax=apparmor +# orbit2 permissions + + # system library + /usr/lib/orbit-2.0/*.so mr, diff --git a/apparmor.d/abstractions/p11-kit b/apparmor.d/abstractions/p11-kit new file mode 100644 index 00000000..84b7b11d --- /dev/null +++ b/apparmor.d/abstractions/p11-kit @@ -0,0 +1,27 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /etc/pkcs11/ r, + /etc/pkcs11/pkcs11.conf r, + /etc/pkcs11/modules/ r, + /etc/pkcs11/modules/* r, + + /usr/lib{,32,64}/pkcs11/*.so mr, + /usr/lib/@{multiarch}/pkcs11/*.so mr, + + /usr/share/p11-kit/modules/ r, + /usr/share/p11-kit/modules/* r, + + # gnome-keyring pkcs11 module + owner /{,var/}run/user/[0-9]*/keyring*/pkcs11 rw, + + # p11-kit also supports reading user configuration from ~/.pkcs11 depending + # on how /etc/pkcs11/pkcs11.conf is configured. This should generally not be + # included in this abstraction. diff --git a/apparmor.d/abstractions/perl b/apparmor.d/abstractions/perl new file mode 100644 index 00000000..0e20aeb5 --- /dev/null +++ b/apparmor.d/abstractions/perl @@ -0,0 +1,23 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # a few files typically required for perl scripts + /usr/bin/perl rmix, + /usr/bin/perl[0-9].[0-9].[0-9] rmix, + + /usr/lib{,32,64}/perl5/** r, + /usr/lib{,32,64}/perl{,5}/**.so* mr, + /usr/lib/@{multiarch}/perl{,5,-base}/** r, + /usr/lib/@{multiarch}/perl{,5,-base}/[0-9]*/**.so* mr, + + /usr/share/perl/** r, + /usr/share/perl5/** r, + /etc/perl/** r, diff --git a/apparmor.d/abstractions/php b/apparmor.d/abstractions/php new file mode 100644 index 00000000..4aba2415 --- /dev/null +++ b/apparmor.d/abstractions/php @@ -0,0 +1,39 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2009-2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # shared snippets for config files + /etc/php{,5,7}/**/ r, + /etc/php{,5,7}/**.ini r, + + # Xlibs + /usr/X11R6/lib{,32,64}/lib*.so* mr, + # php extensions + /usr/lib{64,}/php{,5,7}/*/*.so mr, + + # ICU (unicode support) data tables + /usr/share/icu/*/*.dat r, + + # php session mmap socket + /var/lib/php{,5,7}/session_mm_* rwlk, + # file based session handler + /var/lib/php{,5,7}/sess_* rwlk, + /var/lib/php{,5,7}/sessions/* rwlk, + + # php libraries + /usr/share/php{,5,7}/ r, + /usr/share/php{,5,7}/** mr, + + # MySQL extension + /usr/share/mysql/** r, + + # Zend opcache + /tmp/.ZendSem.* rwlk, diff --git a/apparmor.d/abstractions/php5 b/apparmor.d/abstractions/php5 new file mode 100644 index 00000000..9f5355f9 --- /dev/null +++ b/apparmor.d/abstractions/php5 @@ -0,0 +1,3 @@ +#backwards compatibility include, actual abstraction moved from php5 to php + +#include diff --git a/apparmor.d/abstractions/postfix-common b/apparmor.d/abstractions/postfix-common new file mode 100644 index 00000000..b10f888f --- /dev/null +++ b/apparmor.d/abstractions/postfix-common @@ -0,0 +1,39 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2005 Novell/SUSE +# Copyright (C) 2015-2018 Canonical, Ltd. +# Copyright (C) 2020 Christian Boltz +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ +# used with postfix/* + + + capability setuid, + capability setgid, + capability sys_chroot, + + # postfix's master can send us signals + signal receive peer=/usr/lib/postfix/master, + signal receive peer=postfix-master, + + unix (send, receive) peer=(label=/usr/lib/postfix/master), + unix (send, receive) peer=(label=postfix-master), + + /etc/mailname r, + /etc/postfix/*.cf r, + /etc/postfix/*.db rk, + @{PROC}/net/if_inet6 r, + /usr/lib/postfix/*.so mr, + /usr/lib{,32,64}/sasl2/* mr, + /usr/lib{,32,64}/sasl2/ r, + /usr/lib/@{multiarch}/sasl2/* mr, + /usr/lib/@{multiarch}/sasl2/ r, + /usr/share/icu/[0-9]*.[0-9]*/*.dat r, + + /var/spool/postfix/etc/* r, + /var/spool/postfix/lib/lib*.so* mr, + /var/spool/postfix/lib/@{multiarch}/lib*.so* mr, diff --git a/apparmor.d/abstractions/private-files b/apparmor.d/abstractions/private-files new file mode 100644 index 00000000..09f6d9bd --- /dev/null +++ b/apparmor.d/abstractions/private-files @@ -0,0 +1,47 @@ +# vim:syntax=apparmor +# privacy-violations contains rules for common files that you want to +# explicitly deny access + + # privacy violations (don't audit files under $HOME otherwise get a + # lot of false positives when reading contents of directories) + deny @{HOME}/.*history mrwkl, + deny @{HOME}/.fetchmail* mrwkl, + deny @{HOME}/.mutt** mrwkl, + deny @{HOME}/.viminfo* mrwkl, + deny @{HOME}/.*~ mrwkl, + deny @{HOME}/.*.swp mrwkl, + deny @{HOME}/.*~1~ mrwkl, + deny @{HOME}/.*.bak mrwkl, + + # special attention to (potentially) executable files + audit deny @{HOME}/bin/{,**} wl, + audit deny @{HOME}/.config/ w, + audit deny @{HOME}/.config/autostart/{,**} wl, + audit deny @{HOME}/.config/upstart/{,**} wl, + audit deny @{HOME}/.init/{,**} wl, + audit deny @{HOME}/.kde{,4}/ w, + audit deny @{HOME}/.kde{,4}/Autostart/{,**} wl, + audit deny @{HOME}/.kde{,4}/env/{,**} wl, + audit deny @{HOME}/.local/{,share/} w, + audit deny @{HOME}/.local/share/thumbnailers/{,**} wl, + audit deny @{HOME}/.pki/ w, + audit deny @{HOME}/.pki/nssdb/{,*.so{,.[0-9]*}} wl, + + # don't allow reading/updating of run control files + deny @{HOME}/.*rc mrk, + audit deny @{HOME}/.*rc wl, + + # bash + deny @{HOME}/.bash* mrk, + audit deny @{HOME}/.bash* wl, + deny @{HOME}/.inputrc mrk, + audit deny @{HOME}/.inputrc wl, + + # sh/dash/csh/tcsh/pdksh/zsh + deny @{HOME}/.{,z}profile* mrk, + audit deny @{HOME}/.{,z}profile* wl, + deny @{HOME}/.{,z}log{in,out} mrk, + audit deny @{HOME}/.{,z}log{in,out} wl, + + deny @{HOME}/.zshenv mrk, + audit deny @{HOME}/.zshenv wl, diff --git a/apparmor.d/abstractions/private-files-strict b/apparmor.d/abstractions/private-files-strict new file mode 100644 index 00000000..31934318 --- /dev/null +++ b/apparmor.d/abstractions/private-files-strict @@ -0,0 +1,25 @@ +# vim:syntax=apparmor +# privacy-violations-strict contains additional rules for sensitive +# files that you want to explicitly deny access + + #include + + # potentially extremely sensitive files + audit deny @{HOME}/.aws/{,**} mrwkl, + audit deny @{HOME}/.gnupg/{,**} mrwkl, + audit deny @{HOME}/.ssh/{,**} mrwkl, + audit deny @{HOME}/.gnome2_private/{,**} mrwkl, + audit deny @{HOME}/.gnome2/ w, + audit deny @{HOME}/.gnome2/keyrings/{,**} mrwkl, + # don't allow access to any gnome-keyring modules + audit deny /{,var/}run/user/[0-9]*/keyring** mrwkl, + audit deny @{HOME}/.mozilla/{,**} mrwkl, + audit deny @{HOME}/.config/ w, + audit deny @{HOME}/.config/chromium/{,**} mrwkl, + audit deny @{HOME}/.config/evolution/{,**} mrwkl, + audit deny @{HOME}/.evolution/{,**} mrwkl, + audit deny @{HOME}/.{,mozilla-}thunderbird/{,**} mrwkl, + audit deny @{HOME}/.kde{,4}/{,share/,share/apps/} w, + audit deny @{HOME}/.kde{,4}/share/apps/kmail{,2}/{,**} mrwkl, + audit deny @{HOME}/.kde{,4}/share/apps/kwallet/{,**} mrwkl, + diff --git a/apparmor.d/abstractions/python b/apparmor.d/abstractions/python new file mode 100644 index 00000000..925161c1 --- /dev/null +++ b/apparmor.d/abstractions/python @@ -0,0 +1,37 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /usr/lib{,32,64}/python{2.[4-7],3.[0-9]}/**.{pyc,so} mr, + /usr/lib{,32,64}/python{2.[4-7],3.[0-9]}/**.{egg,py,pth} r, + /usr/lib{,32,64}/python{2.[4-7],3.[0-9]}/{site,dist}-packages/ r, + /usr/lib{,32,64}/python3.[0-9]/lib-dynload/*.so mr, + + /usr/local/lib{,32,64}/python{2.[4-7],3,3.[0-9]}/**.{pyc,so} mr, + /usr/local/lib{,32,64}/python{2.[4-7],3,3.[0-9]}/**.{egg,py,pth} r, + /usr/local/lib{,32,64}/python{2.[4-7],3,3.[0-9]}/{site,dist}-packages/ r, + /usr/local/lib{,32,64}/python3.[0-9]/lib-dynload/*.so mr, + + # Site-wide configuration + /etc/python{2.[4-7],3.[0-9]}/** r, + + # shared python paths + /usr/share/{pyshared,pycentral,python-support}/** r, + /{var,usr}/lib/{pyshared,pycentral,python-support}/** r, + /usr/lib/{pyshared,pycentral,python-support}/**.so mr, + /var/lib/{pyshared,pycentral,python-support}/**.pyc mr, + /usr/lib/python3/dist-packages/**.so mr, + + # wx paths + /usr/lib/wx/python/*.pth r, + + # python build configuration and headers + /usr/include/python{2.[4-7],3.[0-9]}*/pyconfig.h r, diff --git a/apparmor.d/abstractions/qt5 b/apparmor.d/abstractions/qt5 new file mode 100644 index 00000000..66a574bf --- /dev/null +++ b/apparmor.d/abstractions/qt5 @@ -0,0 +1,22 @@ +# vim:syntax=apparmor +# Common rules for Qt5-based applications + + # Additional libraries + + /usr/lib{,64,/@{multiarch}}/qt5/plugins/**.so mr, + /usr/lib{,64,/@{multiarch}}/qt5/qml/**.so mr, + /usr/lib{,64,/@{multiarch}}/qt5/qml/**.{qmlc,jsc} mr, # Precompiled QML/JavaScript modules + + # System files + + /etc/xdg/QtProject/qtlogging.ini r, + /usr/share/qt5/translations/*.qm r, + /usr/lib{,64,/@{multiarch}}/qt5/plugins/** r, + /usr/lib{,64,/@{multiarch}}/qt5/qml/** r, + + # User files + + owner @{HOME}/.config/QtProject/qtlogging.ini r, + owner @{HOME}/.config/QtProject.conf r, # common settings for QFileDialog, etc (application might need write access) + owner @{HOME}/.cache/qt_compose_cache_{little,big}_endian_* r, # for "platforminputcontexts" plugins + diff --git a/apparmor.d/abstractions/qt5-compose-cache-write b/apparmor.d/abstractions/qt5-compose-cache-write new file mode 100644 index 00000000..38cb2348 --- /dev/null +++ b/apparmor.d/abstractions/qt5-compose-cache-write @@ -0,0 +1,8 @@ +# vim:syntax=apparmor +# Allow writing cache for Qt5 "platforminputcontexts" plugins + + # User files + + owner @{HOME}/.cache/qt_compose_cache_{little,big}_endian_* rwl -> @{HOME}/.cache/#[0-9]*[0-9], + owner @{HOME}/.cache/#[0-9]*[0-9] rw, # QSaveFile (anonymous shared memory) + diff --git a/apparmor.d/abstractions/qt5-settings-write b/apparmor.d/abstractions/qt5-settings-write new file mode 100644 index 00000000..07d10972 --- /dev/null +++ b/apparmor.d/abstractions/qt5-settings-write @@ -0,0 +1,11 @@ +# vim:syntax=apparmor +# Allow writing shared settings for Qt-based applications + + # User files + + owner @{HOME}/.config/#[0-9]*[0-9] rw, + owner @{HOME}/.config/QtProject.conf rwl -> @{HOME}/.config/#[0-9]*[0-9], + # for temporary files like QtProject.conf.Aqrgeb + owner @{HOME}/.config/QtProject.conf.?????? rwl -> @{HOME}/.config/#[0-9]*[0-9], + owner @{HOME}/.config/QtProject.conf.lock rwk, + diff --git a/apparmor.d/abstractions/recent-documents-write b/apparmor.d/abstractions/recent-documents-write new file mode 100644 index 00000000..d95febb8 --- /dev/null +++ b/apparmor.d/abstractions/recent-documents-write @@ -0,0 +1,10 @@ +# vim:syntax=apparmor +# Allow updating recent documents + + # User files + + owner @{HOME}/.local/share/RecentDocuments/ rw, + owner @{HOME}/.local/share/RecentDocuments/#[0-9]* rw, + owner @{HOME}/.local/share/RecentDocuments/*.desktop rwl -> @{HOME}/.local/share/RecentDocuments/#[0-9]*, + owner @{HOME}/.local/share/RecentDocuments/*.lock rwk, + diff --git a/apparmor.d/abstractions/ruby b/apparmor.d/abstractions/ruby new file mode 100644 index 00000000..ff4ac9fa --- /dev/null +++ b/apparmor.d/abstractions/ruby @@ -0,0 +1,21 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /usr/lib{,32,64}/ruby/1.[89]{.[0-9],}/ r, + /usr/lib{,32,64}/ruby/1.[89]{.[0-9],}/**.rb r, + /usr/lib{,32,64}/ruby/1.[89]{.[0-9],}/*-linux/**.so mr, + + /usr/{,local/}lib{,32,64}/ruby/{site,vendor}_ruby/1.[89]{.[0-9],}/ r, + /usr/{,local/}lib{,32,64}/ruby/{site,vendor}_ruby/1.[89]{.[0-9],}/**.rb r, + /usr/{,local/}lib{,32,64}/ruby/{site,vendor}_ruby/1.[89]{.[0-9],}/*-linux/**.so mr, + + /usr/lib{,32,64}/ruby/gems/1.[89]{.[0-9],}/ r, + /usr/lib{,32,64}/ruby/gems/1.[89]{.[0-9],}/** r, diff --git a/apparmor.d/abstractions/samba b/apparmor.d/abstractions/samba new file mode 100644 index 00000000..1cab7309 --- /dev/null +++ b/apparmor.d/abstractions/samba @@ -0,0 +1,27 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009-2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /etc/samba/* r, + /usr/lib*/ldb/*.so mr, + /usr/lib*/samba/ldb/*.so mr, + /usr/share/samba/*.dat r, + /usr/share/samba/codepages/{lowcase,upcase,valid}.dat r, + /var/cache/samba/ w, + /var/cache/samba/lck/* rwk, + /var/lib/samba/** rwk, + /var/log/samba/cores/ rw, + /var/log/samba/cores/** rw, + /var/log/samba/* w, + /{,var/}run/samba/ w, + /{,var/}run/samba/*.tdb rw, + + # required for clustering + /var/lib/ctdb/** rwk, diff --git a/apparmor.d/abstractions/smbpass b/apparmor.d/abstractions/smbpass new file mode 100644 index 00000000..eb4cf26b --- /dev/null +++ b/apparmor.d/abstractions/smbpass @@ -0,0 +1,13 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # libpam-smbpass/pam_smbpass.so permissions + /var/lib/samba/*.[lt]db rwk, diff --git a/apparmor.d/abstractions/ssl_certs b/apparmor.d/abstractions/ssl_certs new file mode 100644 index 00000000..789efc58 --- /dev/null +++ b/apparmor.d/abstractions/ssl_certs @@ -0,0 +1,44 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2005 Novell/SUSE +# Copyright (C) 2010-2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /etc/ssl/ r, + /etc/ssl/certs/ r, + /etc/ssl/certs/* r, + /etc/pki/trust/ r, + /etc/pki/trust/* r, + /etc/pki/trust/anchors/ r, + /etc/pki/trust/anchors/** r, + /usr/share/ca-certificates/ r, + /usr/share/ca-certificates/** r, + /usr/share/ssl/certs/ca-bundle.crt r, + /usr/local/share/ca-certificates/ r, + /usr/local/share/ca-certificates/** r, + /var/lib/ca-certificates/ r, + /var/lib/ca-certificates/** r, + + # acmetool + /var/lib/acme/certs/*/chain r, + /var/lib/acme/certs/*/cert r, + + # dehydrated + /{etc,var/lib}/dehydrated/certs/*/cert*.pem r, + /{etc,var/lib}/dehydrated/certs/*/chain*.pem r, + /{etc,var/lib}/dehydrated/certs/*/fullchain*.pem r, + /{etc,var/lib}/dehydrated/certs/*/ocsp*.der r, + + # certbot + /etc/letsencrypt/archive/*/cert*.pem r, + /etc/letsencrypt/archive/*/chain*.pem r, + /etc/letsencrypt/archive/*/fullchain*.pem r, + + /etc/certbot/archive/*/cert*.pem r, + /etc/certbot/archive/*/chain*.pem r, + /etc/certbot/archive/*/fullchain*.pem r, diff --git a/apparmor.d/abstractions/ssl_keys b/apparmor.d/abstractions/ssl_keys new file mode 100644 index 00000000..2de760b5 --- /dev/null +++ b/apparmor.d/abstractions/ssl_keys @@ -0,0 +1,30 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # private ssl permissions + + # Just include the whole /etc/ssl directory if we should have access to + # private keys too + /etc/ssl/ r, + /etc/ssl/** r, + + # acmetool + /var/lib/acme/live/* r, + /var/lib/acme/certs/** r, + /var/lib/acme/keys/** r, + + # dehydrated + /{etc,var/lib}/dehydrated/certs/*/privkey*.pem r, + + # certbot / letsencrypt + /etc/letsencrypt/archive/*/privkey*.pem r, + + /etc/certbot/archive/*/privkey*.pem r, diff --git a/apparmor.d/abstractions/svn-repositories b/apparmor.d/abstractions/svn-repositories new file mode 100644 index 00000000..68ac5e0b --- /dev/null +++ b/apparmor.d/abstractions/svn-repositories @@ -0,0 +1,52 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # This little snippet should abstract the read/write access to a repository. + # it is intended to be included in profiles for svnserve/apache2 and maybe + # some repository viewers like trac/viewvc + + # no hooks exec by default; please define whatever you need explicitely. + + /srv/svn/**/conf/* r, + /srv/svn/**/format r, + /srv/svn/**/db/fs-type r, + /srv/svn/**/db/format r, + + # FSFS + /srv/svn/**/db/ r, + /srv/svn/**/db/uuid r, + /srv/svn/**/db/write-lock rwl, + /srv/svn/**/db/current rwl, + /srv/svn/**/db/current*.tmp rwl, + /srv/svn/**/db/revs/ r, + /srv/svn/**/db/revs/* rw, + /srv/svn/**/db/revprops/ r, + /srv/svn/**/db/revprops/* rw, + /srv/svn/**/db/transactions/** rw, + + # BDB + /srv/svn/**/db/DB_CONFIG r, + /srv/svn/**/db/__db.[0-9]* rwl, + /srv/svn/**/db/log.[0-9]* rwl, + /srv/svn/**/db/nodes rwl, + /srv/svn/**/db/revisions rwl, + /srv/svn/**/db/transactions rwl, + /srv/svn/**/db/copies rwl, + /srv/svn/**/db/changes rwl, + /srv/svn/**/db/representations rwl, + /srv/svn/**/db/strings rwl, + /srv/svn/**/db/uuids rwl, + /srv/svn/**/db/locks rwl, + /srv/svn/**/db/lock-tokens rwl, + + # temp files + /tmp/apr* rwl, + /var/tmp/apr* rwl, + /tmp/report*.tmp rwl, diff --git a/apparmor.d/abstractions/ubuntu-bittorrent-clients b/apparmor.d/abstractions/ubuntu-bittorrent-clients new file mode 100644 index 00000000..fb820c5a --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-bittorrent-clients @@ -0,0 +1,17 @@ +# vim:syntax=apparmor +# +# abstraction for allowing graphical bittorrent clients in Ubuntu +# +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + /usr/bin/azureus Cxr -> sanitized_helper, + /usr/bin/bitstormlite Cxr -> sanitized_helper, + /usr/bin/btmaketorrentgui Cxr -> sanitized_helper, + /usr/bin/deluge{,-gtk,-console} Cxr -> sanitized_helper, + /usr/bin/gnome-btdownload Cxr -> sanitized_helper, + /usr/bin/kget Cxr -> sanitized_helper, + /usr/bin/ktorrent Cxr -> sanitized_helper, + /usr/bin/qbittorrent Cxr -> sanitized_helper, + /usr/bin/transmission{,-gtk,-qt,-cli} Cxr -> sanitized_helper, diff --git a/apparmor.d/abstractions/ubuntu-browsers b/apparmor.d/abstractions/ubuntu-browsers new file mode 100644 index 00000000..d4438ad6 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers @@ -0,0 +1,42 @@ +# vim:syntax=apparmor +# +# abstraction for allowing access to graphical browsers in Ubuntu +# +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + /usr/bin/arora Cx -> sanitized_helper, + /usr/bin/conkeror Cx -> sanitized_helper, + /usr/bin/dillo Cx -> sanitized_helper, + /usr/bin/Dooble Cx -> sanitized_helper, + /usr/bin/epiphany Cx -> sanitized_helper, + /usr/bin/epiphany-browser Cx -> sanitized_helper, + /usr/bin/epiphany-webkit Cx -> sanitized_helper, + /usr/lib/fennec-*/fennec Cx -> sanitized_helper, + /usr/bin/galeon Cx -> sanitized_helper, + /usr/bin/kazehakase Cx -> sanitized_helper, + /usr/bin/konqueror Cx -> sanitized_helper, + /usr/bin/midori Cx -> sanitized_helper, + /usr/bin/netsurf Cx -> sanitized_helper, + /usr/bin/prism Cx -> sanitized_helper, + /usr/bin/rekonq Cx -> sanitized_helper, + /usr/bin/seamonkey Cx -> sanitized_helper, + /usr/bin/sensible-browser Pixr, + + /usr/bin/chromium{,-browser} Cx -> sanitized_helper, + /usr/lib{,64}/chromium{,-browser}/chromium{,-browser} Cx -> sanitized_helper, + + # this should cover all firefox browsers and versions (including shiretoko + # and abrowser) + /usr/bin/firefox Cxr -> sanitized_helper, + /usr/lib{,64}/firefox*/firefox* Cx -> sanitized_helper, + + # Iceweasel + /usr/bin/iceweasel Cxr -> sanitized_helper, + /usr/lib/iceweasel/iceweasel Cx -> sanitized_helper, + + # some unpackaged, but popular browsers + /usr/lib/icecat-*/icecat Cx -> sanitized_helper, + /usr/bin/opera Cx -> sanitized_helper, + /opt/google/chrome{,-beta,-unstable}/google-chrome{,-beta,-unstable} Cx -> sanitized_helper, diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/java b/apparmor.d/abstractions/ubuntu-browsers.d/java new file mode 100644 index 00000000..e0a67cf3 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/java @@ -0,0 +1,118 @@ +# vim:syntax=apparmor + + # Java plugin + owner @{HOME}/.java/deployment/deployment.properties k, + /etc/java-*/ r, + /etc/java-*/** r, + /usr/lib/jvm/java-[1-9]{,[0-9]}-openjdk/{,jre/}lib/*/IcedTeaPlugin.so mr, + /usr/lib/jvm/java-[1-9]{,[0-9]}-openjdk-{amd64,armel,armhf,i386,powerpc}/{,jre/}lib/*/IcedTeaPlugin.so mr, + /usr/lib/jvm/java-[1-9]{,[0-9]}-openjdk/{,jre/}bin/java cx -> browser_openjdk, + /usr/lib/jvm/java-[1-9]{,[0-9]}-openjdk-{amd64,armel,armhf,i386,powerpc}/{,jre/}bin/java cx -> browser_openjdk, + /usr/lib/jvm/java-*-sun-1.*/jre/bin/java{,_vm} cx -> browser_java, + /usr/lib/jvm/java-*-sun-1.*/jre/lib/*/libnp*.so cx -> browser_java, + /usr/lib/j2*-ibm/jre/bin/java cx -> browser_java, + owner /{,var/}run/user/*/icedteaplugin-*/ rw, + owner /{,var/}run/user/*/icedteaplugin-*/** rwk, + + # Profile for the supported OpenJDK in Ubuntu. This doesn't require the + # unfortunate workarounds of the proprietary Javas, so have a separate + # profile. + profile browser_openjdk { + #include + #include + #include + #include + #include + #include + #include + #include + + network inet stream, + network inet6 stream, + @{PROC}/@{pid}/net/if_inet6 r, + @{PROC}/@{pid}/net/ipv6_route r, + + /etc/java-*/ r, + /etc/java-*/** r, + /etc/lsb-release r, + /etc/ssl/certs/java/* r, + /etc/timezone r, + /etc/writable/timezone r, + + @{PROC}/@{pid}/ r, + @{PROC}/@{pid}/fd/ r, + @{PROC}/filesystems r, + @{sys}/devices/system/cpu/ r, + @{sys}/devices/system/cpu/** r, + /usr/share/** r, + /var/lib/dbus/machine-id r, + + /usr/bin/env ix, + /usr/lib/jvm/java-[1-9]{,[0-9]}-openjdk/{,jre/}bin/java ix, + /usr/lib/jvm/java-[1-9]{,[0-9]}-openjdk-{amd64,armel,armhf,i386,powerpc}/{,jre/}bin/java ix, + /usr/lib/jvm/java-{6,7}-openjdk*/jre/lib/i386/client/classes.jsa m, + + # Why would java need this? + deny /usr/bin/gconftool-2 x, + + owner /{,var/}run/user/[0-9]*/icedteaplugin-*-*/[0-9]*-icedteanp-appletviewer-to-plugin rw, + owner /{,var/}run/user/[0-9]*/icedteaplugin-*-*/[0-9]*-icedteanp-plugin-{,debug-}to-appletviewer r, + owner @{HOME}/ r, + owner @{HOME}/** rwk, + } + + # Profile for commercial Javas. These need workarounds to work right (eg + # Sun's forcing of an executable stack (LP: #535247)). + profile browser_java { + #include + #include + #include + #include + #include + #include + #include + #include + + network inet stream, + network inet6 stream, + @{PROC}/@{pid}/net/if_inet6 r, + @{PROC}/@{pid}/net/ipv6_route r, + @{PROC}/loadavg r, + + /etc/debian_version r, + /etc/java-*/ r, + /etc/java-*/** r, + /etc/lsb-release r, + /etc/ssl/certs/java/* r, + /etc/timezone r, + /etc/writable/timezone r, + + @{PROC}/@{pid}/ r, + @{PROC}/@{pid}/fd/ r, + @{PROC}/filesystems r, + @{sys}/devices/system/cpu/ r, + @{sys}/devices/system/cpu/** r, + /usr/share/** r, + /var/lib/dbus/machine-id r, + + /usr/bin/env ix, + /usr/lib/jvm/java-*-sun-1.*/jre/bin/java{,_vm} ix, + /usr/lib/jvm/java-*-sun-1.*/jre/lib/i386/client/classes.jsa m, + /usr/lib/j2*-ibm/jre/bin/java ix, + + # noisy, can't write here anyway + deny /etc/.java/ w, + deny /etc/.java/** w, + + deny /usr/bin/gconftool-2 x, + + owner @{HOME}/ r, + owner @{HOME}/** rwk, + + # These are seriously unfortunate, but required due to LP: #535247 + /etc/passwd m, + owner @{HOME}/.java/**/cache/** m, + owner /tmp/** m, + /usr/lib{,32,64}/jvm/**/*.jar mr, + /usr/share/fonts/** m, + } diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/kde b/apparmor.d/abstractions/ubuntu-browsers.d/kde new file mode 100644 index 00000000..038952a8 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/kde @@ -0,0 +1,7 @@ +# vim:syntax=apparmor +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + #include + /usr/bin/kde4-config Cx -> sanitized_helper, diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/mailto b/apparmor.d/abstractions/ubuntu-browsers.d/mailto new file mode 100644 index 00000000..40236a7b --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/mailto @@ -0,0 +1,9 @@ +# vim:syntax=apparmor + + # for mailto: + #include + #include + + # Terminals for using console applications. These abstractions should ideally + # have 'ix' to restrct access to what only firefox is allowed to do + #include diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/multimedia b/apparmor.d/abstractions/ubuntu-browsers.d/multimedia new file mode 100644 index 00000000..591d6b85 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/multimedia @@ -0,0 +1,66 @@ +# vim:syntax=apparmor +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + #include + + # Pulseaudio + /usr/bin/pulseaudio Pixr, + + # Image viewers + /usr/bin/eog Cxr -> sanitized_helper, + /usr/bin/gimp* Cxr -> sanitized_helper, + /usr/bin/shotwell Cxr -> sanitized_helper, + /usr/bin/digikam Cxr -> sanitized_helper, + /usr/bin/f-spot Cxr -> sanitized_helper, + /usr/bin/gwenview Cxr -> sanitized_helper, + + #include + owner @{HOME}/.adobe/ w, + owner @{HOME}/.adobe/** rw, + owner @{HOME}/.macromedia/ w, + owner @{HOME}/.macromedia/** rw, + /opt/real/RealPlayer/mozilla/nphelix.so rm, + /usr/bin/lpstat Cxr -> sanitized_helper, + /usr/bin/lpr Cxr -> sanitized_helper, + + # npviewer + /usr/lib/nspluginwrapper/i386/linux/npviewer{,.bin} ixr, + /var/lib/ r, + /var/lib/**/*.so mr, + /usr/bin/setarch ixr, + + # Bittorrent clients + #include + + # Mozplugger + /etc/mozpluggerrc r, + /usr/bin/mozplugger-helper Cxr -> sanitized_helper, + + # Archivers + /usr/bin/ark Cxr -> sanitized_helper, + /usr/bin/file-roller Cxr -> sanitized_helper, + /usr/bin/xarchiver Cxr -> sanitized_helper, + /usr/local/lib{,32,64}/*.so* mr, + + # News feed readers + #include + + # Googletalk + /opt/google/talkplugin/*.so mr, + /opt/google/talkplugin/lib/*.so mr, + /opt/google/talkplugin/GoogleTalkPlugin ixr, + owner @{HOME}/.config/google-googletalkplugin/** rw, + + # If we allow the above, nvidia based systems will also need this + #include + + # Virus scanners + /usr/bin/clamscan Cx -> sanitized_helper, + + # gxine (LP: #1057642) + /var/lib/xine/gxine.desktop r, + + # For WebRTC camera access (LP: #1665535) + /dev/video[0-9]* rw, diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/plugins-common b/apparmor.d/abstractions/ubuntu-browsers.d/plugins-common new file mode 100644 index 00000000..c928f92c --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/plugins-common @@ -0,0 +1,16 @@ +# vim:syntax=apparmor + + # + # Plugins/helpers + # + @{PROC}/@{pid}/fd/ r, + /usr/lib/** rm, + /{,usr/}bin/bash ixr, + /{,usr/}bin/dash ixr, + /{,usr/}bin/grep ixr, + /{,usr/}bin/sed ixr, + /usr/bin/m4 ixr, + + # Since all the ubuntu-browsers.d abstractions need this, just include it + # here + #include diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/productivity b/apparmor.d/abstractions/ubuntu-browsers.d/productivity new file mode 100644 index 00000000..2c898d13 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/productivity @@ -0,0 +1,28 @@ +# vim:syntax=apparmor +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + # Openoffice.org + /usr/bin/ooffice Cxr -> sanitized_helper, + /usr/bin/oocalc Cxr -> sanitized_helper, + /usr/bin/oodraw Cxr -> sanitized_helper, + /usr/bin/ooimpress Cxr -> sanitized_helper, + /usr/bin/oowriter Cxr -> sanitized_helper, + /usr/lib/openoffice/program/soffice Cxr -> sanitized_helper, + + # LibreOffice + /usr/bin/libreoffice Cxr -> sanitized_helper, + /usr/bin/localc Cxr -> sanitized_helper, + /usr/bin/lodraw Cxr -> sanitized_helper, + /usr/bin/loimpress Cxr -> sanitized_helper, + /usr/bin/lowriter Cxr -> sanitized_helper, + /usr/lib/libreoffice/program/soffice Cxr -> sanitized_helper, + + # PDFs + /usr/bin/evince Cxr -> sanitized_helper, + /usr/bin/okular Cxr -> sanitized_helper, + + owner @{HOME}/.adobe/** rw, + /opt/Adobe/Reader9/bin/acroread Cxr -> sanitized_helper, + /opt/Adobe/Reader9/** r, diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/text-editors b/apparmor.d/abstractions/ubuntu-browsers.d/text-editors new file mode 100644 index 00000000..bf5eb1d1 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/text-editors @@ -0,0 +1,14 @@ +# vim:syntax=apparmor +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + # Text editors (It's All Text [https://addons.mozilla.org/en-US/firefox/addon/4125]) + /usr/bin/emacsclient.emacs-snapshot Cxr -> sanitized_helper, + /usr/bin/emacsclient.emacs2[2-9] Cxr -> sanitized_helper, + /usr/bin/emacs-snapshot-gtk Cxr -> sanitized_helper, + /usr/bin/gedit Cxr -> sanitized_helper, + /usr/bin/vim.gnome Cxr -> sanitized_helper, + /usr/bin/leafpad Cxr -> sanitized_helper, + /usr/bin/mousepad Cxr -> sanitized_helper, + /usr/bin/kate Cxr -> sanitized_helper, diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration b/apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration new file mode 100644 index 00000000..0cd0928e --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration @@ -0,0 +1,41 @@ +# vim:syntax=apparmor +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + # Apport + /usr/bin/apport-bug Cx -> sanitized_helper, + + # Package installation + /usr/bin/apturl Cxr -> sanitized_helper, + /usr/bin/gnome-codec-install Cxr -> sanitized_helper, + /usr/lib/gstreamer0.10/gstreamer-0.10/gst-plugin-scanner ix, + /usr/lib/@{multiarch}/gstreamer0.10/gstreamer-0.10/gst-plugin-scanner ix, + /usr/share/software-center/software-center Cxr -> sanitized_helper, + + # Input Methods + /usr/bin/scim Cx -> sanitized_helper, + /usr/bin/scim-bridge Cx -> sanitized_helper, + + # File managers + /usr/bin/nautilus Cxr -> sanitized_helper, + /usr/bin/{t,T}hunar Cxr -> sanitized_helper, + /usr/bin/dolphin Cxr -> sanitized_helper, + + # Themes + /usr/bin/gnome-appearance-properties Cxr -> sanitized_helper, + + # Kubuntu + /usr/lib/mozilla/kmozillahelper Cxr -> sanitized_helper, + + # Exo-aware applications + /usr/bin/exo-open ixr, + /usr/lib/@{multiarch}/xfce4/exo-1/exo-helper-1 ixr, + /etc/xdg/xdg-xubuntu/xfce4/helpers.rc r, + /etc/xdg/xfce4/helpers.rc r, + + # unity webapps integration. Could go in its own abstraction + owner /run/user/*/dconf/user rw, + owner @{HOME}/.local/share/unity-webapps/availableapps*.db rwk, + /usr/bin/debconf-communicate Cxr -> sanitized_helper, + owner @{HOME}/.config/libaccounts-glib/accounts.db rk, diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration-xul b/apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration-xul new file mode 100644 index 00000000..0429c13f --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/ubuntu-integration-xul @@ -0,0 +1,6 @@ +# vim:syntax=apparmor + + # firefox-notify + #include + /usr/bin/python2.[4567] ix, + /usr/share/xul-ext/notify/**/download_complete_notify.py ix, diff --git a/apparmor.d/abstractions/ubuntu-browsers.d/user-files b/apparmor.d/abstractions/ubuntu-browsers.d/user-files new file mode 100644 index 00000000..ffe68245 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-browsers.d/user-files @@ -0,0 +1,28 @@ +# vim:syntax=apparmor + + # Allow read to all files user has DAC access to and write access to all + # files owned by the user in $HOME. + @{HOME}/ r, + @{HOME}/** r, + owner @{HOME}/** w, + + # Do not allow read and/or write to particularly sensitive/problematic files + #include + audit deny @{HOME}/.ssh/{,**} mrwkl, + audit deny @{HOME}/.gnome2_private/{,**} mrwkl, + audit deny @{HOME}/.kde{,4}/{,share/,share/apps/} w, + audit deny @{HOME}/.kde{,4}/share/apps/kwallet/{,**} mrwkl, + + # Comment this out if using gpg plugin/addons + audit deny @{HOME}/.gnupg/{,**} mrwkl, + + # Allow read to all files user has DAC access to and write for files the user + # owns on removable media and filesystems. + /media/** r, + /mnt/** r, + /srv/** r, + /net/** r, + owner /media/** w, + owner /mnt/** w, + owner /srv/** w, + owner /net/** w, diff --git a/apparmor.d/abstractions/ubuntu-console-browsers b/apparmor.d/abstractions/ubuntu-console-browsers new file mode 100644 index 00000000..554469e7 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-console-browsers @@ -0,0 +1,18 @@ +# vim:syntax=apparmor +# +# abstraction for allowing access to text-only browsers in Ubuntu. These will +# typically also need a terminal, so when using this abstraction, should also +# do something like: +# +# #include +# +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + /usr/bin/elinks Cx -> sanitized_helper, + /usr/bin/links Cx -> sanitized_helper, + /usr/bin/lynx.cur Cx -> sanitized_helper, + /usr/bin/netrik Cx -> sanitized_helper, + /usr/bin/w3m Cx -> sanitized_helper, + diff --git a/apparmor.d/abstractions/ubuntu-console-email b/apparmor.d/abstractions/ubuntu-console-email new file mode 100644 index 00000000..f77c9bd6 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-console-email @@ -0,0 +1,18 @@ +# vim:syntax=apparmor +# +# abstraction for allowing console email clients in Ubuntu. These will +# typically also need a terminal, so when using this abstraction, should also +# do something like: +# +# #include +# +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + /usr/bin/alpine Cx -> sanitized_helper, + /usr/bin/citadel Cx -> sanitized_helper, + /usr/bin/cone Cx -> sanitized_helper, + /usr/bin/elmo Cx -> sanitized_helper, + /usr/bin/mutt Cx -> sanitized_helper, + diff --git a/apparmor.d/abstractions/ubuntu-email b/apparmor.d/abstractions/ubuntu-email new file mode 100644 index 00000000..48e0c6f4 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-email @@ -0,0 +1,24 @@ +# vim:syntax=apparmor +# +# abstraction for allowing graphical email clients in Ubuntu +# +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + /usr/bin/anjal Cx -> sanitized_helper, + /usr/bin/balsa Cx -> sanitized_helper, + /usr/bin/claws-mail Cx -> sanitized_helper, + /usr/bin/evolution Cx -> sanitized_helper, + /usr/bin/geary Cx -> sanitized_helper, + /usr/bin/gnome-gmail Cx -> sanitized_helper, + /usr/lib/GNUstep/Applications/GNUMail.app/GNUMail Cx -> sanitized_helper, + /usr/bin/kmail Cx -> sanitized_helper, + /usr/bin/mailody Cx -> sanitized_helper, + /usr/bin/modest Cx -> sanitized_helper, + /usr/bin/seamonkey Cx -> sanitized_helper, + /usr/bin/sylpheed Cx -> sanitized_helper, + /usr/bin/tkrat Cx -> sanitized_helper, + + /usr/bin/thunderbird Cx -> sanitized_helper, # used by gio-launch-desktop + /usr/lib/thunderbird*/thunderbird{,.sh,-bin} Cx -> sanitized_helper, diff --git a/apparmor.d/abstractions/ubuntu-feed-readers b/apparmor.d/abstractions/ubuntu-feed-readers new file mode 100644 index 00000000..85379e30 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-feed-readers @@ -0,0 +1,10 @@ +# vim:syntax=apparmor +# +# abstraction for allowing graphical news feed readers in Ubuntu +# +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + /usr/bin/akregator Cxr -> sanitized_helper, + /usr/bin/liferea-add-feed Cxr -> sanitized_helper, diff --git a/apparmor.d/abstractions/ubuntu-gnome-terminal b/apparmor.d/abstractions/ubuntu-gnome-terminal new file mode 100644 index 00000000..7604df1e --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-gnome-terminal @@ -0,0 +1,10 @@ +# vim:syntax=apparmor +# +# for allowing access to gnome-terminal +# + + #include + + # do not use ux or PUx here. Use at a minimum ix + /usr/bin/gnome-terminal ix, + diff --git a/apparmor.d/abstractions/ubuntu-helpers b/apparmor.d/abstractions/ubuntu-helpers new file mode 100644 index 00000000..a1ab7bc0 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-helpers @@ -0,0 +1,83 @@ +# Lenient profile that is intended to be used when 'Ux' is desired but +# does not provide enough environment sanitizing. This effectively is an +# open profile that blacklists certain known dangerous files and also +# does not allow any capabilities. For example, it will not allow 'm' on files +# owned be the user invoking the program. While this provides some additional +# protection, please use with care as applications running under this profile +# are effectively running without any AppArmor protection. Use this profile +# only if the process absolutely must be run (effectively) unconfined. +# +# Usage: +# Because this abstraction defines the sanitized_helper profile, it must only +# be #included once. Therefore this abstraction should typically not be +# included in other abstractions so as to avoid parser errors regarding +# multiple definitions. +# +# Limitations: +# 1. This does not work for root owned processes, because of the way we use +# owner matching in the sanitized helper. We could do a better job with +# this to support root, but it would make the policy harder to understand +# and going unconfined as root is not desirable any way. +# +# 2. For this sanitized_helper to work, the program running in the sanitized +# environment must open symlinks directly in order for AppArmor to mediate +# it. This is confirmed to work with: +# - compiled code which can load shared libraries +# - python imports +# It is known not to work with: +# - perl includes +# 3. Sanitizing ruby and java +# +# Use at your own risk. This profile was developed as an interim workaround for +# LP: #851986 until AppArmor utilizes proper environment filtering. + +profile sanitized_helper { + #include + #include + + # Allow all networking + network inet, + network inet6, + + # Allow all DBus communications + #include + #include + dbus, + + # Needed for Google Chrome + ptrace (trace) peer=**//sanitized_helper, + + # Allow exec of anything, but under this profile. Allow transition + # to other profiles if they exist. + /{usr/,usr/local/,}{bin,sbin}/* Pixr, + + # Allow exec of libexec applications in /usr/lib* and /usr/local/lib* + /usr/{,local/}lib*/{,**/}* Pixr, + + # Allow exec of software-center scripts. We may need to allow wider + # permissions for /usr/share, but for now just do this. (LP: #972367) + /usr/share/software-center/* Pixr, + + # Allow exec of texlive font build scripts (LP: #1010909) + /usr/share/texlive/texmf{,-dist}/web2c/{,**/}* Pixr, + + # While the chromium and chrome sandboxes are setuid root, they only link + # in limited libraries so glibc's secure execution should be enough to not + # require the santized_helper (ie, LD_PRELOAD will only use standard system + # paths (man ld.so)). + /usr/lib/chromium-browser/chromium-browser-sandbox PUxr, + /usr/lib/chromium{,-browser}/chrome-sandbox PUxr, + /opt/google/chrome{,-beta,-unstable}/chrome-sandbox PUxr, + /opt/google/chrome{,-beta,-unstable}/google-chrome Pixr, + /opt/google/chrome{,-beta,-unstable}/chrome Pixr, + /opt/google/chrome{,-beta,-unstable}/{,**/}lib*.so{,.*} m, + + # Full access + / r, + /** rwkl, + /{,usr/,usr/local/}lib{,32,64}/{,**/}*.so{,.*} m, + + # Dangerous files + audit deny owner /**/* m, # compiled libraries + audit deny owner /**/*.py* r, # python imports +} diff --git a/apparmor.d/abstractions/ubuntu-konsole b/apparmor.d/abstractions/ubuntu-konsole new file mode 100644 index 00000000..baa8fb39 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-konsole @@ -0,0 +1,17 @@ +# vim:syntax=apparmor +# +# for allowing access to konsole +# + + #include + #include + capability sys_ptrace, + @{PROC}/@{pid}/status r, + @{PROC}/@{pid}/stat r, + @{PROC}/@{pid}/cmdline r, + /{,var/}run/utmp r, + /dev/ptmx rw, + + # do not use ux or Ux here. Use at a minimum ix + /usr/bin/konsole ix, + diff --git a/apparmor.d/abstractions/ubuntu-media-players b/apparmor.d/abstractions/ubuntu-media-players new file mode 100644 index 00000000..5918cb8c --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-media-players @@ -0,0 +1,60 @@ +# vim:syntax=apparmor +# +# abstraction for allowing access to media players in Ubuntu +# +# Users of this abstraction need to #include the ubuntu-helpers abstraction +# in the toplevel profile. Eg: +# #include + + /usr/bin/amarok Cxr -> sanitized_helper, + /usr/bin/audacious2 Cxr -> sanitized_helper, + /usr/bin/audacity Cxr -> sanitized_helper, + /usr/bin/bangarang Cxr -> sanitized_helper, + /usr/bin/banshee Cxr -> sanitized_helper, + /usr/bin/banshee-1 Cxr -> sanitized_helper, + /usr/bin/decibel Cxr -> sanitized_helper, + /usr/bin/dragon Cxr -> sanitized_helper, + /usr/bin/esperanza Cxr -> sanitized_helper, + /usr/bin/exaile Cxr -> sanitized_helper, + /usr/bin/freevo Cxr -> sanitized_helper, + /usr/bin/gmerlin Cxr -> sanitized_helper, + /usr/bin/gxmms Cxr -> sanitized_helper, + /usr/bin/gxmms2 Cxr -> sanitized_helper, + /usr/bin/hornsey Cxr -> sanitized_helper, + /usr/bin/jlgui Cxr -> sanitized_helper, + /usr/bin/juk Cxr -> sanitized_helper, + /usr/bin/kaffeine Cxr -> sanitized_helper, + /usr/bin/listen Cxr -> sanitized_helper, + /usr/share/minirok/minirok.py Cxr -> sanitized_helper, + + # mplayer + /etc/mplayerplug-in.conf r, + /usr/bin/gmplayer Cxr -> sanitized_helper, + /usr/bin/gnome-mplayer Cxr -> sanitized_helper, + /usr/bin/kmplayer Cxr -> sanitized_helper, + /usr/bin/mplayer Cxr -> sanitized_helper, + /usr/bin/smplayer Cxr -> sanitized_helper, + + /usr/bin/muine Cxr -> sanitized_helper, + /usr/bin/potamus Cxr -> sanitized_helper, + /usr/bin/promoe Cxr -> sanitized_helper, + /usr/bin/qmmp Cxr -> sanitized_helper, + /usr/bin/quodlibet Cxr -> sanitized_helper, + /usr/bin/rhythmbox Cxr -> sanitized_helper, + /usr/bin/strange-quark Cxr -> sanitized_helper, + /usr/bin/swfdec-player Cxr -> sanitized_helper, + /usr/bin/timidity Cxr -> sanitized_helper, + /usr/lib/totem/** ixr, + /usr/bin/totem-gstreamer Cxr -> sanitized_helper, + /usr/bin/totem-xine Cxr -> sanitized_helper, + /usr/bin/totem Cxr -> sanitized_helper, + /usr/bin/vlc Cxr -> sanitized_helper, + /usr/bin/xfmedia Cxr -> sanitized_helper, + /usr/bin/xmms Cxr -> sanitized_helper, + + # gnash + /usr/bin/gtk-gnash ixr, + /etc/gnashrc r, + /etc/gnashpluginrc r, + owner @{HOME}/.gnash/ rw, + owner @{HOME}/.gnash/** rw, diff --git a/apparmor.d/abstractions/ubuntu-unity7-base b/apparmor.d/abstractions/ubuntu-unity7-base new file mode 100644 index 00000000..25e88b69 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-unity7-base @@ -0,0 +1,100 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2013-2014 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# +# Rules common to applications running under Unity 7 +# + +#include + +#include +#include + + # + # Access required for connecting to/communication with Unity HUD + # + dbus (send) + bus=session + path="/com/canonical/hud", + dbus (send) + bus=session + interface="com.canonical.hud.*", + dbus (send) + bus=session + path="/com/canonical/hud/applications/*", + dbus (receive) + bus=session + path="/com/canonical/hud", + dbus (receive) + bus=session + interface="com.canonical.hud.*", + + # + # Allow access for connecting to/communication with the appmenu + # + # dbusmenu + dbus (send) + bus=session + interface="com.canonical.AppMenu.*", + dbus (receive, send) + bus=session + path=/com/canonical/menu/**, + + # gmenu + dbus (receive, send) + bus=session + interface=org.gtk.Actions, + dbus (receive, send) + bus=session + interface=org.gtk.Menus, + + # + # Access required for using freedesktop notifications + # + dbus (send) + bus=session + path=/org/freedesktop/Notifications + member=GetCapabilities, + dbus (send) + bus=session + path=/org/freedesktop/Notifications + member=GetServerInformation, + dbus (send) + bus=session + path=/org/freedesktop/Notifications + member=Notify, + dbus (receive) + bus=session + member="Notify" + peer=(name="org.freedesktop.DBus"), + dbus (receive) + bus=session + path=/org/freedesktop/Notifications + member=NotificationClosed, + dbus (send) + bus=session + path=/org/freedesktop/Notifications + member=CloseNotification, + + # accessibility + dbus (send) + bus=session + peer=(name=org.a11y.Bus), + dbus (receive) + bus=session + interface=org.a11y.atspi*, + dbus (receive, send) + bus=accessibility, + + # + # Deny potentially dangerous access + # + deny dbus bus=session path=/com/canonical/[Uu]nity/[Dd]ebug**, diff --git a/apparmor.d/abstractions/ubuntu-unity7-launcher b/apparmor.d/abstractions/ubuntu-unity7-launcher new file mode 100644 index 00000000..52f6cd43 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-unity7-launcher @@ -0,0 +1,7 @@ + # + # Access required for connecting to/communicating with the Unity Launcher + # + dbus (send) + bus=session + interface="com.canonical.Unity.LauncherEntry" + member="Update", diff --git a/apparmor.d/abstractions/ubuntu-unity7-messaging b/apparmor.d/abstractions/ubuntu-unity7-messaging new file mode 100644 index 00000000..828592ee --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-unity7-messaging @@ -0,0 +1,7 @@ + # + # Access required for connecting to/communicating with the Unity messaging + # indicator + # + dbus (receive, send) + bus=session + path="/com/canonical/indicator/messages/*", diff --git a/apparmor.d/abstractions/ubuntu-xterm b/apparmor.d/abstractions/ubuntu-xterm new file mode 100644 index 00000000..a062cc72 --- /dev/null +++ b/apparmor.d/abstractions/ubuntu-xterm @@ -0,0 +1,13 @@ +# vim:syntax=apparmor +# +# for allowing access to xterm +# + + #include + /dev/ptmx rw, + /{,var/}run/utmp r, + /etc/X11/app-defaults/XTerm r, + + # do not use ux or Ux here. Use at a minimum ix + /usr/bin/xterm ix, + diff --git a/apparmor.d/abstractions/user-download b/apparmor.d/abstractions/user-download new file mode 100644 index 00000000..ea1043a3 --- /dev/null +++ b/apparmor.d/abstractions/user-download @@ -0,0 +1,24 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2014 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# Description: Where common programs should allow users to download +# files + + owner @{HOME}/tmp/** rwl, + owner @{HOME}/[dD]ownload{,s}/ r, + owner @{HOME}/[dD]ownload{,s}/** rwl, + owner @{HOME}/[^.]* rwl, + owner @{HOME}/@{XDG_DESKTOP_DIR}/ r, + owner @{HOME}/@{XDG_DESKTOP_DIR}/* rwl, + owner @{HOME}/@{XDG_DOWNLOAD_DIR}/ r, + owner @{HOME}/@{XDG_DOWNLOAD_DIR}/* rwl, + owner "@{HOME}/My Downloads/" r, + owner "@{HOME}/My Downloads/**" rwl, diff --git a/apparmor.d/abstractions/user-mail b/apparmor.d/abstractions/user-mail new file mode 100644 index 00000000..b799ffca --- /dev/null +++ b/apparmor.d/abstractions/user-mail @@ -0,0 +1,23 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2014 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # location of user mail, spool and mboxes + owner @{HOME}/[mM]ail/ r, + owner @{HOME}/[mM]ail/** rwl, + owner @{HOME}/postponed* rwl, + /var/{,spool/}mail/ r, + owner /var/{,spool/}mail/* rwl, + owner @{HOME}/mbox.lock* rwl, + owner @{HOME}/mbox rw, + owner @{HOME}/inbox rw, + owner @{HOME}/.forward r, + owner @{HOME}/Maildir/ r, + owner @{HOME}/Maildir/** rwl, diff --git a/apparmor.d/abstractions/user-manpages b/apparmor.d/abstractions/user-manpages new file mode 100644 index 00000000..b7cc0cb8 --- /dev/null +++ b/apparmor.d/abstractions/user-manpages @@ -0,0 +1,24 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # perhaps your configuration has users elsewhere, or you don't wish + # them to read their own manpages + owner @{HOME}/man/ r, + owner @{HOME}/man/** r, + owner @{HOME}/tmp/groff* rwl, + + # kindof required + owner /tmp/groff* rwl, + + # standard system manpages + /usr/local/share/man/man?/ r, + /usr/local/share/man/man?/** r, + /usr/{share,X11R6,local,kerberos}/man/** r, + /usr/man/** r, diff --git a/apparmor.d/abstractions/user-tmp b/apparmor.d/abstractions/user-tmp new file mode 100644 index 00000000..63993d60 --- /dev/null +++ b/apparmor.d/abstractions/user-tmp @@ -0,0 +1,20 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009-2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # per-user tmp directories + owner @{HOME}/tmp/** rwkl, + owner @{HOME}/tmp/ rw, + + # global tmp directories + owner /var/tmp/** rwkl, + /var/tmp/ rw, + owner /tmp/** rwkl, + /tmp/ rw, diff --git a/apparmor.d/abstractions/user-write b/apparmor.d/abstractions/user-write new file mode 100644 index 00000000..c6ea29bd --- /dev/null +++ b/apparmor.d/abstractions/user-write @@ -0,0 +1,21 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2014 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # per-user write directories + owner @{HOME}/ r, + owner @{HOME}/@{XDG_DESKTOP_DIR}/ r, + owner @{HOME}/@{XDG_DOCUMENTS_DIR}/ r, + owner @{HOME}/@{XDG_PUBLICSHARE_DIR}/ r, + owner @{HOME}/[^.]*/ rw, + owner @{HOME}/[^.]* rwl, + owner @{HOME}/@{XDG_DESKTOP_DIR}/** rwl, + owner @{HOME}/@{XDG_DOCUMENTS_DIR}/** rwl, + owner @{HOME}/@{XDG_PUBLICSHARE_DIR}/** rwl, diff --git a/apparmor.d/abstractions/video b/apparmor.d/abstractions/video new file mode 100644 index 00000000..00a83468 --- /dev/null +++ b/apparmor.d/abstractions/video @@ -0,0 +1,6 @@ +# vim:syntax=apparmor +# video device access + + # System devices + @{sys}/class/video4linux r, + @{sys}/class/video4linux/** r, diff --git a/apparmor.d/abstractions/vulkan b/apparmor.d/abstractions/vulkan new file mode 100644 index 00000000..04c8ec26 --- /dev/null +++ b/apparmor.d/abstractions/vulkan @@ -0,0 +1,20 @@ +# vim:syntax=apparmor +# Vulkan access requirements + + # System files + /dev/dri/ r, # libvulkan_radeon.so, libvulkan_intel.so (Mesa) + /etc/glvnd/egl_vendor.d/{*,.json} r, + /etc/vulkan/icd.d/{,*.json} r, + /etc/vulkan/{explicit,implicit}_layer.d/{,*.json} r, + # for drmGetMinorNameForFD() from libvulkan_intel.so (Mesa) + @{sys}/devices/pci[0-9]*/*/drm/ r, + @{sys}/devices/pci[0-9]*/*/drm/card[0-9]/gt_{max,min}_freq_mhz r, # anv_enumerate_physical_devices() from libvulkan_intel.so + @{sys}/devices/pci[0-9]*/*/drm/card[0-9]/metrics/ r, # anv_enumerate_physical_devices() from libvulkan_intel.so + @{sys}/devices/pci[0-9]*/*/drm/card[0-9]/metrics/????????-????-????-????-????????????/id r, # anv_enumerate_physical_devices() from libvulkan_intel.so + /usr/share/glvnd/egl_vendor.d/{,*.json} r, + /usr/share/vulkan/icd.d/{,*.json} r, + /usr/share/vulkan/{explicit,implicit}_layer.d/{,*.json} r, + + # User files + owner @{HOME}/.local/share/vulkan/implicit_layer.d/{,*.json} r, + diff --git a/apparmor.d/abstractions/wayland b/apparmor.d/abstractions/wayland new file mode 100644 index 00000000..f5290b28 --- /dev/null +++ b/apparmor.d/abstractions/wayland @@ -0,0 +1,14 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2016 intrigeri +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + owner /var/run/user/*/weston-shared-* rw, + owner /run/user/*/wayland-[0-9]* rw, + owner /run/user/*/{mesa,mutter,sdl,wayland-cursor,weston,xwayland}-shared-* rw, diff --git a/apparmor.d/abstractions/web-data b/apparmor.d/abstractions/web-data new file mode 100644 index 00000000..0baf2990 --- /dev/null +++ b/apparmor.d/abstractions/web-data @@ -0,0 +1,25 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2006 Novell/SUSE +# Copyright (C) 2014 Canonical Ltd +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /srv/www/htdocs/ r, + /srv/www/htdocs/** r, + # virtual hosting + /srv/www/vhosts/ r, + /srv/www/vhosts/** r, + # mod_userdir + @{HOME}/public_html/ r, + @{HOME}/public_html/** r, + + /srv/www/rails/*/public/ r, + /srv/www/rails/*/public/** r, + + /var/www/html/ r, + /var/www/html/** r, diff --git a/apparmor.d/abstractions/winbind b/apparmor.d/abstractions/winbind new file mode 100644 index 00000000..e982889e --- /dev/null +++ b/apparmor.d/abstractions/winbind @@ -0,0 +1,21 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # pam_winbindd + /tmp/.winbindd/pipe rw, + /var/{lib,run}/samba/winbindd_privileged/pipe rw, + /etc/samba/smb.conf r, + /etc/samba/dhcp.conf r, + /usr/lib*/samba/valid.dat r, + /usr/lib*/samba/upcase.dat r, + /usr/lib*/samba/lowcase.dat r, + /usr/share/samba/codepages/{lowcase,upcase,valid}.dat r, + diff --git a/apparmor.d/abstractions/wutmp b/apparmor.d/abstractions/wutmp new file mode 100644 index 00000000..d7509558 --- /dev/null +++ b/apparmor.d/abstractions/wutmp @@ -0,0 +1,16 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2002-2009 Novell/SUSE +# Copyright (C) 2009 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # some services update wtmp, utmp, and lastlog with per-user + # connection information + /var/log/lastlog rwk, + /var/log/wtmp wk, + /{,var/}run/utmp rwk, diff --git a/apparmor.d/abstractions/xad b/apparmor.d/abstractions/xad new file mode 100644 index 00000000..54b0f40e --- /dev/null +++ b/apparmor.d/abstractions/xad @@ -0,0 +1,25 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2007 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + /opt/novell/xad/lib/ r, + /opt/novell/xad/lib/lib*.so* mr, + /opt/novell/xad/lib/gss/*.so* mr, + /opt/novell/lib/libpthread_ext*.so* mr, + /opt/novell/lib/libccs2.so* mr, + /opt/novell/xad/lib64/ r, + /opt/novell/xad/lib64/lib*.so* mr, + /opt/novell/xad/lib64/gss/*.so* mr, + /opt/novell/lib64/libpthread_ext*.so* mr, + /opt/novell/lib64/libccs2.so* mr, + /etc/opt/novell/xad/krb5.conf r, + /etc/opt/novell/nici.cfg r, + /var/opt/novell/nici/* r, + /var/opt/novell/nici/*/ r, + /var/opt/novell/nici/*/* rw, diff --git a/apparmor.d/abstractions/xdg-desktop b/apparmor.d/abstractions/xdg-desktop new file mode 100644 index 00000000..bc8f6a00 --- /dev/null +++ b/apparmor.d/abstractions/xdg-desktop @@ -0,0 +1,24 @@ +# vim:syntax=apparmor +# ------------------------------------------------------------------ +# +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + + # Entries based on: + # http://standards.freedesktop.org/basedir-spec/basedir-spec-latest.html + + owner @{HOME}/.cache/ rw, + + owner @{HOME}/.config/ rw, + + owner @{HOME}/.local/ rw, + owner @{HOME}/.local/share/ rw, + + # fallbacks + /usr/share/ r, + /usr/local/share/ r, diff --git a/apparmor.d/abstractions/xdg-open b/apparmor.d/abstractions/xdg-open new file mode 100644 index 00000000..531022e3 --- /dev/null +++ b/apparmor.d/abstractions/xdg-open @@ -0,0 +1,84 @@ +# vim:syntax=apparmor + +# This abstraction is designed to be used in a child profile to limit what +# confined application can invoke via xdg-open helper. xdg-open abstraction +# will allow to use gio-open, kde-open5 and other helpers of the different +# desktop environments. +# +# Usage example: +# +# ``` +# profile foo /usr/bin/foo { +# ... +# /usr/bin/xdg-open rPx -> foo//xdg-open, +# ... +# } # end of main profile +# +# # out-of-line child profile +# profile foo//xdg-open { +# #include +# +# # Enable a11y support if considered required by +# # profile author for (rare) error message boxes. +# #include +# +# # Enable gstreamer support if considered required by +# # profile author for (rare) error message boxes. +# #include if exists +# +# # needed for ubuntu-* abstractions +# #include +# +# # Only allow to handle http[s]: and mailto: links +# #include +# #include +# +# # < add additional allowed applications here > +# } +# ``` + + #include + + # for openin with `exo-open` + #include + + # for opening with `gio open ` + #include + + # for opening with gvfs-open (deprecated) + #include + + # for opening with kde-open5 + #include + + # Main executables + + /{,usr/}bin/{b,d}ash mr, + /usr/bin/xdg-open r, + + # Additional executables + + /usr/bin/xdg-mime rix, + /{,usr/}bin/cut rix, # for xdg-mime + /{,usr/}bin/head rix, # for xdg-mime + /{,usr/}bin/sed rix, # for xdg-open + /{,usr/}bin/tr rix, # for xdg-mime + /{,usr/}bin/which rix, # for xdg-open + /{,usr/}bin/{grep,egrep} rix, # for xdg-open + + # System files + + /dev/pts/[0-9]* rw, + /dev/tty w, + /etc/gnome/defaults.list r, # for grep + /usr/share/applications/mimeinfo.cache r, # for grep + /usr/share/terminfo/s/screen r, # for bash on openSUSE + /usr/share/{,*/}applications/{,*.desktop} r, # for xdg-mime + /var/lib/menu-xdg/applications/ r, # for xdg-mime + + # Usr files + + owner @{HOME}/.local/share/applications/{,*.desktop} r, + + # Include additions to the abstraction + #include if exists diff --git a/apparmor.d/local/README b/apparmor.d/local/README new file mode 100644 index 00000000..a3cf2e49 --- /dev/null +++ b/apparmor.d/local/README @@ -0,0 +1,24 @@ +# This directory is intended to contain profile additions and overrides for +# inclusion by distributed profiles to aid in packaging AppArmor for +# distributions. +# +# The shipped profiles in /etc/apparmor.d can still be modified by an +# administrator and people should modify the shipped profile when making +# large policy changes, rather than trying to make those adjustments here. +# +# For simple access additions or the occasional deny override, adjusting them +# here can prevent the package manager of the distribution from interfering +# with local modifications. As always, new policy should be reviewed to ensure +# it is appropriate for your site. +# +# For example, if the shipped /etc/apparmor.d/usr.sbin.smbd profile has: +# #include +# +# then an administrator can adjust /etc/apparmor.d/local/usr.sbin.smbd to +# contain any additional paths to be allowed, such as: +# +# /var/exports/** lrwk, +# +# Keep in mind that 'deny' rules are evaluated after allow rules, so you won't +# be able to allow access to files that are explicitly denied by the shipped +# profile using this mechanism. diff --git a/apparmor.d/local/lsb_release b/apparmor.d/local/lsb_release new file mode 100644 index 00000000..e69de29b diff --git a/apparmor.d/local/nvidia_modprobe b/apparmor.d/local/nvidia_modprobe new file mode 100644 index 00000000..e69de29b diff --git a/apparmor.d/local/usr.bin.man b/apparmor.d/local/usr.bin.man new file mode 100644 index 00000000..e69de29b diff --git a/apparmor.d/lsb_release b/apparmor.d/lsb_release new file mode 100644 index 00000000..5c05ba4d --- /dev/null +++ b/apparmor.d/lsb_release @@ -0,0 +1,50 @@ +# Note: This profile does not specify an attachment path because it is +# intended to be used only via "Px -> lsb_release" exec transitions from +# other profiles. We want to confine the lsb_release(1) utility when it +# is invoked from other confined applications, but not when it is used +# in regular (unconfined) shell scripts or run directly by the user. + +#include + +# Do not attach to /usr/bin/lsb_release by default +profile lsb_release { + #include + #include + + owner @{PROC}/@{pid}/fd/ r, + + /dev/tty rw, + + /usr/bin/lsb_release r, + /usr/bin/python3.[0-9] mr, + + /etc/debian_version r, + /etc/default/apport r, + /etc/dpkg/origins/** r, + /etc/lsb-release r, + /etc/lsb-release.d/ r, + + /{usr/,}bin/bash ixr, + /{usr/,}bin/dash ixr, + /usr/bin/basename ixr, + /usr/bin/dpkg-query ixr, + /usr/bin/getopt ixr, + /usr/bin/sed ixr, + /usr/bin/tr ixr, + + # TODO - many more permissions needed for this to work + deny /usr/bin/apt-cache x, + + /usr/bin/ r, + /usr/include/python*/pyconfig.h r, + /usr/share/distro-info/** r, + /usr/share/dpkg/** r, + /usr/share/terminfo/** r, + /var/lib/dpkg/** r, + + # file_inherit + deny /tmp/gtalkplugin.log w, + + # Site-specific additions and overrides. See local/README for details. + #include +} diff --git a/apparmor.d/nvidia_modprobe b/apparmor.d/nvidia_modprobe new file mode 100644 index 00000000..2c29b997 --- /dev/null +++ b/apparmor.d/nvidia_modprobe @@ -0,0 +1,65 @@ +# vim:syntax=apparmor + +#include + +profile nvidia_modprobe { + #include + + # Capabilities + + capability chown, + capability mknod, + capability setuid, + capability sys_admin, + + # Main executable + + /usr/bin/nvidia-modprobe mr, + + # Other executables + + /usr/bin/kmod Cx -> kmod, + + # System files + + /dev/nvidia-modeset w, + /dev/nvidia-uvm w, + /dev/nvidia-uvm-tools w, + @{sys}/bus/pci/devices/ r, + @{sys}/devices/pci[0-9]*/**/config r, + @{PROC}/devices r, + @{PROC}/driver/nvidia/params r, + @{PROC}/modules r, + @{PROC}/sys/kernel/modprobe r, + + # Child profiles + + profile kmod { + #include + + # Capabilities + + capability sys_module, + + # Main executable + + /usr/bin/kmod mrix, + + # Other executables + + /{,usr/}bin/{,ba,da}sh ix, + + # System files + + /etc/modprobe.d/{,*.conf} r, + /etc/nvidia/current/*.conf r, + @{sys}/module/ipmi_devintf/initstate r, + @{sys}/module/ipmi_msghandler/initstate r, + @{sys}/module/nvidia/initstate r, + @{PROC}/cmdline r, + } + + # Site-specific additions and overrides. See local/README for details. + #include +} + diff --git a/apparmor.d/tunables/alias b/apparmor.d/tunables/alias new file mode 100644 index 00000000..a0c55c4f --- /dev/null +++ b/apparmor.d/tunables/alias @@ -0,0 +1,16 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# Alias rules can be used to rewrite paths and are done after variable +# resolution. For example, if '/usr' is on removable media: +# alias /usr/ -> /mnt/usr/, +# +# Or if mysql databases are stored in /home: +# alias /var/lib/mysql/ -> /home/mysql/, diff --git a/apparmor.d/tunables/apparmorfs b/apparmor.d/tunables/apparmorfs new file mode 100644 index 00000000..8df86759 --- /dev/null +++ b/apparmor.d/tunables/apparmorfs @@ -0,0 +1,11 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +#include + +@{apparmorfs}=@{securityfs}/apparmor/ diff --git a/apparmor.d/tunables/dovecot b/apparmor.d/tunables/dovecot new file mode 100644 index 00000000..702da58e --- /dev/null +++ b/apparmor.d/tunables/dovecot @@ -0,0 +1,20 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2013 Christian Boltz +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ +# vim:ft=apparmor + +# @{DOVECOT_MAILSTORE} is a space-separated list of all directories +# where dovecot is allowed to store and read mails +# +# The default value is quite broad to avoid breaking existing setups. +# Please change @{DOVECOT_MAILSTORE} to (only) contain the directory +# you use, and remove everything else. + +@{DOVECOT_MAILSTORE}=@{HOME}/Maildir/ @{HOME}/mail/ @{HOME}/Mail/ /var/vmail/ /var/mail/ /var/spool/mail/ + diff --git a/apparmor.d/tunables/global b/apparmor.d/tunables/global new file mode 100644 index 00000000..3b6f99cc --- /dev/null +++ b/apparmor.d/tunables/global @@ -0,0 +1,22 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2006-2009 Novell/SUSE +# Copyright (C) 2010-2014 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# All the tunables definitions that should be available to every profile +# should be included here + +#include +#include +#include +#include +#include +#include +#include +#include diff --git a/apparmor.d/tunables/home b/apparmor.d/tunables/home new file mode 100644 index 00000000..550ccd5d --- /dev/null +++ b/apparmor.d/tunables/home @@ -0,0 +1,25 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2006-2009 Novell/SUSE +# Copyright (C) 2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# @{HOME} is a space-separated list of all user home directories. While +# it doesn't refer to a specific home directory (AppArmor doesn't +# enforce discretionary access controls) it can be used as if it did +# refer to a specific home directory +@{HOME}=@{HOMEDIRS}/*/ /root/ + +# @{HOMEDIRS} is a space-separated list of where user home directories +# are stored, for programs that must enumerate all home directories on a +# system. +@{HOMEDIRS}=/home/ + +# Also, include files in tunables/home.d for site-specific adjustments to +# @{HOMEDIRS}. +#include diff --git a/apparmor.d/tunables/home.d/site.local b/apparmor.d/tunables/home.d/site.local new file mode 100644 index 00000000..e6796a0c --- /dev/null +++ b/apparmor.d/tunables/home.d/site.local @@ -0,0 +1,13 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2010 Canonical Ltd. +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# The following is a space-separated list of where additional user home +# directories are stored, each must have a trailing '/'. Directories added +# here are appended to @{HOMEDIRS}. See tunables/home for details. Eg: +#@{HOMEDIRS}+=/srv/nfs/home/ /mnt/home/ diff --git a/apparmor.d/tunables/home.d/ubuntu b/apparmor.d/tunables/home.d/ubuntu new file mode 100644 index 00000000..32db0928 --- /dev/null +++ b/apparmor.d/tunables/home.d/ubuntu @@ -0,0 +1,7 @@ +# This file is auto-generated. It is recommended you update it using: +# $ sudo dpkg-reconfigure apparmor +# +# The following is a space-separated list of where additional user home +# directories are stored, each must have a trailing '/'. Directories added +# here are appended to @{HOMEDIRS}. See tunables/home for details. +#@{HOMEDIRS}+= diff --git a/apparmor.d/tunables/kernelvars b/apparmor.d/tunables/kernelvars new file mode 100644 index 00000000..65ee2667 --- /dev/null +++ b/apparmor.d/tunables/kernelvars @@ -0,0 +1,33 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# This file should contain declarations to kernel vars or variables +# that will become kernel vars at some point + +# until kernel vars are implemented +# and until the parser supports nested groupings like +# @{pid}=[1-9]{[0-9]{[0-9]{[0-9]{[0-9]{[0-9],},},},},} +# use +@{pid}={[1-9],[1-9][0-9],[1-9][0-9][0-9],[1-9][0-9][0-9][0-9],[1-9][0-9][0-9][0-9][0-9],[1-9][0-9][0-9][0-9][0-9][0-9],[1-4][0-9][0-9][0-9][0-9][0-9][0-9]} + +#same pattern as @{pid} for now +@{tid}=@{pid} + +#A pattern for pids that can appear +@{pids}=@{pid} + +# Placeholder for user id until kernel var is implemented to match +# current user of the confined application. +# Values are 0...4,294,967,295 (32-bit unsigned, 10 digits). +@{uid}={[0-9],[1-9][0-9],[1-9][0-9][0-9],[1-9][0-9][0-9][0-9],[1-9][0-9][0-9][0-9][0-9],[1-9][0-9][0-9][0-9][0-9][0-9],[1-9][0-9][0-9][0-9][0-9][0-9][0-9],[1-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9],[1-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9],[1-4][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]} + +#same pattern as @{uid} for now +@{uids}=@{uid} + +# until kernel var is implemented +@{sys}=/sys/ diff --git a/apparmor.d/tunables/multiarch b/apparmor.d/tunables/multiarch new file mode 100644 index 00000000..c54082e0 --- /dev/null +++ b/apparmor.d/tunables/multiarch @@ -0,0 +1,17 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2010 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# @{multiarch} is the set of patterns matching multi-arch library +# install prefixes. +@{multiarch}=*-linux-gnu* + +# Also, include files in tunables/multiarch.d for site and packaging +# specific adjustments to @{multiarch}. +#include diff --git a/apparmor.d/tunables/multiarch.d/site.local b/apparmor.d/tunables/multiarch.d/site.local new file mode 100644 index 00000000..91877e2a --- /dev/null +++ b/apparmor.d/tunables/multiarch.d/site.local @@ -0,0 +1,14 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2011 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# The following is a space-separated list of where additional multipath +# prefixes are stored, each should not have a trailing '/'. Directories +# added here are appended to @{multiarch}. See tunables/mutliarch for details. Eg: +#@{multiarch}+=*-freebsd* s390-hurd-zomg diff --git a/apparmor.d/tunables/proc b/apparmor.d/tunables/proc new file mode 100644 index 00000000..25a1964d --- /dev/null +++ b/apparmor.d/tunables/proc @@ -0,0 +1,12 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2006 Novell/SUSE +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# @{PROC} is the location where procfs is mounted. +@{PROC}=/proc/ diff --git a/apparmor.d/tunables/run b/apparmor.d/tunables/run new file mode 100644 index 00000000..5b81925e --- /dev/null +++ b/apparmor.d/tunables/run @@ -0,0 +1 @@ +@{run}=/run/ /var/run/ diff --git a/apparmor.d/tunables/securityfs b/apparmor.d/tunables/securityfs new file mode 100644 index 00000000..c572139f --- /dev/null +++ b/apparmor.d/tunables/securityfs @@ -0,0 +1,10 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# @{securityfs} is the location where securityfs is mounted. +@{securityfs}=@{sys}/kernel/security/ diff --git a/apparmor.d/tunables/share b/apparmor.d/tunables/share new file mode 100644 index 00000000..f41121c8 --- /dev/null +++ b/apparmor.d/tunables/share @@ -0,0 +1,15 @@ +@{flatpak_exports_root} = {flatpak/exports,flatpak/{app,runtime}/*/*/*/*/export} + +# System-wide directories with behaviour analogous to /usr/share +# in patterns like the freedesktop.org basedir spec. These are +# owned by root or a system user, appear in XDG_DATA_DIRS, and +# are the parent directory for `applications`, `themes`, +# `dbus-1/services`, etc. +@{system_share_dirs} = /{usr,usr/local,var/lib/@{flatpak_exports_root}}/share + +# Per-user/personal directories with behaviour analogous to +# ~/.local/share in patterns like the freedesktop.org basedir spec. +# These are owned by the user running an application, appear in +# XDG_DATA_DIRS or XDG_DATA_HOME, and are the parent directory +# for the same subdirectories as @{system_share_dirs} +@{user_share_dirs} = @{HOME}/.local{,/share/@{flatpak_exports_root}}/share diff --git a/apparmor.d/tunables/sys b/apparmor.d/tunables/sys new file mode 100644 index 00000000..c5257e30 --- /dev/null +++ b/apparmor.d/tunables/sys @@ -0,0 +1,9 @@ +# Copyright (C) 2012 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +#This file is DEPRECATED! @{sys} is defined in tunables/kernelvars now. diff --git a/apparmor.d/tunables/xdg-user-dirs b/apparmor.d/tunables/xdg-user-dirs new file mode 100644 index 00000000..fcaf8d40 --- /dev/null +++ b/apparmor.d/tunables/xdg-user-dirs @@ -0,0 +1,24 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2014 Canonical Ltd. +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# Define the common set of XDG user directories (usually defined in +# /etc/xdg/user-dirs.defaults) +@{XDG_DESKTOP_DIR}="Desktop" +@{XDG_DOWNLOAD_DIR}="Downloads" +@{XDG_TEMPLATES_DIR}="Templates" +@{XDG_PUBLICSHARE_DIR}="Public" +@{XDG_DOCUMENTS_DIR}="Documents" +@{XDG_MUSIC_DIR}="Music" +@{XDG_PICTURES_DIR}="Pictures" +@{XDG_VIDEOS_DIR}="Videos" + +# Also, include files in tunables/xdg-user-dirs.d for site-specific adjustments +# to the various XDG directories +#include diff --git a/apparmor.d/tunables/xdg-user-dirs.d/site.local b/apparmor.d/tunables/xdg-user-dirs.d/site.local new file mode 100644 index 00000000..8fcabfa0 --- /dev/null +++ b/apparmor.d/tunables/xdg-user-dirs.d/site.local @@ -0,0 +1,21 @@ +# ------------------------------------------------------------------ +# +# Copyright (C) 2014 Canonical Ltd. +# This program is free software; you can redistribute it and/or +# modify it under the terms of version 2 of the GNU General Public +# License published by the Free Software Foundation. +# +# ------------------------------------------------------------------ + +# The following may be used to add additional entries such as for +# translations. See tunables/xdg-user-dirs for details. Eg: +#@{XDG_MUSIC_DIR}+="Musique" + +#@{XDG_DESKTOP_DIR}+="" +#@{XDG_DOWNLOAD_DIR}+="" +#@{XDG_TEMPLATES_DIR}+="" +#@{XDG_PUBLICSHARE_DIR}+="" +#@{XDG_DOCUMENTS_DIR}+="" +#@{XDG_MUSIC_DIR}+="" +#@{XDG_PICTURES_DIR}+="" +#@{XDG_VIDEOS_DIR}+="" diff --git a/apparmor.d/usr.bin.man b/apparmor.d/usr.bin.man new file mode 100644 index 00000000..b6cd0be6 --- /dev/null +++ b/apparmor.d/usr.bin.man @@ -0,0 +1,113 @@ +# vim:syntax=apparmor + +#include + +/usr/bin/man { + #include + + # Use a special profile when man calls anything groff-related. We only + # include the programs that actually parse input data in a non-trivial + # way, not wrappers such as groff and nroff, since the latter would need a + # broader profile. + /usr/bin/eqn rmCx -> &man_groff, + /usr/bin/grap rmCx -> &man_groff, + /usr/bin/pic rmCx -> &man_groff, + /usr/bin/preconv rmCx -> &man_groff, + /usr/bin/refer rmCx -> &man_groff, + /usr/bin/tbl rmCx -> &man_groff, + /usr/bin/troff rmCx -> &man_groff, + /usr/bin/vgrind rmCx -> &man_groff, + + # Similarly, use a special profile when man calls decompressors and other + # simple filters. + /{,usr/}bin/bzip2 rmCx -> &man_filter, + /{,usr/}bin/gzip rmCx -> &man_filter, + /usr/bin/col rmCx -> &man_filter, + /usr/bin/compress rmCx -> &man_filter, + /usr/bin/iconv rmCx -> &man_filter, + /usr/bin/lzip.lzip rmCx -> &man_filter, + /usr/bin/tr rmCx -> &man_filter, + /usr/bin/xz rmCx -> &man_filter, + + # Allow basically anything in terms of file system access, subject to DAC. + # The purpose of this profile isn't to confine man itself (that might be + # nice in the future, but is tricky since it's quite configurable), but to + # confine the processes it calls that parse untrusted data. + /** mrixwlk, + unix, + + capability setuid, + capability setgid, + + # Ordinary permission checks sometimes involve checking whether the + # process has this capability, which can produce audit log messages. + # Silence them. + deny capability dac_override, + deny capability dac_read_search, + + signal peer=@{profile_name}, + signal peer=/usr/bin/man//&man_groff, + signal peer=/usr/bin/man//&man_filter, + + # Site-specific additions and overrides. See local/README for details. + #include +} + +profile man_groff { + #include + # Recent kernels revalidate open FDs, and there are often some still + # open on TTYs. This is temporary until man learns to close irrelevant + # open FDs before execve. + #include + # man always runs its groff pipeline with the input file open on stdin, + # so we can skip . + + /usr/bin/eqn rm, + /usr/bin/grap rm, + /usr/bin/pic rm, + /usr/bin/preconv rm, + /usr/bin/refer rm, + /usr/bin/tbl rm, + /usr/bin/troff rm, + /usr/bin/vgrind rm, + + /etc/groff/** r, + /etc/papersize r, + /usr/lib/groff/site-tmac/** r, + /usr/share/groff/** r, + + /tmp/groff* rw, + + signal peer=/usr/bin/man, + # @{profile_name} doesn't seem to work here. + signal peer=/usr/bin/man//&man_groff, +} + +profile man_filter { + #include + # Recent kernels revalidate open FDs, and there are often some still + # open on TTYs. This is temporary until man learns to close irrelevant + # open FDs before execve. + #include + + /{,usr/}bin/bzip2 rm, + /{,usr/}bin/gzip rm, + /usr/bin/col rm, + /usr/bin/compress rm, + /usr/bin/iconv rm, + /usr/bin/lzip.lzip rm, + /usr/bin/tr rm, + /usr/bin/xz rm, + + # Manual pages can be more or less anywhere, especially with "man -l", and + # there's no harm in allowing wide read access here since the worst it can + # do is feed data to the invoking man process. + /** r, + + # Allow writing cat pages. + /var/cache/man/** w, + + signal peer=/usr/bin/man, + # @{profile_name} doesn't seem to work here. + signal peer=/usr/bin/man//&man_filter, +} diff --git a/apparmor.d/usr.sbin.mariadbd b/apparmor.d/usr.sbin.mariadbd new file mode 100644 index 00000000..b1f229b3 --- /dev/null +++ b/apparmor.d/usr.sbin.mariadbd @@ -0,0 +1,15 @@ +# This file is intentionally empty to disable apparmor by default for newer +# versions of MariaDB, while providing seamless upgrade from older versions +# and from mysql, where apparmor is used. +# +# By default, we do not want to have any apparmor profile for the MariaDB +# server. It does not provide much useful functionality/security, and causes +# several problems for users who often are not even aware that apparmor +# exists and runs on their system. +# +# Users can modify and maintain their own profile, and in this case it will +# be used. +# +# When upgrading from previous version, users who modified the profile +# will be prompted to keep or discard it, while for default installs +# we will automatically disable the profile. diff --git a/apparmor/init/network-interface-security/usr.sbin.ntpd b/apparmor/init/network-interface-security/usr.sbin.ntpd new file mode 120000 index 00000000..dbd958f8 --- /dev/null +++ b/apparmor/init/network-interface-security/usr.sbin.ntpd @@ -0,0 +1 @@ +../../../apparmor.d/usr.sbin.ntpd \ No newline at end of file diff --git a/apparmor/parser.conf b/apparmor/parser.conf new file mode 100644 index 00000000..58d0d2da --- /dev/null +++ b/apparmor/parser.conf @@ -0,0 +1,65 @@ +# parser.conf is a global AppArmor config file for the apparmor_parser +# +# It can be used to specify the default options for the parser, which +# can then be overriden by options passed on the command line. +# +# Leading whitespace is ignored and lines that begin with # are treated +# as comments. +# +# Config options are specified one per line using the same format as the +# longform command line options (without the preceding --). +# +# If a value is specified twice the last version to appear is used. + +## Suppress Warnings +#quiet + +## Be verbose +#verbose + +## Set additional include path +#Include /etc/apparmor.d/ +# or +#Include /usr/share/apparmor + + +## Set location of apparmor filesystem +#subdomainfs /sys/kernel/security/apparmor + +## Set match-string to use - for forcing compiler to treat different kernels +## the same +# match-string "pattern=aadfa audit perms=crwxamlk/ user::other" + +## Turn creating/updating of the cache on by default +#write-cache + +## Show cache hits +#show-cache + +## skip cached policy +#skip-cache + +## skip reading cache but allow updating +#skip-read-cache + + +#### Set Optimizaions. Multiple Optimizations can be set, one per line #### +# For supported optimizations see +# apparmor_parser --help=O + +## Turn on equivalence classes +#equiv + +## Turn off expr tree simplification +#Optimize=no-expr-simplify + +## Turn off DFA minimization +#Optimize=no-minimize + +## Adjust compression +#Optimize=compress-small +#Optimize=compress-fast + +## Pin the policy feature set (avoid regressions when policy is lagging behind +## the kernel) +compile-features=/usr/share/apparmor-features/features diff --git a/apt/apt.conf.d/00CDMountPoint b/apt/apt.conf.d/00CDMountPoint new file mode 100644 index 00000000..6a2c664f --- /dev/null +++ b/apt/apt.conf.d/00CDMountPoint @@ -0,0 +1,4 @@ +Acquire::cdrom { + mount "/media/cdrom"; +}; +Dir::Media::MountPath "/media/cdrom"; diff --git a/apt/apt.conf.d/00trustcdrom b/apt/apt.conf.d/00trustcdrom new file mode 100644 index 00000000..c7588cb4 --- /dev/null +++ b/apt/apt.conf.d/00trustcdrom @@ -0,0 +1 @@ +APT::Authentication::TrustCDROM "true"; diff --git a/apt/apt.conf.d/01autoremove b/apt/apt.conf.d/01autoremove new file mode 100644 index 00000000..478c571e --- /dev/null +++ b/apt/apt.conf.d/01autoremove @@ -0,0 +1,41 @@ +APT +{ + NeverAutoRemove + { + "^firmware-linux.*"; + "^linux-firmware$"; + "^linux-image-[a-z0-9]*$"; + "^linux-image-[a-z0-9]*-[a-z0-9]*$"; + }; + + VersionedKernelPackages + { + # kernels + "linux-.*"; + "kfreebsd-.*"; + "gnumach-.*"; + # (out-of-tree) modules + ".*-modules"; + ".*-kernel"; + }; + + Never-MarkAuto-Sections + { + "metapackages"; + "contrib/metapackages"; + "non-free/metapackages"; + "restricted/metapackages"; + "universe/metapackages"; + "multiverse/metapackages"; + }; + + Move-Autobit-Sections + { + "oldlibs"; + "contrib/oldlibs"; + "non-free/oldlibs"; + "restricted/oldlibs"; + "universe/oldlibs"; + "multiverse/oldlibs"; + }; +}; diff --git a/apt/apt.conf.d/01autoremove-kernels b/apt/apt.conf.d/01autoremove-kernels new file mode 100644 index 00000000..bede81d4 --- /dev/null +++ b/apt/apt.conf.d/01autoremove-kernels @@ -0,0 +1,2 @@ +// DO NOT EDIT! File autogenerated by /etc/kernel/postinst.d/apt-auto-removal +APT::LastInstalledKernel "5.10.0-15-amd64"; diff --git a/apt/apt.conf.d/05etckeeper b/apt/apt.conf.d/05etckeeper new file mode 100644 index 00000000..5e690a2d --- /dev/null +++ b/apt/apt.conf.d/05etckeeper @@ -0,0 +1,5 @@ +DPkg::Pre-Invoke { "if [ -x /usr/bin/etckeeper ]; then etckeeper pre-install; fi"; }; +DPkg::Post-Invoke { "if [ -x /usr/bin/etckeeper ]; then etckeeper post-install; fi"; }; + +RPM::Pre-Invoke { "if [ -x /usr/bin/etckeeper ]; then etckeeper pre-install; fi"; }; +RPM::Post-Invoke { "if [ -x /usr/bin/etckeeper ]; then etckeeper post-install; fi"; }; diff --git a/apt/apt.conf.d/20listchanges b/apt/apt.conf.d/20listchanges new file mode 100644 index 00000000..4af5989d --- /dev/null +++ b/apt/apt.conf.d/20listchanges @@ -0,0 +1,5 @@ +DPkg::Pre-Install-Pkgs { "/usr/bin/apt-listchanges --apt || test $? -lt 10"; }; +DPkg::Tools::Options::/usr/bin/apt-listchanges::Version "2"; +DPkg::Tools::Options::/usr/bin/apt-listchanges::InfoFD "20"; +Dir::Etc::apt-listchanges-main "listchanges.conf"; +Dir::Etc::apt-listchanges-parts "listchanges.conf.d"; diff --git a/apt/apt.conf.d/70debconf b/apt/apt.conf.d/70debconf new file mode 100644 index 00000000..0c8b4ca4 --- /dev/null +++ b/apt/apt.conf.d/70debconf @@ -0,0 +1,3 @@ +// Pre-configure all packages with debconf before they are installed. +// If you don't like it, comment it out. +DPkg::Pre-Install-Pkgs {"/usr/sbin/dpkg-preconfigure --apt || true";}; diff --git a/apt/keyrings/rspamd.gpg b/apt/keyrings/rspamd.gpg new file mode 100644 index 00000000..54cb4213 Binary files /dev/null and b/apt/keyrings/rspamd.gpg differ diff --git a/apt/listchanges.conf b/apt/listchanges.conf new file mode 100644 index 00000000..d2056d62 --- /dev/null +++ b/apt/listchanges.conf @@ -0,0 +1,10 @@ +[apt] +frontend=pager +which=news +email_address=root +email_format=text +confirm=false +headers=false +reverse=false +save_seen=/var/lib/apt/listchanges.db + diff --git a/apt/preferences.d/mariadb-enterprise.pref b/apt/preferences.d/mariadb-enterprise.pref new file mode 100644 index 00000000..7cc49b4a --- /dev/null +++ b/apt/preferences.d/mariadb-enterprise.pref @@ -0,0 +1,3 @@ +Package: * +Pin: origin dlm.mariadb.com +Pin-Priority: 1000 diff --git a/apt/sources.list b/apt/sources.list new file mode 100644 index 00000000..5a18f3f1 --- /dev/null +++ b/apt/sources.list @@ -0,0 +1,21 @@ +# + +# deb cdrom:[Debian GNU/Linux 10.0.0 _bullseye_ - Official amd64 NETINST 20190706-10:23]/ bullseye main + +#deb cdrom:[Debian GNU/Linux 10.0.0 _bullseye_ - Official amd64 NETINST 20190706-10:23]/ bullseye main + +deb http://deb.debian.org/debian/ bullseye main +deb-src http://deb.debian.org/debian/ bullseye main + +deb http://security.debian.org/debian-security bullseye-security main +deb-src http://security.debian.org/debian-security bullseye-security main + +# bullseye-updates, previously known as 'volatile' +deb http://deb.debian.org/debian/ bullseye-updates main +deb-src http://deb.debian.org/debian/ bullseye-updates main + +# This system was installed using small removable media +# (e.g. netinst, live or single CD). The matching "deb cdrom" +# entries were disabled at the end of the installation process. +# For information about how to configure apt package sources, +# see the sources.list(5) manual. diff --git a/apt/sources.list.d/mariadb.list b/apt/sources.list.d/mariadb.list new file mode 100644 index 00000000..aa91ba14 --- /dev/null +++ b/apt/sources.list.d/mariadb.list @@ -0,0 +1,14 @@ + +# MariaDB Server +# To use a different major version of the server, or to pin to a specific minor version, change URI below. +deb [arch=amd64,arm64] https://dlm.mariadb.com/repo/mariadb-server/10.8/repo/debian bullseye main + + +# MariaDB MaxScale +# To use the latest stable release of MaxScale, use "latest" as the version +# To use the latest beta (or stable if no current beta) release of MaxScale, use "beta" as the version +deb [arch=amd64,arm64] https://dlm.mariadb.com/repo/maxscale/latest/apt bullseye main + + +# MariaDB Tools +deb [arch=amd64] http://downloads.mariadb.com/Tools/debian bullseye main diff --git a/apt/sources.list.d/php.list b/apt/sources.list.d/php.list new file mode 100644 index 00000000..c06ab57b --- /dev/null +++ b/apt/sources.list.d/php.list @@ -0,0 +1 @@ +deb [signed-by=/usr/share/keyrings/deb.sury.org-php.gpg] https://packages.sury.org/php/ bullseye main diff --git a/apt/sources.list.d/rspamd.list b/apt/sources.list.d/rspamd.list new file mode 100644 index 00000000..d2a92b28 --- /dev/null +++ b/apt/sources.list.d/rspamd.list @@ -0,0 +1,2 @@ +deb [arch=amd64 signed-by=/etc/apt/keyrings/rspamd.gpg] http://rspamd.com/apt-stable/ bullseye main +deb-src [arch=amd64 signed-by=/etc/apt/keyrings/rspamd.gpg] http://rspamd.com/apt-stable/ bullseye main diff --git a/apt/trusted.gpg.d/debian-archive-bullseye-automatic.gpg b/apt/trusted.gpg.d/debian-archive-bullseye-automatic.gpg new file mode 100644 index 00000000..dd04cb13 Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-bullseye-automatic.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-bullseye-security-automatic.gpg b/apt/trusted.gpg.d/debian-archive-bullseye-security-automatic.gpg new file mode 100644 index 00000000..1c10c2a1 Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-bullseye-security-automatic.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-bullseye-stable.gpg b/apt/trusted.gpg.d/debian-archive-bullseye-stable.gpg new file mode 100644 index 00000000..8ecabc7d Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-bullseye-stable.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-buster-automatic.gpg b/apt/trusted.gpg.d/debian-archive-buster-automatic.gpg new file mode 100644 index 00000000..9ff7af7e Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-buster-automatic.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-buster-security-automatic.gpg b/apt/trusted.gpg.d/debian-archive-buster-security-automatic.gpg new file mode 100644 index 00000000..81afdb70 Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-buster-security-automatic.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-buster-stable.gpg b/apt/trusted.gpg.d/debian-archive-buster-stable.gpg new file mode 100644 index 00000000..6990f456 Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-buster-stable.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-stretch-automatic.gpg b/apt/trusted.gpg.d/debian-archive-stretch-automatic.gpg new file mode 100644 index 00000000..81b99e4a Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-stretch-automatic.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-stretch-security-automatic.gpg b/apt/trusted.gpg.d/debian-archive-stretch-security-automatic.gpg new file mode 100644 index 00000000..fd24510b Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-stretch-security-automatic.gpg differ diff --git a/apt/trusted.gpg.d/debian-archive-stretch-stable.gpg b/apt/trusted.gpg.d/debian-archive-stretch-stable.gpg new file mode 100644 index 00000000..046cf38b Binary files /dev/null and b/apt/trusted.gpg.d/debian-archive-stretch-stable.gpg differ diff --git a/apt/trusted.gpg.d/mariadb-keyring-2019.gpg b/apt/trusted.gpg.d/mariadb-keyring-2019.gpg new file mode 100644 index 00000000..44cc9cb1 Binary files /dev/null and b/apt/trusted.gpg.d/mariadb-keyring-2019.gpg differ diff --git a/bash.bashrc b/bash.bashrc new file mode 100644 index 00000000..f092bd61 --- /dev/null +++ b/bash.bashrc @@ -0,0 +1,76 @@ +# System-wide .bashrc file for interactive bash(1) shells. + +# To enable the settings / commands in this file for login shells as well, +# this file has to be sourced in /etc/profile. + +# If not running interactively, don't do anything +[ -z "$PS1" ] && return + +# check the window size after each command and, if necessary, +# update the values of LINES and COLUMNS. +shopt -s checkwinsize + +# set variable identifying the chroot you work in (used in the prompt below) +if [ -z "${debian_chroot:-}" ] && [ -r /etc/debian_chroot ]; then + debian_chroot=$(cat /etc/debian_chroot) +fi + +# set a fancy prompt (non-color, overwrite the one in /etc/profile) +# but only if not SUDOing and have SUDO_PS1 set; then assume smart user. +if ! [ -n "${SUDO_USER}" -a -n "${SUDO_PS1}" ]; then + PS1='${debian_chroot:+($debian_chroot)}\u@\h:\w\$ ' +fi + +# Commented out, don't overwrite xterm -T "title" -n "icontitle" by default. +# If this is an xterm set the title to user@host:dir +#case "$TERM" in +#xterm*|rxvt*) +# PROMPT_COMMAND='echo -ne "\033]0;${USER}@${HOSTNAME}: ${PWD}\007"' +# ;; +#*) +# ;; +#esac + +# enable bash completion in interactive shells +#if ! shopt -oq posix; then +# if [ -f /usr/share/bash-completion/bash_completion ]; then +# . /usr/share/bash-completion/bash_completion +# elif [ -f /etc/bash_completion ]; then +# . /etc/bash_completion +# fi +#fi + +# if the command-not-found package is installed, use it +if [ -x /usr/lib/command-not-found -o -x /usr/share/command-not-found/command-not-found ]; then + function command_not_found_handle { + # check because c-n-f could've been removed in the meantime + if [ -x /usr/lib/command-not-found ]; then + /usr/lib/command-not-found -- "$1" + return $? + elif [ -x /usr/share/command-not-found/command-not-found ]; then + /usr/share/command-not-found/command-not-found -- "$1" + return $? + else + printf "%s: command not found\n" "$1" >&2 + return 127 + fi + } +fi + +##----------------------------------------------------- +## better-ls +if [ -f /usr/local/bin/better-ls.sh ] && [ -n "$( echo $- | grep i )" ]; then + source /usr/local/bin/better-ls.sh +fi + +##----------------------------------------------------- +## alias +if [ -f /usr/local/bin/alias.sh ] && [ -n "$( echo $- | grep i )" ]; then + source /usr/local/bin/alias.sh +fi + +##----------------------------------------------------- +## better-history +if [ -f /usr/local/bin/better-history.sh ] && [ -n "$( echo $- | grep i )" ]; then + source /usr/local/bin/better-history.sh +fi diff --git a/bash_completion b/bash_completion new file mode 100644 index 00000000..41ffe595 --- /dev/null +++ b/bash_completion @@ -0,0 +1 @@ +. /usr/share/bash-completion/bash_completion diff --git a/bash_completion.d/git-prompt b/bash_completion.d/git-prompt new file mode 100644 index 00000000..8b5852a9 --- /dev/null +++ b/bash_completion.d/git-prompt @@ -0,0 +1,11 @@ +# In git versions < 1.7.12, this shell library was part of the +# git completion script. +# +# Some users rely on the __git_ps1 function becoming available +# when bash-completion is loaded. Continue to load this library +# at bash-completion startup for now, to ease the transition to a +# world order where the prompt function is requested separately. +# +if [[ -e /usr/lib/git-core/git-sh-prompt ]]; then + . /usr/lib/git-core/git-sh-prompt +fi diff --git a/bindresvport.blacklist b/bindresvport.blacklist new file mode 100644 index 00000000..1dc056eb --- /dev/null +++ b/bindresvport.blacklist @@ -0,0 +1,15 @@ +# +# This file contains a list of port numbers between 600 and 1024, +# which should not be used by bindresvport. bindresvport is mostly +# called by RPC services. This mostly solves the problem, that a +# RPC service uses a well known port of another service. +# +631 # cups +636 # ldaps +655 # tinc +774 # rpasswd +783 # spamd +873 # rsync +921 # lwresd +993 # imaps +995 # pops diff --git a/ca-certificates.conf b/ca-certificates.conf new file mode 100644 index 00000000..4bb6d9a0 --- /dev/null +++ b/ca-certificates.conf @@ -0,0 +1,160 @@ +# This file lists certificates that you wish to use or to ignore to be +# installed in /etc/ssl/certs. +# update-ca-certificates(8) will update /etc/ssl/certs by reading this file. +# +# This is autogenerated by dpkg-reconfigure ca-certificates. +# Certificates should be installed under /usr/share/ca-certificates +# and files with extension '.crt' is recognized as available certs. +# +# line begins with # is comment. +# line begins with ! is certificate filename to be deselected. +# +mozilla/ACCVRAIZ1.crt +mozilla/AC_RAIZ_FNMT-RCM.crt +mozilla/Actalis_Authentication_Root_CA.crt +!mozilla/AddTrust_External_Root.crt +mozilla/AffirmTrust_Commercial.crt +mozilla/AffirmTrust_Networking.crt +mozilla/AffirmTrust_Premium.crt +mozilla/AffirmTrust_Premium_ECC.crt +mozilla/Amazon_Root_CA_1.crt +mozilla/Amazon_Root_CA_2.crt +mozilla/Amazon_Root_CA_3.crt +mozilla/Amazon_Root_CA_4.crt +mozilla/Atos_TrustedRoot_2011.crt +mozilla/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.crt +mozilla/Baltimore_CyberTrust_Root.crt +mozilla/Buypass_Class_2_Root_CA.crt +mozilla/Buypass_Class_3_Root_CA.crt +mozilla/CA_Disig_Root_R2.crt +mozilla/Certigna.crt +!mozilla/Certinomis_-_Root_CA.crt +!mozilla/Certplus_Class_2_Primary_CA.crt +mozilla/certSIGN_ROOT_CA.crt +mozilla/Certum_Trusted_Network_CA_2.crt +mozilla/Certum_Trusted_Network_CA.crt +mozilla/CFCA_EV_ROOT.crt +mozilla/Chambers_of_Commerce_Root_-_2008.crt +mozilla/Comodo_AAA_Services_root.crt +mozilla/COMODO_Certification_Authority.crt +mozilla/COMODO_ECC_Certification_Authority.crt +mozilla/COMODO_RSA_Certification_Authority.crt +mozilla/Cybertrust_Global_Root.crt +!mozilla/Deutsche_Telekom_Root_CA_2.crt +mozilla/DigiCert_Assured_ID_Root_CA.crt +mozilla/DigiCert_Assured_ID_Root_G2.crt +mozilla/DigiCert_Assured_ID_Root_G3.crt +mozilla/DigiCert_Global_Root_CA.crt +mozilla/DigiCert_Global_Root_G2.crt +mozilla/DigiCert_Global_Root_G3.crt +mozilla/DigiCert_High_Assurance_EV_Root_CA.crt +mozilla/DigiCert_Trusted_Root_G4.crt +mozilla/DST_Root_CA_X3.crt +mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt +mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt +mozilla/EC-ACC.crt +!mozilla/EE_Certification_Centre_Root_CA.crt +mozilla/Entrust.net_Premium_2048_Secure_Server_CA.crt +mozilla/Entrust_Root_Certification_Authority.crt +mozilla/Entrust_Root_Certification_Authority_-_EC1.crt +mozilla/Entrust_Root_Certification_Authority_-_G2.crt +mozilla/ePKI_Root_Certification_Authority.crt +mozilla/E-Tugra_Certification_Authority.crt +mozilla/GDCA_TrustAUTH_R5_ROOT.crt +!mozilla/GeoTrust_Global_CA.crt +!mozilla/GeoTrust_Primary_Certification_Authority.crt +mozilla/GeoTrust_Primary_Certification_Authority_-_G2.crt +!mozilla/GeoTrust_Primary_Certification_Authority_-_G3.crt +!mozilla/GeoTrust_Universal_CA_2.crt +!mozilla/GeoTrust_Universal_CA.crt +mozilla/Global_Chambersign_Root_-_2008.crt +mozilla/GlobalSign_ECC_Root_CA_-_R4.crt +mozilla/GlobalSign_ECC_Root_CA_-_R5.crt +mozilla/GlobalSign_Root_CA.crt +mozilla/GlobalSign_Root_CA_-_R2.crt +mozilla/GlobalSign_Root_CA_-_R3.crt +mozilla/GlobalSign_Root_CA_-_R6.crt +mozilla/Go_Daddy_Class_2_CA.crt +mozilla/Go_Daddy_Root_Certificate_Authority_-_G2.crt +mozilla/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.crt +mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2011.crt +mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2015.crt +mozilla/Hongkong_Post_Root_CA_1.crt +mozilla/IdenTrust_Commercial_Root_CA_1.crt +mozilla/IdenTrust_Public_Sector_Root_CA_1.crt +mozilla/ISRG_Root_X1.crt +mozilla/Izenpe.com.crt +!mozilla/LuxTrust_Global_Root_2.crt +mozilla/Microsec_e-Szigno_Root_CA_2009.crt +mozilla/NetLock_Arany_=Class_Gold=_Főtanúsítvány.crt +mozilla/Network_Solutions_Certificate_Authority.crt +!mozilla/OISTE_WISeKey_Global_Root_GA_CA.crt +mozilla/OISTE_WISeKey_Global_Root_GB_CA.crt +mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt +mozilla/QuoVadis_Root_CA_1_G3.crt +mozilla/QuoVadis_Root_CA_2.crt +mozilla/QuoVadis_Root_CA_2_G3.crt +mozilla/QuoVadis_Root_CA_3.crt +mozilla/QuoVadis_Root_CA_3_G3.crt +mozilla/QuoVadis_Root_CA.crt +mozilla/Secure_Global_CA.crt +mozilla/SecureSign_RootCA11.crt +mozilla/SecureTrust_CA.crt +mozilla/Security_Communication_RootCA2.crt +mozilla/Security_Communication_Root_CA.crt +mozilla/Sonera_Class_2_Root_CA.crt +mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt +mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt +mozilla/SSL.com_Root_Certification_Authority_ECC.crt +mozilla/SSL.com_Root_Certification_Authority_RSA.crt +mozilla/Staat_der_Nederlanden_EV_Root_CA.crt +!mozilla/Staat_der_Nederlanden_Root_CA_-_G2.crt +mozilla/Staat_der_Nederlanden_Root_CA_-_G3.crt +mozilla/Starfield_Class_2_CA.crt +mozilla/Starfield_Root_Certificate_Authority_-_G2.crt +mozilla/Starfield_Services_Root_Certificate_Authority_-_G2.crt +mozilla/SwissSign_Gold_CA_-_G2.crt +mozilla/SwissSign_Silver_CA_-_G2.crt +mozilla/SZAFIR_ROOT_CA2.crt +!mozilla/Taiwan_GRCA.crt +mozilla/TeliaSonera_Root_CA_v1.crt +!mozilla/thawte_Primary_Root_CA.crt +!mozilla/thawte_Primary_Root_CA_-_G2.crt +!mozilla/thawte_Primary_Root_CA_-_G3.crt +mozilla/TrustCor_ECA-1.crt +mozilla/TrustCor_RootCert_CA-1.crt +mozilla/TrustCor_RootCert_CA-2.crt +mozilla/Trustis_FPS_Root_CA.crt +mozilla/T-TeleSec_GlobalRoot_Class_2.crt +mozilla/T-TeleSec_GlobalRoot_Class_3.crt +mozilla/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.crt +mozilla/TWCA_Global_Root_CA.crt +mozilla/TWCA_Root_Certification_Authority.crt +mozilla/USERTrust_ECC_Certification_Authority.crt +mozilla/USERTrust_RSA_Certification_Authority.crt +!mozilla/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.crt +!mozilla/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.crt +!mozilla/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.crt +mozilla/VeriSign_Universal_Root_Certification_Authority.crt +mozilla/XRamp_Global_CA_Root.crt +mozilla/Certigna_Root_CA.crt +mozilla/Entrust_Root_Certification_Authority_-_G4.crt +mozilla/GTS_Root_R1.crt +mozilla/GTS_Root_R2.crt +mozilla/GTS_Root_R3.crt +mozilla/GTS_Root_R4.crt +mozilla/Hongkong_Post_Root_CA_3.crt +mozilla/UCA_Extended_Validation_Root.crt +mozilla/UCA_Global_G2_Root.crt +mozilla/emSign_ECC_Root_CA_-_C3.crt +mozilla/emSign_ECC_Root_CA_-_G3.crt +mozilla/emSign_Root_CA_-_C1.crt +mozilla/emSign_Root_CA_-_G1.crt +mozilla/certSIGN_Root_CA_G2.crt +mozilla/e-Szigno_Root_CA_2017.crt +mozilla/Microsoft_ECC_Root_Certificate_Authority_2017.crt +mozilla/Microsoft_RSA_Root_Certificate_Authority_2017.crt +mozilla/NAVER_Global_Root_Certification_Authority.crt +mozilla/Trustwave_Global_Certification_Authority.crt +mozilla/Trustwave_Global_ECC_P256_Certification_Authority.crt +mozilla/Trustwave_Global_ECC_P384_Certification_Authority.crt diff --git a/calendar/default b/calendar/default new file mode 100644 index 00000000..fa521807 --- /dev/null +++ b/calendar/default @@ -0,0 +1,15 @@ +/* This is the system-wide default calendar file, used if calendar(1) + * is invoked by a user without a ~/calendar or ~/.calendar/calendar file. + * It may be edited or even deleted to reflect local policy. + * + * In the standard setup, we simply include the default calendar + * definitions from /usr/share/calendar/calendar.all. If you want + * only some of those definitions, copy calendar.all to /etc/calendar + * and edit it there. That way, your changes will be kept next time + * you upgrade. + * + * The search path for include files is: + * /etc/calendar + * /usr/share/calendar + */ +#include "calendar.all" diff --git a/clamav-unofficial-sigs/master.conf b/clamav-unofficial-sigs/master.conf new file mode 100644 index 00000000..66f1c97b --- /dev/null +++ b/clamav-unofficial-sigs/master.conf @@ -0,0 +1,746 @@ +# This file contains master configuration settings for clamav-unofficial-sigs.sh +################################################################################ +# This is property of eXtremeSHOK.com +# You are free to use, modify and distribute, however you may not remove this notice. +# Copyright (c) Adrian Jon Kriel :: admin@extremeshok.com +# License: BSD (Berkeley Software Distribution) +################################################################################ +# +# DO NOT EDIT THIS FILE !! DO NOT EDIT THIS FILE !! DO NOT EDIT THIS FILE !! +# +################################################################################ +# +# SET YOUR CUSTOM OPTIONS AND SETTINGS IN THE user.conf +# +# os.conf (os.***.conf) AND user.conf OVERRIDES THE OPTIONS IN THIS FILE +# +################################################################################ + +# Edit the quoted variables below to meet your own particular needs +# and requirements, but do not remove the "quote" marks. + +# Set the appropriate ClamD user and group accounts for your system. +# If you do not want the script to set user and group permissions on +# files and directories, comment the next two variables. +#clam_user="clamav" +#clam_group="clamav" + +# If you do not want the script to change the file mode of all signature +# database files in the ClamAV working directory to 0644 (-rw-r--r--): +# +# owner: read, write +# group: read +# world: read +# +# as defined in the "clam_dbs" path variable below, then set the following +# "setmode" variable to "no". +setmode="yes" + +# Set path to ClamAV database files location. If unsure, check +# your clamd.conf file for the "DatabaseDirectory" path setting. +clam_dbs="/var/lib/clamav" + +# Set path to clamd.pid file (see clamd.conf for path location). +clamd_pid="/var/run/clamav/clamd.pid" + +# To enable "ham" (non-spam) directory scanning and removal of +# signatures that trigger on ham messages, uncomment the following +# variable and set it to the appropriate ham message directory. +#ham_dir="/var/lib/clamav-unofficial-sigs/ham-test" + +# If you would like to reload the clamd databases after an update, +# change the following variable to "yes". +reload_dbs="yes" + +# Custom Command to do a full clamd reload, this is only used when reload_dbs is enabled +clamd_reload_opt="clamdscan --reload" + +# Top level working directory, script will attempt to create them. +work_dir="/var/lib/clamav-unofficial-sigs" #Top level working directory + +# Log update information to '$log_file_path/$log_file_name'. +logging_enabled="yes" +log_file_path="/var/log/clamav-unofficial-sigs" +log_file_name="clamav-unofficial-sigs.log" +## Use a program to log messages +#log_pipe_cmd="/usr/bin/logger -it 'clamav-unofficial-sigs'" + + +# ========================= +# MalwarePatrol : https://www.malwarepatrol.net +# MalwarePatrol 2016 (free) clamav signatures +# +# 1. Sign up for an account : https://www.malwarepatrol.net/free-guard-upgrade-option/ +# 2. You will recieve an email containing your password/receipt number +# 3. Login to your account at malwarePatrol +# 4. In My Accountpage, choose the ClamAV list you will download. Free subscribers only get ClamAV Basic, commercial subscribers have access to ClamAV Extended. Do not use the agressive lists. +# 5. In the download URL, you will see 3 parameters: receipt, product and list, enter them in the variables below. + +malwarepatrol_receipt_code="YOUR-RECEIPT-NUMBER" +malwarepatrol_product_code="8" +malwarepatrol_list="clamav_basic" # clamav_basic or clamav_ext +# if the malwarepatrol_product_code is not 8, +# the malwarepatrol_free is set to no (non-free) +# set to no to enable the commercial subscription url, +malwarepatrol_free="yes" +malwarepatrol_db="malwarepatrol.db" + + +# ========================= +# Malware Expert : https://www.Malware Expert +# Malware Expert 2020 (non-free) clamav signatures +malwareexpert_serial_key="YOUR-SERIAL-KEY" + +# ========================= +# SecuriteInfo : https://www.SecuriteInfo.com +# SecuriteInfo 2015 free clamav signatures +# +# Usage of SecuriteInfo 2015 free clamav signatures : https://www.securiteinfo.com +# - 1. Sign up for a free account : https://www.securiteinfo.com/clients/customers/signup +# - 2. You will recieve an email to activate your account and then a followup email with your login name +# - 3. Login and navigate to your customer account : https://www.securiteinfo.com/clients/customers/account +# - 4. Click on the Setup tab +# - 5. You will need to get your unique identifier from one of the download links, they are individual for every user +# - 5.1. The 128 character string is after the http://www.securiteinfo.com/get/signatures/ +# - 5.2. Example https://www.securiteinfo.com/get/signatures/your_unique_and_very_long_random_string_of_characters/securiteinfo.hdb +# Your 128 character authorisation signature would be : your_unique_and_very_long_random_string_of_characters +# - 6. Enter the authorisation signature into the config securiteinfo_authorisation_signature: replacing YOUR-SIGNATURE-NUMBER with your authorisation signature from the link + +securiteinfo_authorisation_signature="YOUR-SIGNATURE-NUMBER" +# Enable if you have a commercial/premium/non-free subscription +securiteinfo_premium="no" + + +# ======================== +# Database provider update time +# ======================== +# Since the database files are dynamically created, non default values can cause banning, change with caution +additional_update_hours="4" # Default is 4 hours (6 downloads daily). +interserver_update_hours="1" # Default is 2 hours (12 downloads daily). +linuxmalwaredetect_update_hours="6" # Default is 6 hours (4 downloads daily). +malwareexpert_update_hours="2" # Default is 2 hours (12 downloads daily). +malwarepatrol_update_hours="24" # Default is 24 hours (1 downloads daily). +sanesecurity_update_hours="2" # Default is 2 hours (12 downloads daily). +securiteinfo_premium_update_hours="1" # Default is 1 hours (24 downloads daily). +securiteinfo_update_hours="4" # Default is 4 hours (6 downloads daily). +urlhaus_update_hours="1" # Default is 1 hours (24 downloads daily). +yararulesproject_update_hours="24" # Default is 24 hours (1 downloads daily). + +# ======================== +# Enabled Databases +# ======================== +# Set to no to disable an entire database, if the database is empty it will also be disabled. +additional_enabled="yes" # Additional Databases +interserver_enabled="yes" # interServer +linuxmalwaredetect_enabled="yes" # Linux Malware Detect +malwareexpert_enabled="yes" # Malware Expert +malwarepatrol_enabled="yes" # Malware Patrol +sanesecurity_enabled="yes" # Sanesecurity +securiteinfo_enabled="yes" # SecuriteInfo +urlhaus_enabled="yes" # urlhaus +yararulesproject_enabled="yes" # Yara-Rule Project, automatically disabled if clamav is older than 0.100 and enable_yararules is disabled + +# Disabled by default +## Enabling this will also cause the yararulesproject to be enabled if they are det to enabled. +enable_yararules="yes" #Enables yararules in the various databases, automatically disabled if clamav is older than 0.100 + +# ======================== +# eXtremeSHOK Database format +# ======================== +# The new and old database formats are supported for backwards compatibility +# +# New Format Usage: +# declare -a new_example_dbs=( +# file.name|RATING #description +# ) +# +# Rating (False Positive Rating) +# valid ratings: +# REQUIRED : always used +# LOW : used when the rating is low, medium and high +# MEDIUM : used when the rating is medium and high +# HIGH : used when the rating is high +# LOWONLY : used only when the rating is low +# MEDIUMONLY : used only when the rating is medium +# LOWMEDIUMONLY : used only when the rating is medium or low +# DISABLED : never used, will automatically remove the present file +# +# Old Format is still supported, requiring you to comment out files to disable them +# old_example_dbs=" +# file.name #LOW description +# " + +# Default dbs rating +# valid rating: LOW, MEDIUM, HIGH, DISABLE +default_dbs_rating="MEDIUM" + +# Per Database +# These ratings will override the global rating for the specific database +# valid ratings: LOW | MEDIUM | HIGH | DISABLE +#linuxmalwaredetect_dbs_rating="" +#sanesecurity_dbs_rating="" +#securiteinfo_dbs_rating="" +#urlhaus_dbs_rating="" +#yararulesproject_dbs_rating="" + +# ======================== +# Sanesecurity Database(s) +# ======================== +# Add or remove database file names between quote marks as needed. To +# disable usage of any of the Sanesecurity distributed database files +# shown, remove the database file name from the quoted section below. +# Only databases defined as "low" risk have been enabled by default +# for additional information about the database ratings, see: +# http://www.sanesecurity.com/clamav/databases.htm +# Only add signature databases here that are "distributed" by Sanesecuirty +# as defined at the URL shown above. Database distributed by others sources +# (e.g., SecuriteInfo & MalewarePatrol, can be added to other sections of +# this config file below). Finally, make sure that the database names are +# spelled correctly or you will experience issues when the script runs +# (hint: all rsync servers will fail to download signature updates). + +declare -a sanesecurity_dbs=( # BEGIN SANESECURITY DATABASE +### SANESECURITY http://sanesecurity.com/usage/signatures/ +## REQUIRED, Do NOT disable +sanesecurity.ftm|REQUIRED # Message file types, for best performance +sigwhitelist.ign2|REQUIRED # Fast update file to whitelist any problem signatures +# LOW +blurl.ndb|LOW # Blacklisted full urls over the last 7 days, covering malware/spam/phishing. URLs added only when main signatures have failed to detect but are known to be "bad" +junk.ndb|LOW # General high hitting junk, containing spam/phishing/lottery/jobs/419s etc +jurlbl.ndb|LOW # Junk Url based +malwarehash.hsb|LOW # Malware hashes without known Size +phish.ndb|LOW # Phishing and Malware +rogue.hdb|LOW # Malware, Rogue anti-virus software and Fake codecs etc. Updated hourly to cover the latest malware threats +scam.ndb|LOW # Spam/scams +spamattach.hdb|LOW # Spam Spammed attachments such as pdf/doc/rtf/zips +spamimg.hdb|LOW # Spam images +# MEDIUM +badmacro.ndb|MEDIUM # Blocks dangerous macros embedded in Word/Excel/Xml/RTF/JS documents +jurlbla.ndb|MEDIUM # Junk Url based autogenerated from various feeds +lott.ndb|MEDIUM # Lottery +shelter.ldb|MEDIUM # Phishing and Malware +spam.ldb|MEDIUM # Spam detected using the new Logical Signature type +spear.ndb|MEDIUM # Spear phishing email addresses (autogenerated from data here) +spearl.ndb|MEDIUM # Spear phishing urls (autogenerated from data here) + +### FOXHOLE http://sanesecurity.com/foxhole-databases/ +# LOW +foxhole_filename.cdb|LOW # See Foxhole page for more details +foxhole_generic.cdb|LOW # See Foxhole page for more details +# MEDIUM +foxhole_js.cdb|MEDIUM # See Foxhole page for more details +foxhole_js.ndb|MEDIUM # See Foxhole page for more details +# HIGH +foxhole_all.cdb|HIGH # See Foxhole page for more details +foxhole_all.ndb|HIGH # See Foxhole page for more details +foxhole_mail.cdb|HIGH # block any mail that contains a possible dangerous attachments such as: js, jse, exe, bat, com, scr, uue, ace, pif, jar, gz, lnk, lzh. + +### OITC http://www.oitc.com/winnow/clamsigs/index.html +### Note: the two databases winnow_phish_complete.ndb and winnow_phish_complete_url.ndb should NOT be used together. +# LOW +winnow_bad_cw.hdb|LOW # md5 hashes of malware attachments acquired directly from a group of botnets +winnow_extended_malware.hdb|LOW # contain hand generated signatures for malware +winnow_malware_links.ndb|LOW # Links to malware +winnow_malware.hdb|LOW # Current virus, trojan and other malware not yet detected by ClamAV. +winnow_phish_complete_url.ndb|LOWMEDIUMONLY # Similar to winnow_phish_complete.ndb except that entire urls are used +winnow.attachments.hdb|LOW # Spammed attachments such as pdf/doc/rtf/zip as well as malware crypted configs +# MEDIUM +winnow_extended_malware_links.ndb|MEDIUM # contain hand generated signatures for malware links +winnow_spam_complete.ndb|MEDIUM # Signatures to detect fraud and other malicious spam +winnow.complex.patterns.ldb|MEDIUM # contain hand generated signatures for malware and some egregious fraud +# HIGH +winnow_phish_complete.ndb|HIGH # Phishing and other malicious urls and compromised hosts **DO NOT USE WITH winnow_phish_complete_url** +### OITC YARA Format rules +### Note: Yara signatures require ClamAV 0.100 or newer to work +winnow_malware.yara|DISABLED # Duplicated in EMAIL_Cryptowall.yar and no longer maintaned + +### MiscreantPunch http://malwarefor.me/about/ +## MEDIUM +MiscreantPunch099-Low.ldb|MEDIUM # ruleset contains comprehensive rules for detecting malicious or abnormal Macros, JS, HTA, HTML, XAP, JAR, SWF, and more. +## HIGH +MiscreantPunch099-INFO-Low.ldb|HIGH # ruleset provides context to various files. Info and Suspicious level signatures may inform analysts of potentially interesting conditions that exist within a document. + +### SCAMNAILER http://www.scamnailer.info/ +# MEDIUM +scamnailer.ndb|DISABLED # Spear phishing and other phishing emails, service has been discontinued https://github.com/extremeshok/clamav-unofficial-sigs/issues/365 + +### BOFHLAND http://clamav.bofhland.org/ +# LOW +bofhland_cracked_URL.ndb|LOW # Spam URLs +bofhland_malware_attach.hdb|LOW # Malware Hashes +bofhland_malware_URL.ndb|LOW # Malware URLs +bofhland_phishing_URL.ndb|LOW # Phishing URLs + +### RockSecurity http://rooksecurity.com/ +# LOW +hackingteam.hsb|LOW # Hacking Team hashes based on work by rooksecurity.com + +### Porcupine +# LOW +phishtank.ndb|LOW # Online and valid phishing urls from phishtank.com data feed +porcupine.hsb|LOW # Sha256 Hashes of VBS and JSE malware, kept for 7 days +porcupine.ndb|LOW # Brazilian e-mail phishing and malware signatures + +### Sanesecurity YARA Format rules +### Note: Yara signatures require ClamAV 0.100 or newer to work +Sanesecurity_sigtest.yara|LOW # Sanesecurity test signatures +Sanesecurity_spam.yara|LOW # Detects Spam emails + +) # END SANESECURITY DATABASES + +# ======================== +# SecuriteInfo Database(s) +# ======================== +# Only active when you set your securiteinfo_authorisation_signature +# Add or remove database file names between quote marks as needed. To +# disable any SecuriteInfo database downloads, remove the appropriate +# lines below. +declare -a securiteinfo_dbs=( #START SECURITEINFO DATABASES +### Securiteinfo https://www.securiteinfo.com/services/anti-spam-anti-virus/improve-detection-rate-of-zero-day-malwares-for-clamav.shtml +## REQUIRED, Do NOT disable +securiteinfo.ign2|REQUIRED # Signature Whitelist +# LOW +javascript.ndb|LOW # Malwares Javascript +securiteinfo.hdb|LOW # Malwares younger than 3 years. +securiteinfoandroid.hdb|LOW # Malwares Java/Android Dalvik +securiteinfoascii.hdb|LOW # Text file malwares (Perl or shell scripts, bat files, exploits, ...) +securiteinfohtml.hdb|LOW # Malwares HTML +securiteinfoold.hdb|LOW # Malwares older than 3 years. +securiteinfopdf.hdb|LOW # Malwares PDF +# HIGH +spam_marketing.ndb|HIGH # Spam Marketing / spammer blacklist +) #END SECURITEINFO DATABASES + +# SECURITEINFO PREMIUM (NON-FREE) DATABASES +declare -a securiteinfo_premium_dbs=( #START SECURITEINFO DATABASES +securiteinfo.mdb|LOW # 0-day Malwares +securiteinfo0hour.hdb|LOW # 0-Hour Malwares +) #END NON-FREE SECURITEINFO DATABASES + +# ======================== +# LinuxMalwareDetect Database(s) +# ======================== +# Add or remove database file names between quote marks as needed. To +# disable any LinuxMalwareDetect database downloads, remove the appropriate +# lines below. +declare -a linuxmalwaredetect_dbs=( +### Linux Malware Detect https://www.rfxn.com/projects/linux-malware-detect/ +# LOW +rfxn.ndb|LOW # HEX Malware detection signatures +rfxn.hdb|LOW # MD5 Malware detection signatures +rfxn.yara|LOW # Yara Malware detection signatures +) #END LINUXMALWAREDETECT DATABASES + +# ======================== +# interServer Database(s) +# ======================== +# Add or remove database file names between quote marks as needed. To +# disable any Malware Expert database downloads, remove the appropriate +# lines below. +declare -a interserver_dbs=( +## REQUIRED, Do NOT disable +whitelist.fp|REQUIRED # found to be false positive malware +# LOW +interserver256.hdb|LOW # 100% known malware sha256 format +# MEDIUM +interservertopline.db|MEDIUM # inserts into files, manual cleaning HEX +# HIGH +shell.ldb|HIGH # 99.9% known malware using logical signatures +) #END Malware Expert DATABASES + +# ======================== +# Malware Expert Database(s) +# ======================== +# Add or remove database file names between quote marks as needed. To +# disable any Malware Expert database downloads, remove the appropriate +# lines below. +declare -a malwareexpert_dbs=( +## REQUIRED, Do NOT disable +malware.expert.fp|REQUIRED # found to be false positive malware +# LOW +malware.expert.hdb|LOW # statics MD5 pattern for files +# MEDIUM +malware.expert.ldb|MEDIUM # which use multi-words search for malware in files +malware.expert.ndb|MEDIUM # Generic Hex pattern PHP malware, which can cause false positive alarms +) #END Malware Expert DATABASES + +# ======================== +# urlhaus Database(s) +# ======================== +# Add or remove database file names between quote marks as needed. To +# disable any urlhaus database downloads, remove the appropriate +# lines below. +declare -a urlhaus_dbs=( +### urlhaus https://urlhaus.abuse.ch/browse/ +# LOW +urlhaus.ndb|LOW # malicious URLs that are being used for malware distribution +) #END URLHAUS DATABASES + +# ======================== +# Yara Rules Project Database(s) +# ======================== +# Add or remove database file names between quote marks as needed. To +# disable any Yara Rule database downloads, remove the appropriate +# lines below. +declare -a yararulesproject_dbs=( +### Yara Rules https://github.com/Yara-Rules/rules +# +# Some rules are now in sub-directories. To reference a file in a sub-directory +# use subdir/file +# LOW +# Anti debug and anti virtualization techniques used by malware +antidebug_antivm/antidebug_antivm.yar|DISABLED # (core dumped) +# Aimed toward the detection and existence of Exploit Kits. +exploit_kits/EK_Angler.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_Blackhole.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_BleedingLife.yar|LOW # duplicated in rxfn.yara +exploit_kits/EK_Crimepack.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_Eleonore.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_Fragus.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_Phoenix.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_Sakura.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_ZeroAcces.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_Zerox88.yar|DISABLED # duplicated in rxfn.yara +exploit_kits/EK_Zeus.yar|DISABLED # duplicated in rxfn.yara +#Identification of well-known webshells +webshells/WShell_APT_Laudanum.yar|DISABLED # duplicated in rxfn.yara +webshells/WShell_ASPXSpy.yar|LOW +webshells/WShell_Drupalgeddon2_icos.yar|LOW +webshells/WShell_PHP_Anuna.yar|DISABLED # duplicated in rxfn.yara +webshells/WShell_PHP_in_images.yar|DISABLED # duplicated in rxfn.yara +webshells/WShell_THOR_Webshells.yar|DISABLED # duplicated in rxfn.yara +webshells/Wshell_ChineseSpam.yar|DISABLED # duplicated in rxfn.yara +webshells/Wshell_fire2013.yar|DISABLED # duplicated in rxfn.yara +# MEDIUM +# Identification of specific Common Vulnerabilities and Exposures (CVEs) +cve_rules/CVE-2010-0805.yar|MEDIUM +cve_rules/CVE-2010-0887.yar|MEDIUM +cve_rules/CVE-2010-1297.yar|MEDIUM +cve_rules/CVE-2012-0158.yar|MEDIUM +cve_rules/CVE-2013-0074.yar|MEDIUM +cve_rules/CVE-2013-0422.yar|MEDIUM +cve_rules/CVE-2015-1701.yar|MEDIUM +cve_rules/CVE-2015-2426.yar|MEDIUM +cve_rules/CVE-2015-2545.yar|MEDIUM +cve_rules/CVE-2015-5119.yar|MEDIUM +cve_rules/CVE-2016-5195.yar|MEDIUM +cve_rules/CVE-2017-11882.yar|MEDIUM +cve_rules/CVE-2018-20250.yar|MEDIUM +cve_rules/CVE-2018-4878.yar|MEDIUM +# Identification of malicious e-mails. +email/bank_rule.yar|MEDIUM +email/EMAIL_Cryptowall.yar|MEDIUM +email/Email_fake_it_maintenance_bulletin.yar|MEDIUM +email/Email_quota_limit_warning.yar|MEDIUM +email/email_Ukraine_BE_powerattack.yar|MEDIUM +email/scam.yar|MEDIUM +# Detect well-known software packers, that can be used by malware to hide itself. +packers/JJencode.yar|DISABLED # Causes high CPU load with email attachments (images) https://github.com/extremeshok/clamav-unofficial-sigs/issues/362 +# HIGH +# Used with documents to find if they have been crafted to leverage malicious code. +email/Email_generic_phishing.yar|HIGH +maldocs/Maldoc_APT_OLE_JSRat.yar|HIGH +maldocs/Maldoc_APT10_MenuPass.yar|HIGH +maldocs/Maldoc_APT19_CVE-2017-0199.yar|HIGH +maldocs/Maldoc_Contains_VBE_File.yar|HIGH +maldocs/Maldoc_CVE_2017_11882.yar|HIGH +maldocs/Maldoc_CVE_2017_8759.yar|HIGH +maldocs/Maldoc_CVE-2017-0199.yar|HIGH +maldocs/Maldoc_DDE.yar|HIGH +maldocs/Maldoc_Dridex.yar|HIGH +maldocs/Maldoc_hancitor_dropper.yar|HIGH +maldocs/Maldoc_Hidden_PE_file.yar|HIGH +maldocs/Maldoc_malrtf_ole2link.yar|HIGH +maldocs/Maldoc_MIME_ActiveMime_b64.yar|HIGH +maldocs/Maldoc_PDF.yar|HIGH +maldocs/Maldoc_PowerPointMouse.yar|HIGH +maldocs/maldoc_somerules.yar|HIGH +maldocs/Maldoc_Suspicious_OLE_target.yar|HIGH +maldocs/Maldoc_UserForm.yar|HIGH +maldocs/Maldoc_VBA_macro_code.yar|HIGH +maldocs/Maldoc_Word_2007_XML_Flat_OPC.yar|HIGH +# Yara Rules aimed to detect well-known software packers, that can be used by malware to hide itself. +packers/Javascript_exploit_and_obfuscation.yar|HIGH +# DISABLED +# NOT SUPPORTED OR CRASHING CLAMAV +email/attachment.yar|DISABLED # detects all emails with attachments +email/image.yar|DISABLED # detects all emails with images +email/urls.yar|DISABLED # detects all emails with urls +crypto/crypto_signatures.yar|DISABLED # detects all files which are encrypted +# These files use module includes not supported by ClamAV +packers/packer_compiler_signatures.yar|DISABLED +packers/packer.yar|DISABLED +packers/peid.yar|DISABLED +antidebug_antivm|DISABLED +) #END yararulesproject DATABASES + +declare -a yararulesproject_dbs_catagories=( +#LOW +cve_rules|LOW +exploit_kits|LOW +malware|LOW +webshells|LOW +#MEDIUM +email|MEDIUM +maldocs|MEDIUM +# HIGH +capabilities|HIGH +crypto|HIGH +packers|HIGH +) + + +# ========================= +# Additional signature databases +# ========================= +# Additional signature databases can be specified here in the following +# format: PROTOCOL://URL-or-IP/PATH/TO/FILE-NAME (use a trailing "/" in +# place of the "FILE-NAME" to download all files from specified location, +# but this *ONLY* works for files downloaded via rsync). For non-rsync +# downloads, wget and curl is used. For download protocols supported by +# wget and curl, see "man wget" and "man curl". +# This also works well for locations that have many ClamAV +# servers that use 3rd party signature databases, as only one server need +# download the remote databases, and all others can update from the local +# mirrors copy. See format examples below. To use, remove the comments +# and examples shown and add your own sites between the quote marks. +#declare -a additional_dbs=( +# rsync://192.168.1.50/new-db/sigs.hdb +# rsync://rsync.example.com/all-dbs/ +# ftp://ftp.example.net/pub/sigs.ndb +# http://www.example.org/sigs.ldb +#) #END ADDITIONAL DATABASES + +# ================================================== +# ================================================== +# D E B U G O P T I O N S +# ================================================== +# ================================================== + +# Enable debugging, will cause all options below to enable +debug="no" + +# Causes the xshok_file_download function to be verbose, used for debugging +downloader_debug="no" + +# Causes clamscan signature test errors to be vebose +clamscan_debug="no" + +# Causes curl errors to be vebose +curl_debug="no" + +# Causes wget errors to be vebose +wget_debug="no" + +# Causes rsync errors to be vebose +rsync_debug="no" + +# ================================================== +# ================================================== +# A D V A N C E D O P T I O N S +# ================================================== +# ================================================== + +# Branch for update checking, default: master +git_branch="master" + +# Enable support for script and master.conf upgrades +# enbles the --upgrade command line option +# packagers, if required please disable or set this option to no in the os.conf +allow_upgrades="yes" + +# Enable support for script and master.conf update checks +# packagers, if required please disable or set this option to no in the os.conf +allow_update_checks="yes" + +# How often the script should check for updates +update_check_hours="12"# Default is 12 hours (2 checks daily). + +# Enable or disable download time randomization. This allows the script to +# be executed via cron, but the actual database file checking will pause +# for a random number of seconds between the "min" and "max" time settings +# specified below. This helps to more evenly distribute load on the host +# download sites. To disable, set the following variable to "no". +enable_random="yes" + +# Enable to prevent issues with multiple instances running +# To disable, set the following variable to "no". +enable_locking="yes" + +# If download time randomization is enabled above (enable_random="yes"), +# then set the min and max radomization time intervals (in seconds). +max_sleep_time="600" # Default maximum is 600 seconds (10 minutes). +min_sleep_time="60" # Default minimum is 60 seconds (1 minute). + +# Command to do a full clamd service stop/start +#clamd_restart_opt="service clamd restart" + +# Custom Command Paths, these are detected with the which command when not set +#clamscan_bin="/usr/bin/clamscan" +#curl_bin="/usr/bin/curl" +#gpg_bin="/usr/bin/gpg" +#rsync_bin="/usr/bin/rsync" +#tar_bin="/usr/bin/tar" +#uname_bin="/usr/bin/uname" +#wget_bin="/usr/bin/wget" +#dig_bin="usr/bin/dig" +#host_bin="/usr/bin/host" + +# force wget, by default curl is used when curl and wget is present. +force_wget="no" + +# force host, by default dig is used when dig and host is present. +force_host="no" + +# GnuPG / Signature verification +# To disable usage of gpg, set the following variable to "no". +# If gpg_bin cannot be found, enable_gpg will automatically disable +enable_gpg="yes" + +# If running clamd in "LocalSocket" mode (*NOT* in TCP/IP mode), and +# either "SOcket Cat" (socat) or the "IO::Socket::UNIX" perl module +# are installed on the system, and you want to report whether clamd +# is running or not, uncomment the "clamd_socket" variable below (you +# will be warned if neither socat nor IO::Socket::UNIX are found, but +# the script will still run). You will also need to set the correct +# path to your clamd socket file (if unsure of the path, check the +# "LocalSocket" setting in your clamd.conf file for socket location). +#clamd_socket="/tmp/clamd.socket" + +# Set rsync connection and data transfer timeout limits in seconds. +# The defaults settings here are reasonable, only change if you are +# experiencing timeout issues. +rsync_connect_timeout="60" +rsync_max_time="180" + +# HTTPS validation +# Uncomment to allow and ignore SSL errors leading to insecure transfers +# downloader_ignore_ssl_errors="yes" # Default is "no" + +# Set downloader connection, data transfer timeout limits in seconds. +# The defaults settings here are reasonable, only change if you are +# experiencing timeout issues. +downloader_connect_timeout="60" +downloader_max_time="1800" + +# Set downloader retry count for failed transfers +downloader_tries="5" + +# Set working directory paths (edit to meet your own needs). If these +# directories do not exist, the script will attempt to create them. +# Always located inside the work_dir, do not add / +# Sub-directory names: +add_dir="dbs-add" # User defined databases sub-directory +gpg_dir="gpg-key" # Sanesecurity GPG Key sub-directory +interserver_dir="dbs-is" # interServer sub-directory +linuxmalwaredetect_dir="dbs-lmd" # Linux Malware Detect sub-directory +malwareexpert_dir="dbs-me" # Malware Expert sub-directory +malwarepatrol_dir="dbs-mbl" # MalwarePatrol sub-directory +pid_dir="pid" # User defined pid sub-directory +sanesecurity_dir="dbs-ss" # Sanesecurity sub-directory +securiteinfo_dir="dbs-si" # SecuriteInfo sub-directory +urlhaus_dir="dbs-uh" # urlhaus sub-directory +work_dir_configs="configs" # Script configs sub-directory +yararulesproject_dir="dbs-yara" # Yara-Rules sub-directory + +# If you would like to make a backup copy of the current running database +# file before updating, leave the following variable set to "yes" and a +# backup copy of the file will be created in the production directory +# with -bak appended to the file name. +keep_db_backup="no" + +# When a database integrity has tested BAD, the failed database will be removed. +remove_bad_database="yes" + +# When a database is disabled we will remove the associated database files. +remove_disabled_databases="yes" # Default is "yes" + +# Enable SELinux fixes, ie. running restorecon on the database files. +# **Run the following command as root to enable clamav selinux support** +# setsebool -P antivirus_can_scan_system true +# +selinux_fixes="no" # Default is "no" ignore ssl errors and warnings + +# Proxy Support +# If necessary to proxy database downloads, define the rsync, curl, wget, dig, hosr proxy settings here. +#rsync_proxy="username:password@proxy_host:proxy_port" +# Define rsync to use netcat for socks tunnel +#rsync_connect_prog="nc -X 5 -x socksproxy_host:socksproxy_port %H 873" +#curl_proxy="--proxy http://username:password@proxy_host:proxy_port" +#wget_proxy="-e http_proxy=http://username:password@proxy_host:proxy_port -e https_proxy=https://username:password@proxy_host:proxy_port" +#dig_proxy="@proxy_host -p proxy_host:proxy_port" +#host_proxy="@proxy_host" #does not support port + +# Custom Cron install settings, these are detected and only used if you want to override +# the automatic detection and generation of the values when not set, this is mainly to aid package maintainers +#cron_bash="" #default: detected with the which command +#cron_dir="" #default: /etc/cron.d +#cron_filename="" #default: clamav-unofficial-sigs +#cron_minute="" #default: random value between 0-59 +#cron_script_full_path="" #default: detected to the fullpath of the script +#cron_sudo="no" #default no, yes will append sudo -u before the username +#cron_user="" #default: uses the clam_user + +# Custom logrotate install settings, these are detected and only used if you want to override +# the automatic detection and generation of the values when not set, this is mainly to aid package maintainers +#logrotate_dir="" #default: /etc/logrotate.d +#logrotate_filename="" #default: clamav-unofficial-sigs +#logrotate_group="" #default: uses the clam_group +#logrotate_log_file_full_path="" #default: detected to the $log_file_path/$log_file_name +#logrotate_user="" #default: uses the clam_user + +# Custom man install settings, these are detected and only used if you want to override +# the automatic detection and generation of the values when not set, this is mainly to aid package maintainers +#man_dir="" #default: /usr/share/man/man8 +#man_filename="" #default: clamav-unofficial-sigs.8 + +# Provided two variables that package and port maintainers can use in order to +# prevent the script from removing itself with the '-r' flag +# If the script was installed via a package manager like yum, apt, pkg, etc. +# The script will instead provide feedback to the user about how to uninstall the package. +#pkg_mgr="" #the package manager name +#pkg_rm="" #the package manager command to remove the script + +# Custom full working directory paths, these are detected and only used if you want to override +# the automatic detection and generation of the values when not set, this is mainly to aid package maintainers +#work_dir_add="" #default: uses work_dir/add_dir +#work_dir_gpg="" #default: uses work_dir/gpg_dir +#work_dir_interserver="" #default: uses work_dir/interserver_dir +#work_dir_linuxmalwaredetect="" #default: uses work_dir/linuxmalwaredetect_dir +#work_dir_malwareexpert="" #default: uses work_dir/malwareexpert_dir +#work_dir_malwarepatrol="" #default: uses work_dir/malwarepatrol_dir +#work_dir_pid="" #default: uses work_dir/pid_dir +#work_dir_sanesecurity="" #default: uses work_dir/sanesecurity_dir +#work_dir_securiteinfo="" #default: uses work_dir/securiteinfo_dir +#work_dir_urlhaus="" #default: uses work_dir/urlhaus_dir +#work_dir_work_configs="" #default: uses work_dir/work_dir_configs +#work_dir_yararulesproject="" #default: uses work_dir/yararulesproject_dir + +# ======================== +# After you have completed the configuration of this file, set the value to "yes" +user_configuration_complete="no" + +# ======================== +# DO NOT EDIT ! +# Database provider URLs +interserver_url="https://sigs.interserver.net" +linuxmalwaredetect_sigpack_url="https://cdn.rfxn.com/downloads/maldet-sigpack.tgz" +linuxmalwaredetect_version_url="https://cdn.rfxn.com/downloads/maldet.sigs.ver" +malwareexpert_url="https://signatures.malware.expert" +malwarepatrol_url="https://lists.malwarepatrol.net/cgi/getfile" +sanesecurity_gpg_url="https://www.sanesecurity.com/publickey.gpg" +sanesecurity_url="rsync.sanesecurity.net" +securiteinfo_url="https://www.securiteinfo.com/get/signatures" +urlhaus_url="https://urlhaus.abuse.ch/downloads" +yararulesproject_url="https://raw.githubusercontent.com/Yara-Rules/rules/master" + +# ======================== +# DO NOT EDIT ! +config_version="97" + +################################################################################ +# +# DO NOT EDIT THIS FILE !! DO NOT EDIT THIS FILE !! DO NOT EDIT THIS FILE !! +# +################################################################################ +# https://eXtremeSHOK.com ###################################################### diff --git a/clamav-unofficial-sigs/os.conf b/clamav-unofficial-sigs/os.conf new file mode 100644 index 00000000..cf99926e --- /dev/null +++ b/clamav-unofficial-sigs/os.conf @@ -0,0 +1,37 @@ +# This file contains os configuration settings for clamav-unofficial-sigs.sh +################### +# This is property of eXtremeSHOK.com +# You are free to use, modify and distribute, however you may not remove this notice. +# Copyright (c) Adrian Jon Kriel :: admin@extremeshok.com +# License: BSD (Berkeley Software Distribution) +################## +# +# Script updates can be found at: https://github.com/extremeshok/clamav-unofficial-sigs +# +################## +# +# NOT COMPATIBLE WITH VERSION 3.XX / 4.XX CONFIG +# +################################################################################ +# SEE MASTER.CONF FOR CONFIG EXPLANATIONS +################################################################################ +# Rename to os.conf to enable this file +################################################################################ + +# Debian 9+ (stretch, buster) + +clam_user="clamav" +clam_group="clamav" + +logrotate_group="adm" + +clam_dbs="/var/lib/clamav" + +clamd_pid="/run/clamav/clamd.pid" + +#systemd. +clamd_restart_opt="systemctl restart clamav-daemon.service" + +#clamd_socket="/run/clamav/clamd.ctl" + +# https://eXtremeSHOK.com ###################################################### diff --git a/clamav-unofficial-sigs/user.conf b/clamav-unofficial-sigs/user.conf new file mode 100644 index 00000000..6b75b7bd --- /dev/null +++ b/clamav-unofficial-sigs/user.conf @@ -0,0 +1,83 @@ +# This file contains user configuration settings for clamav-unofficial-sigs.sh +################### +# This is property of eXtremeSHOK.com +# You are free to use, modify and distribute, however you may not remove this notice. +# Copyright (c) Adrian Jon Kriel :: admin@extremeshok.com +# License: BSD (Berkeley Software Distribution) +################## +# +# Script updates can be found at: https://github.com/extremeshok/clamav-unofficial-sigs +# +################## +# +# NOT COMPATIBLE WITH VERSION 3.XX / 4.XX CONFIG +# +################################################################################ +# SEE MASTER.CONF FOR CONFIG EXPLANATIONS +################################################################################ + +# Values in this file will always override those in the master.conf and os.conf files. +# This is useful to specify your authorisation/receipt codes and to always force certain options. +# Please note, it is your responsibility to manage the contents of this file. +# Values provided here are just examples, feel free to use any values from the main config file. + +# When a database is disabled we will remove the associated database files. +# remove_disabled_databases="yes" # Default is "yes" + +# Malware Expert 2020 (non-free) clamav signatures +# set to no to enable the commercial subscription databases +#malwareexpert_serial_key="YOUR-SERIAL-KEY" + +# set to no to enable the commercial subscription url +#malwarepatrol_free="yes" +#malwarepatrol_list="clamav_basic" # clamav_basic or clamav_ext +# if the malwarepatrol_product_code is not 8 the malwarepatrol_free is set to no (non-free) +#malwarepatrol_product_code="8" +#malwarepatrol_receipt_code="YOUR-RECEIPT-NUMBER" +#malwarepatrol_db="malwarepatrol.db" + +#securiteinfo_authorisation_signature="YOUR-SIGNATURE-NUMBER" +# Enable if you have a commercial/premium/non-free subscription +#securiteinfo_premium="yes" + +# Default dbs rating (Default: MEDIUM) +# valid rating: LOW, MEDIUM, HIGH, DISABLE +#default_dbs_rating="HIGH" + +# Per Database +# These ratings will override the global rating for the specific database +# valid rating: LOW, MEDIUM, HIGH, DISABLE +#interserver_dbs_rating="HIGH" +#linuxmalwaredetect_dbs_rating="HIGH" +#malwareexpert_dbs_rating="HIGH" +#sanesecurity_dbs_rating="HIGH" +#securiteinfo_dbs_rating="HIGH" +#urlhaus_dbs_rating="HIGH" +#yararulesproject_dbs_rating="HIGH" + +# ========================= +# Additional signature databases +# ========================= +#declare -a additional_dbs=( +# ftp://ftp.example.net/pub/sigs.ndb +# http://www.example.org/sigs.ldb +#) #END ADDITIONAL DATABASES + +# Uncomment the following line to enable the script +user_configuration_complete="yes" + +# HTTPS validation +# Uncomment to allow and ignore SSL errors leading to insecure transfers +# downloader_ignore_ssl_errors="yes" # Default is "no" + +# Proxy Support +# If necessary to proxy database downloads, define the rsync, curl, wget, dig, hosr proxy settings here. +#curl_proxy="--proxy http://username:password@proxy_host:proxy_port" +#dig_proxy="@proxy_host -p proxy_host:proxy_port" +#host_proxy="@proxy_host" #does not support port +#rsync_proxy="username:password@proxy_host:proxy_port" +# Define rsync to use netcat for socks tunnel +#rsync_connect_prog="nc -X 5 -x socksproxy_host:socksproxy_port %H 873" +#wget_proxy="-e http_proxy=http://username:password@proxy_host:proxy_port -e https_proxy=https://username:password@proxy_host:proxy_port" + +# https://eXtremeSHOK.com ###################################################### diff --git a/clamav/clamd.conf b/clamav/clamd.conf new file mode 100644 index 00000000..9823e40a --- /dev/null +++ b/clamav/clamd.conf @@ -0,0 +1,87 @@ +#Automatically Generated by clamav-daemon postinst +#To reconfigure clamd run #dpkg-reconfigure clamav-daemon +#Please read /usr/share/doc/clamav-daemon/README.Debian.gz for details +LocalSocket /var/run/clamav/clamd.ctl +FixStaleSocket true +LocalSocketGroup clamav +LocalSocketMode 666 +# TemporaryDirectory is not set to its default /tmp here to make overriding +# the default with environment variables TMPDIR/TMP/TEMP possible +User clamav +ScanMail true +ScanArchive true +ArchiveBlockEncrypted false +MaxDirectoryRecursion 15 +FollowDirectorySymlinks false +FollowFileSymlinks false +ReadTimeout 180 +MaxThreads 10 +MaxConnectionQueueLength 15 +LogSyslog false +LogRotate true +LogFacility LOG_LOCAL6 +LogClean false +LogVerbose false +PreludeEnable no +PreludeAnalyzerName ClamAV +DatabaseDirectory /var/lib/clamav +OfficialDatabaseOnly false +SelfCheck 600 +Foreground false +Debug false +ScanPE true +MaxEmbeddedPE 10M +ScanOLE2 true +ScanPDF true +ScanHTML true +MaxHTMLNormalize 10M +MaxHTMLNoTags 2M +MaxScriptNormalize 5M +MaxZipTypeRcg 1M +ScanSWF true +ExitOnOOM false +LeaveTemporaryFiles false +AlgorithmicDetection true +ScanELF true +IdleTimeout 30 +CrossFilesystems true +PhishingSignatures true +PhishingScanURLs true +PhishingAlwaysBlockSSLMismatch false +PhishingAlwaysBlockCloak false +PartitionIntersection false +DetectPUA false +ScanPartialMessages false +HeuristicScanPrecedence false +StructuredDataDetection false +CommandReadTimeout 5 +SendBufTimeout 200 +MaxQueue 100 +ExtendedDetectionInfo true +OLE2BlockMacros false +AllowAllMatchScan true +ForceToDisk false +DisableCertCheck false +DisableCache false +MaxScanTime 120000 +MaxScanSize 50M +MaxFileSize 15M +MaxRecursion 16 +MaxFiles 10000 +MaxPartitions 50 +MaxIconsPE 100 +PCREMatchLimit 10000 +PCRERecMatchLimit 5000 +PCREMaxFileSize 15M +ScanXMLDOCS true +ScanHWP3 true +MaxRecHWP3 16 +StreamMaxLength 15M +LogFile /var/log/clamav/clamav.log +LogTime true +LogFileUnlock false +LogFileMaxSize 0 +Bytecode true +BytecodeSecurity TrustSigned +BytecodeTimeout 60000 +OnAccessMaxFileSize 5M diff --git a/clamav/freshclam.conf b/clamav/freshclam.conf new file mode 100644 index 00000000..41fb5375 --- /dev/null +++ b/clamav/freshclam.conf @@ -0,0 +1,30 @@ +# Automatically created by the clamav-freshclam postinst +# Comments will get lost when you reconfigure the clamav-freshclam package + +DatabaseOwner clamav +UpdateLogFile /var/log/clamav/freshclam.log +LogVerbose false +LogSyslog false +LogFacility LOG_LOCAL6 +LogFileMaxSize 0 +LogTime true +Foreground false +Debug false +MaxAttempts 5 +DatabaseDirectory /var/lib/clamav +DNSDatabaseInfo current.cvd.clamav.net +#AllowSupplementaryGroups false +PidFile /var/run/clamav/freshclam.pid +ConnectTimeout 30 +ReceiveTimeout 30 +TestDatabases yes +ScriptedUpdates yes +CompressLocalDatabase no +Bytecode true +# Check for new database 24 times a day +Checks 24 +DatabaseMirror db.local.clamav.net +DatabaseMirror database.clamav.net +DatabaseMirror clamav.ilisys.com.au +DatabaseMirror 193.27.50.222 +DatabaseMirror clamav.inode.at diff --git a/cloud/cloud-init.disabled b/cloud/cloud-init.disabled new file mode 100644 index 00000000..e69de29b diff --git a/cloud/cloud.cfg b/cloud/cloud.cfg new file mode 100644 index 00000000..4a6e45ca --- /dev/null +++ b/cloud/cloud.cfg @@ -0,0 +1,106 @@ +# The top level settings are used as module +# and system configuration. + +# A set of users which may be applied and/or used by various modules +# when a 'default' entry is found it will reference the 'default_user' +# from the distro configuration specified below +users: + - default + +# If this is set, 'root' will not be able to ssh in and they +# will get a message to login instead as the above $user (debian) +disable_root: true + +# This will cause the set+update hostname module to not operate (if true) +preserve_hostname: false + +# This prevents cloud-init from rewriting apt's sources.list file, +# which has been a source of surprise. +apt_preserve_sources_list: true + +# Example datasource config +# datasource: +# Ec2: +# metadata_urls: [ 'blah.com' ] +# timeout: 5 # (defaults to 50 seconds) +# max_wait: 10 # (defaults to 120 seconds) + +# The modules that run in the 'init' stage +cloud_init_modules: + - migrator + - seed_random + - bootcmd + - write-files + - growpart + - resizefs + - disk_setup + - mounts + - set_hostname + - update_hostname + - update_etc_hosts + - ca-certs + - rsyslog + - users-groups + - ssh + +# The modules that run in the 'config' stage +cloud_config_modules: +# Emit the cloud config ready event +# this can be used by upstart jobs for 'start on cloud-config'. + - emit_upstart + - ssh-import-id + - locale + - set-passwords + - grub-dpkg + - apt-pipelining + - apt-configure + - ntp + - timezone + - disable-ec2-metadata + - runcmd + - byobu + +# The modules that run in the 'final' stage +cloud_final_modules: + - package-update-upgrade-install + - fan + - puppet + - chef + - salt-minion + - mcollective + - rightscale_userdata + - scripts-vendor + - scripts-per-once + - scripts-per-boot + - scripts-per-instance + - scripts-user + - ssh-authkey-fingerprints + - keys-to-console + - phone-home + - final-message + - power-state-change + +# System and/or distro specific settings +# (not accessible to handlers/transforms) +system_info: + # This will affect which distro class gets used + distro: debian + # Default user name + that default users groups (if added/used) + default_user: + name: debian + lock_passwd: True + gecos: Debian + groups: [adm, audio, cdrom, dialout, dip, floppy, netdev, plugdev, sudo, video] + sudo: ["ALL=(ALL) NOPASSWD:ALL"] + shell: /bin/bash + # Other config here will be given to the distro class and/or path classes + paths: + cloud_dir: /var/lib/cloud/ + templates_dir: /etc/cloud/templates/ + upstart_dir: /etc/init/ + package_mirrors: + - arches: [default] + failsafe: + primary: http://deb.debian.org/debian + security: http://security.debian.org/ + ssh_svcname: ssh diff --git a/cloud/cloud.cfg.d/00_debian.cfg b/cloud/cloud.cfg.d/00_debian.cfg new file mode 100644 index 00000000..ad36cef9 --- /dev/null +++ b/cloud/cloud.cfg.d/00_debian.cfg @@ -0,0 +1,2 @@ +syslog_fix_perms: root:adm +mount_default_fields: [~, ~, 'auto', 'defaults,nofail', '0', '2'] diff --git a/cloud/cloud.cfg.d/05_logging.cfg b/cloud/cloud.cfg.d/05_logging.cfg new file mode 100644 index 00000000..bf917a95 --- /dev/null +++ b/cloud/cloud.cfg.d/05_logging.cfg @@ -0,0 +1,71 @@ +## This yaml formated config file handles setting +## logger information. The values that are necessary to be set +## are seen at the bottom. The top '_log' are only used to remove +## redundency in a syslog and fallback-to-file case. +## +## The 'log_cfgs' entry defines a list of logger configs +## Each entry in the list is tried, and the first one that +## works is used. If a log_cfg list entry is an array, it will +## be joined with '\n'. +_log: + - &log_base | + [loggers] + keys=root,cloudinit + + [handlers] + keys=consoleHandler,cloudLogHandler + + [formatters] + keys=simpleFormatter,arg0Formatter + + [logger_root] + level=DEBUG + handlers=consoleHandler,cloudLogHandler + + [logger_cloudinit] + level=DEBUG + qualname=cloudinit + handlers= + propagate=1 + + [handler_consoleHandler] + class=StreamHandler + level=WARNING + formatter=arg0Formatter + args=(sys.stderr,) + + [formatter_arg0Formatter] + format=%(asctime)s - %(filename)s[%(levelname)s]: %(message)s + + [formatter_simpleFormatter] + format=[CLOUDINIT] %(filename)s[%(levelname)s]: %(message)s + - &log_file | + [handler_cloudLogHandler] + class=FileHandler + level=DEBUG + formatter=arg0Formatter + args=('/var/log/cloud-init.log', 'a', 'UTF-8') + - &log_syslog | + [handler_cloudLogHandler] + class=handlers.SysLogHandler + level=DEBUG + formatter=simpleFormatter + args=("/dev/log", handlers.SysLogHandler.LOG_USER) + +log_cfgs: +# Array entries in this list will be joined into a string +# that defines the configuration. +# +# If you want logs to go to syslog, uncomment the following line. +# - [ *log_base, *log_syslog ] +# +# The default behavior is to just log to a file. +# This mechanism that does not depend on a system service to operate. + - [ *log_base, *log_file ] +# A file path can also be used. +# - /etc/log.conf + +# This tells cloud-init to redirect its stdout and stderr to +# 'tee -a /var/log/cloud-init-output.log' so the user can see output +# there without needing to look on the console. +output: {all: '| tee -a /var/log/cloud-init-output.log'} diff --git a/cloud/cloud.cfg.d/99_nc.cfg b/cloud/cloud.cfg.d/99_nc.cfg new file mode 100644 index 00000000..9e528098 --- /dev/null +++ b/cloud/cloud.cfg.d/99_nc.cfg @@ -0,0 +1,7 @@ +datasource_list: [ NoCloud, None ] +users: [] +ssh_deletekeys: false +growpart: + mode: off +locale: en_US.UTF-8 +timezone: Europe/Berlin diff --git a/cloud/cloud.cfg.d/99_nc_network_disable.cfg b/cloud/cloud.cfg.d/99_nc_network_disable.cfg new file mode 100644 index 00000000..3a7784d8 --- /dev/null +++ b/cloud/cloud.cfg.d/99_nc_network_disable.cfg @@ -0,0 +1,2 @@ +network: + config: disabled diff --git a/cloud/cloud.cfg.d/README b/cloud/cloud.cfg.d/README new file mode 100644 index 00000000..036b80bf --- /dev/null +++ b/cloud/cloud.cfg.d/README @@ -0,0 +1,3 @@ +# All files with the '.cfg' extension in this directory will be read by +# cloud-init. They are read in lexical order. Later files overwrite values in +# earlier files. diff --git a/cloud/templates/chef_client.rb.tmpl b/cloud/templates/chef_client.rb.tmpl new file mode 100644 index 00000000..0a759b04 --- /dev/null +++ b/cloud/templates/chef_client.rb.tmpl @@ -0,0 +1,64 @@ +## template:jinja +{# +This file is only utilized if the module 'cc_chef' is enabled in +cloud-config. Specifically, in order to enable it +you need to add the following to config: + chef: + validation_key: XYZ + validation_cert: XYZ + validation_name: XYZ + server_url: XYZ +-#} +{{generated_by}} +{# +The reason these are not in quotes is because they are ruby +symbols that will be placed inside here, and not actual strings... +#} +{% if chef_license %} +chef_license "{{chef_license}}" +{% endif%} +{% if log_level %} +log_level {{log_level}} +{% endif %} +{% if ssl_verify_mode %} +ssl_verify_mode {{ssl_verify_mode}} +{% endif %} +{% if log_location %} +log_location "{{log_location}}" +{% endif %} +{% if validation_name %} +validation_client_name "{{validation_name}}" +{% endif %} +{% if validation_cert %} +validation_key "{{validation_key}}" +{% endif %} +{% if client_key %} +client_key "{{client_key}}" +{% endif %} +{% if server_url %} +chef_server_url "{{server_url}}" +{% endif %} +{% if environment %} +environment "{{environment}}" +{% endif %} +{% if node_name %} +node_name "{{node_name}}" +{% endif %} +{% if json_attribs %} +json_attribs "{{json_attribs}}" +{% endif %} +{% if file_cache_path %} +file_cache_path "{{file_cache_path}}" +{% endif %} +{% if file_backup_path %} +file_backup_path "{{file_backup_path}}" +{% endif %} +{% if pid_file %} +pid_file "{{pid_file}}" +{% endif %} +{% if show_time %} +Chef::Log::Formatter.show_time = true +{% endif %} +{% if encrypted_data_bag_secret %} +encrypted_data_bag_secret "{{encrypted_data_bag_secret}}" +{% endif %} diff --git a/cloud/templates/chrony.conf.alpine.tmpl b/cloud/templates/chrony.conf.alpine.tmpl new file mode 100644 index 00000000..45efc18c --- /dev/null +++ b/cloud/templates/chrony.conf.alpine.tmpl @@ -0,0 +1,38 @@ +## template:jinja +# Welcome to the chrony configuration file. See chrony.conf(5) for more +# information about usable directives. +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# This directive specifies the location of the file containing ID/key pairs for +# NTP authentication. +keyfile /etc/chrony/chrony.keys + +# This directive specifies the file into which chronyd will store the rate +# information. +driftfile /var/lib/chrony/chrony.drift + +# Uncomment the following line to turn logging on. +#log tracking measurements statistics + +# Log files location. +logdir /var/log/chrony + +# Stop bad estimates upsetting machine clock. +maxupdateskew 100.0 + +# This directive enables kernel synchronisation (every 11 minutes) of the +# real-time clock. Note that it can’t be used along with the 'rtcfile' directive. +rtcsync + +# Step the system clock instead of slewing it if the adjustment is larger than +# one second, but only in the first three clock updates. +makestep 1 3 diff --git a/cloud/templates/chrony.conf.debian.tmpl b/cloud/templates/chrony.conf.debian.tmpl new file mode 100644 index 00000000..661bf04e --- /dev/null +++ b/cloud/templates/chrony.conf.debian.tmpl @@ -0,0 +1,39 @@ +## template:jinja +# Welcome to the chrony configuration file. See chrony.conf(5) for more +# information about usuable directives. +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# This directive specify the location of the file containing ID/key pairs for +# NTP authentication. +keyfile /etc/chrony/chrony.keys + +# This directive specify the file into which chronyd will store the rate +# information. +driftfile /var/lib/chrony/chrony.drift + +# Uncomment the following line to turn logging on. +#log tracking measurements statistics + +# Log files location. +logdir /var/log/chrony + +# Stop bad estimates upsetting machine clock. +maxupdateskew 100.0 + +# This directive enables kernel synchronisation (every 11 minutes) of the +# real-time clock. Note that it can’t be used along with the 'rtcfile' directive. +rtcsync + +# Step the system clock instead of slewing it if the adjustment is larger than +# one second, but only in the first three clock updates. +makestep 1 3 + diff --git a/cloud/templates/chrony.conf.fedora.tmpl b/cloud/templates/chrony.conf.fedora.tmpl new file mode 100644 index 00000000..8551f793 --- /dev/null +++ b/cloud/templates/chrony.conf.fedora.tmpl @@ -0,0 +1,48 @@ +## template:jinja +# Use public servers from the pool.ntp.org project. +# Please consider joining the pool (http://www.pool.ntp.org/join.html). +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Record the rate at which the system clock gains/losses time. +driftfile /var/lib/chrony/drift + +# Allow the system clock to be stepped in the first three updates +# if its offset is larger than 1 second. +makestep 1.0 3 + +# Enable kernel synchronization of the real-time clock (RTC). +rtcsync + +# Enable hardware timestamping on all interfaces that support it. +#hwtimestamp * + +# Increase the minimum number of selectable sources required to adjust +# the system clock. +#minsources 2 + +# Allow NTP client access from local network. +#allow 192.168.0.0/16 + +# Serve time even if not synchronized to a time source. +#local stratum 10 + +# Specify file containing keys for NTP authentication. +#keyfile /etc/chrony.keys + +# Get TAI-UTC offset and leap seconds from the system tz database. +leapsectz right/UTC + +# Specify directory for log files. +logdir /var/log/chrony + +# Select which information is logged. +#log measurements statistics tracking diff --git a/cloud/templates/chrony.conf.opensuse.tmpl b/cloud/templates/chrony.conf.opensuse.tmpl new file mode 100644 index 00000000..a3d3e0ec --- /dev/null +++ b/cloud/templates/chrony.conf.opensuse.tmpl @@ -0,0 +1,38 @@ +## template:jinja +# Use public servers from the pool.ntp.org project. +# Please consider joining the pool (http://www.pool.ntp.org/join.html). +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Record the rate at which the system clock gains/losses time. +driftfile /var/lib/chrony/drift + +# In first three updates step the system clock instead of slew +# if the adjustment is larger than 1 second. +makestep 1.0 3 + +# Enable kernel synchronization of the real-time clock (RTC). +rtcsync + +# Allow NTP client access from local network. +#allow 192.168/16 + +# Serve time even if not synchronized to any NTP server. +#local stratum 10 + +# Specify file containing keys for NTP authentication. +#keyfile /etc/chrony.keys + +# Specify directory for log files. +logdir /var/log/chrony + +# Select which information is logged. +#log measurements statistics tracking diff --git a/cloud/templates/chrony.conf.rhel.tmpl b/cloud/templates/chrony.conf.rhel.tmpl new file mode 100644 index 00000000..5b3542ef --- /dev/null +++ b/cloud/templates/chrony.conf.rhel.tmpl @@ -0,0 +1,45 @@ +## template:jinja +# Use public servers from the pool.ntp.org project. +# Please consider joining the pool (http://www.pool.ntp.org/join.html). +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Record the rate at which the system clock gains/losses time. +driftfile /var/lib/chrony/drift + +# Allow the system clock to be stepped in the first three updates +# if its offset is larger than 1 second. +makestep 1.0 3 + +# Enable kernel synchronization of the real-time clock (RTC). +rtcsync + +# Enable hardware timestamping on all interfaces that support it. +#hwtimestamp * + +# Increase the minimum number of selectable sources required to adjust +# the system clock. +#minsources 2 + +# Allow NTP client access from local network. +#allow 192.168.0.0/16 + +# Serve time even if not synchronized to a time source. +#local stratum 10 + +# Specify file containing keys for NTP authentication. +#keyfile /etc/chrony.keys + +# Specify directory for log files. +logdir /var/log/chrony + +# Select which information is logged. +#log measurements statistics tracking diff --git a/cloud/templates/chrony.conf.sles.tmpl b/cloud/templates/chrony.conf.sles.tmpl new file mode 100644 index 00000000..a3d3e0ec --- /dev/null +++ b/cloud/templates/chrony.conf.sles.tmpl @@ -0,0 +1,38 @@ +## template:jinja +# Use public servers from the pool.ntp.org project. +# Please consider joining the pool (http://www.pool.ntp.org/join.html). +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Record the rate at which the system clock gains/losses time. +driftfile /var/lib/chrony/drift + +# In first three updates step the system clock instead of slew +# if the adjustment is larger than 1 second. +makestep 1.0 3 + +# Enable kernel synchronization of the real-time clock (RTC). +rtcsync + +# Allow NTP client access from local network. +#allow 192.168/16 + +# Serve time even if not synchronized to any NTP server. +#local stratum 10 + +# Specify file containing keys for NTP authentication. +#keyfile /etc/chrony.keys + +# Specify directory for log files. +logdir /var/log/chrony + +# Select which information is logged. +#log measurements statistics tracking diff --git a/cloud/templates/chrony.conf.ubuntu.tmpl b/cloud/templates/chrony.conf.ubuntu.tmpl new file mode 100644 index 00000000..50a6f518 --- /dev/null +++ b/cloud/templates/chrony.conf.ubuntu.tmpl @@ -0,0 +1,42 @@ +## template:jinja +# Welcome to the chrony configuration file. See chrony.conf(5) for more +# information about usuable directives. + +# Use servers from the NTP Pool Project. Approved by Ubuntu Technical Board +# on 2011-02-08 (LP: #104525). See http://www.pool.ntp.org/join.html for +# more information. +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# This directive specify the location of the file containing ID/key pairs for +# NTP authentication. +keyfile /etc/chrony/chrony.keys + +# This directive specify the file into which chronyd will store the rate +# information. +driftfile /var/lib/chrony/chrony.drift + +# Uncomment the following line to turn logging on. +#log tracking measurements statistics + +# Log files location. +logdir /var/log/chrony + +# Stop bad estimates upsetting machine clock. +maxupdateskew 100.0 + +# This directive enables kernel synchronisation (every 11 minutes) of the +# real-time clock. Note that it can’t be used along with the 'rtcfile' directive. +rtcsync + +# Step the system clock instead of slewing it if the adjustment is larger than +# one second, but only in the first three clock updates. +makestep 1 3 diff --git a/cloud/templates/hosts.alpine.tmpl b/cloud/templates/hosts.alpine.tmpl new file mode 100644 index 00000000..33c1a941 --- /dev/null +++ b/cloud/templates/hosts.alpine.tmpl @@ -0,0 +1,28 @@ +## template:jinja +{# +This file /etc/cloud/templates/hosts.alpine.tmpl is only utilized +if enabled in cloud-config. Specifically, in order to enable it +you need to add the following to config: + manage_etc_hosts: True +-#} +# Your system has configured 'manage_etc_hosts' as True. +# As a result, if you wish for changes to this file to persist +# then you will need to either +# a.) make changes to the master file in /etc/cloud/templates/hosts.alpine.tmpl +# b.) change or remove the value of 'manage_etc_hosts' in +# /etc/cloud/cloud.cfg or cloud-config from user-data +# +# The following lines are desirable for IPv4 capable hosts +127.0.1.1 {{fqdn}} {{hostname}} +127.0.0.1 localhost.localdomain localhost +127.0.0.1 localhost4.localdomain4 localhost4 + +# The following lines are desirable for IPv6 capable hosts +::1 {{fqdn}} {{hostname}} +::1 localhost6.localdomain6 localhost6 + +fe00::0 ip6-localnet +ff00::0 ip6-mcastprefix +ff02::1 ip6-allnodes +ff02::2 ip6-allrouters +ff02::3 ip6-allhosts diff --git a/cloud/templates/hosts.debian.tmpl b/cloud/templates/hosts.debian.tmpl new file mode 100644 index 00000000..7e29907a --- /dev/null +++ b/cloud/templates/hosts.debian.tmpl @@ -0,0 +1,26 @@ +## template:jinja +{# +This file (/etc/cloud/templates/hosts.debian.tmpl) is only utilized +if enabled in cloud-config. Specifically, in order to enable it +you need to add the following to config: + manage_etc_hosts: True +-#} +# Your system has configured 'manage_etc_hosts' as True. +# As a result, if you wish for changes to this file to persist +# then you will need to either +# a.) make changes to the master file in /etc/cloud/templates/hosts.debian.tmpl +# b.) change or remove the value of 'manage_etc_hosts' in +# /etc/cloud/cloud.cfg or cloud-config from user-data +# +{# The value '{{hostname}}' will be replaced with the local-hostname -#} +127.0.1.1 {{fqdn}} {{hostname}} +127.0.0.1 localhost + +# The following lines are desirable for IPv6 capable hosts +::1 ip6-localhost ip6-loopback +fe00::0 ip6-localnet +ff00::0 ip6-mcastprefix +ff02::1 ip6-allnodes +ff02::2 ip6-allrouters +ff02::3 ip6-allhosts + diff --git a/cloud/templates/hosts.freebsd.tmpl b/cloud/templates/hosts.freebsd.tmpl new file mode 100644 index 00000000..5cd5d3bc --- /dev/null +++ b/cloud/templates/hosts.freebsd.tmpl @@ -0,0 +1,23 @@ +## template:jinja +{# +This file /etc/cloud/templates/hosts.freebsd.tmpl is only utilized +if enabled in cloud-config. Specifically, in order to enable it +you need to add the following to config: + manage_etc_hosts: True +-#} +# Your system has configured 'manage_etc_hosts' as True. +# As a result, if you wish for changes to this file to persist +# then you will need to either +# a.) make changes to the master file in /etc/cloud/templates/hosts.freebsd.tmpl +# b.) change or remove the value of 'manage_etc_hosts' in +# /etc/cloud/cloud.cfg or cloud-config from user-data + +# The following lines are desirable for IPv6 capable hosts +::1 {{fqdn}} {{hostname}} +::1 localhost.localdomain localhost +::1 localhost6.localdomain6 localhost6 + +# The following lines are desirable for IPv4 capable hosts +127.0.0.1 {{fqdn}} {{hostname}} +127.0.0.1 localhost.localdomain localhost +127.0.0.1 localhost4.localdomain4 localhost4 diff --git a/cloud/templates/hosts.redhat.tmpl b/cloud/templates/hosts.redhat.tmpl new file mode 100644 index 00000000..bc5da32c --- /dev/null +++ b/cloud/templates/hosts.redhat.tmpl @@ -0,0 +1,24 @@ +## template:jinja +{# +This file /etc/cloud/templates/hosts.redhat.tmpl is only utilized +if enabled in cloud-config. Specifically, in order to enable it +you need to add the following to config: + manage_etc_hosts: True +-#} +# Your system has configured 'manage_etc_hosts' as True. +# As a result, if you wish for changes to this file to persist +# then you will need to either +# a.) make changes to the master file in /etc/cloud/templates/hosts.redhat.tmpl +# b.) change or remove the value of 'manage_etc_hosts' in +# /etc/cloud/cloud.cfg or cloud-config from user-data +# +# The following lines are desirable for IPv4 capable hosts +127.0.0.1 {{fqdn}} {{hostname}} +127.0.0.1 localhost.localdomain localhost +127.0.0.1 localhost4.localdomain4 localhost4 + +# The following lines are desirable for IPv6 capable hosts +::1 {{fqdn}} {{hostname}} +::1 localhost.localdomain localhost +::1 localhost6.localdomain6 localhost6 + diff --git a/cloud/templates/hosts.suse.tmpl b/cloud/templates/hosts.suse.tmpl new file mode 100644 index 00000000..5d7953f0 --- /dev/null +++ b/cloud/templates/hosts.suse.tmpl @@ -0,0 +1,32 @@ +## template:jinja +{# +This file /etc/cloud/templates/hosts.suse.tmpl is only utilized +if enabled in cloud-config. Specifically, in order to enable it +you need to add the following to config: + manage_etc_hosts: True +-#} +# Your system has configured 'manage_etc_hosts' as True. +# As a result, if you wish for changes to this file to persist +# then you will need to either +# a.) make changes to the master file in /etc/cloud/templates/hosts.suse.tmpl +# b.) change or remove the value of 'manage_etc_hosts' in +# /etc/cloud/cloud.cfg or cloud-config from user-data +# +# The following lines are desirable for IPv4 capable hosts +127.0.1.1 {{fqdn}} {{hostname}} +127.0.0.1 localhost.localdomain localhost +127.0.0.1 localhost4.localdomain4 localhost4 + +# The following lines are desirable for IPv6 capable hosts +::1 {{fqdn}} {{hostname}} +::1 localhost.localdomain localhost +::1 localhost6.localdomain6 localhost6 +::1 localhost ipv6-localhost ipv6-loopback + + +fe00::0 ipv6-localnet +ff00::0 ipv6-mcastprefix +ff02::1 ipv6-allnodes +ff02::2 ipv6-allrouters +ff02::3 ipv6-allhosts + diff --git a/cloud/templates/ntp.conf.alpine.tmpl b/cloud/templates/ntp.conf.alpine.tmpl new file mode 100644 index 00000000..59ca8fc1 --- /dev/null +++ b/cloud/templates/ntp.conf.alpine.tmpl @@ -0,0 +1,10 @@ +## template:jinja +# /etc/ntp.conf +# +# Configuration for Busybox ntpd - it only supports "server" lines. + +{% if servers %}# Servers +{% endif %} +{% for server in servers -%} +server {{server}} +{% endfor %} diff --git a/cloud/templates/ntp.conf.debian.tmpl b/cloud/templates/ntp.conf.debian.tmpl new file mode 100644 index 00000000..affe983d --- /dev/null +++ b/cloud/templates/ntp.conf.debian.tmpl @@ -0,0 +1,64 @@ +## template:jinja + +# /etc/ntp.conf, configuration for ntpd; see ntp.conf(5) for help + +driftfile /var/lib/ntp/ntp.drift + +# Enable this if you want statistics to be logged. +#statsdir /var/log/ntpstats/ + +statistics loopstats peerstats clockstats +filegen loopstats file loopstats type day enable +filegen peerstats file peerstats type day enable +filegen clockstats file clockstats type day enable + + +# You do need to talk to an NTP server or two (or three). +#server ntp.your-provider.example + +# pool.ntp.org maps to about 1000 low-stratum NTP servers. Your server will +# pick a different set every time it starts up. Please consider joining the +# pool: +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Access control configuration; see /usr/share/doc/ntp-doc/html/accopt.html for +# details. The web page +# might also be helpful. +# +# Note that "restrict" applies to both servers and clients, so a configuration +# that might be intended to block requests from certain clients could also end +# up blocking replies from your own upstream servers. + +# By default, exchange time with everybody, but don't allow configuration. +restrict -4 default kod notrap nomodify nopeer noquery limited +restrict -6 default kod notrap nomodify nopeer noquery limited + +# Local users may interrogate the ntp server more closely. +restrict 127.0.0.1 +restrict ::1 + +# Needed for adding pool entries +restrict source notrap nomodify noquery + +# Clients from this (example!) subnet have unlimited access, but only if +# cryptographically authenticated. +#restrict 192.168.123.0 mask 255.255.255.0 notrust + + +# If you want to provide time to your local subnet, change the next line. +# (Again, the address is an example only.) +#broadcast 192.168.123.255 + +# If you want to listen to time broadcasts on your local subnet, de-comment the +# next lines. Please do this only if you trust everybody on the network! +#disable auth +#broadcastclient diff --git a/cloud/templates/ntp.conf.fedora.tmpl b/cloud/templates/ntp.conf.fedora.tmpl new file mode 100644 index 00000000..af7b1b09 --- /dev/null +++ b/cloud/templates/ntp.conf.fedora.tmpl @@ -0,0 +1,66 @@ +## template:jinja + +# For more information about this file, see the man pages +# ntp.conf(5), ntp_acc(5), ntp_auth(5), ntp_clock(5), ntp_misc(5), ntp_mon(5). + +driftfile /var/lib/ntp/drift + +# Permit time synchronization with our time source, but do not +# permit the source to query or modify the service on this system. +restrict default nomodify notrap nopeer noquery + +# Permit all access over the loopback interface. This could +# be tightened as well, but to do so would effect some of +# the administrative functions. +restrict 127.0.0.1 +restrict ::1 + +# Hosts on local network are less restricted. +#restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap + +# Use public servers from the pool.ntp.org project. +# Please consider joining the pool (http://www.pool.ntp.org/join.html). +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +#broadcast 192.168.1.255 autokey # broadcast server +#broadcastclient # broadcast client +#broadcast 224.0.1.1 autokey # multicast server +#multicastclient 224.0.1.1 # multicast client +#manycastserver 239.255.254.254 # manycast server +#manycastclient 239.255.254.254 autokey # manycast client + +# Enable public key cryptography. +#crypto + +includefile /etc/ntp/crypto/pw + +# Key file containing the keys and key identifiers used when operating +# with symmetric key cryptography. +keys /etc/ntp/keys + +# Specify the key identifiers which are trusted. +#trustedkey 4 8 42 + +# Specify the key identifier to use with the ntpdc utility. +#requestkey 8 + +# Specify the key identifier to use with the ntpq utility. +#controlkey 8 + +# Enable writing of statistics records. +#statistics clockstats cryptostats loopstats peerstats + +# Disable the monitoring facility to prevent amplification attacks using ntpdc +# monlist command when default restrict does not include the noquery flag. See +# CVE-2013-5211 for more details. +# Note: Monitoring will not be disabled with the limited restriction flag. +disable monitor diff --git a/cloud/templates/ntp.conf.opensuse.tmpl b/cloud/templates/ntp.conf.opensuse.tmpl new file mode 100644 index 00000000..f3ab565f --- /dev/null +++ b/cloud/templates/ntp.conf.opensuse.tmpl @@ -0,0 +1,88 @@ +## template:jinja + +## +## Radio and modem clocks by convention have addresses in the +## form 127.127.t.u, where t is the clock type and u is a unit +## number in the range 0-3. +## +## Most of these clocks require support in the form of a +## serial port or special bus peripheral. The particular +## device is normally specified by adding a soft link +## /dev/device-u to the particular hardware device involved, +## where u correspond to the unit number above. +## +## Generic DCF77 clock on serial port (Conrad DCF77) +## Address: 127.127.8.u +## Serial Port: /dev/refclock-u +## +## (create soft link /dev/refclock-0 to the particular ttyS?) +## +# server 127.127.8.0 mode 5 prefer + +## +## Undisciplined Local Clock. This is a fake driver intended for backup +## and when no outside source of synchronized time is available. +## +# server 127.127.1.0 # local clock (LCL) +# fudge 127.127.1.0 stratum 10 # LCL is unsynchronized + +## +## Add external Servers using +## # rcntpd addserver +## The servers will only be added to the currently running instance, not +## to /etc/ntp.conf. +## +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Access control configuration; see /usr/share/doc/packages/ntp/html/accopt.html for +# details. The web page +# might also be helpful. +# +# Note that "restrict" applies to both servers and clients, so a configuration +# that might be intended to block requests from certain clients could also end +# up blocking replies from your own upstream servers. + +# By default, exchange time with everybody, but don't allow configuration. +restrict -4 default notrap nomodify nopeer noquery +restrict -6 default notrap nomodify nopeer noquery + +# Local users may interrogate the ntp server more closely. +restrict 127.0.0.1 +restrict ::1 + +# Clients from this (example!) subnet have unlimited access, but only if +# cryptographically authenticated. +#restrict 192.168.123.0 mask 255.255.255.0 notrust + +## +## Miscellaneous stuff +## + +driftfile /var/lib/ntp/drift/ntp.drift # path for drift file + +logfile /var/log/ntp # alternate log file +# logconfig =syncstatus + sysevents +# logconfig =all + +# statsdir /tmp/ # directory for statistics files +# filegen peerstats file peerstats type day enable +# filegen loopstats file loopstats type day enable +# filegen clockstats file clockstats type day enable + +# +# Authentication stuff +# +keys /etc/ntp.keys # path for keys file +trustedkey 1 # define trusted keys +requestkey 1 # key (7) for accessing server variables +controlkey 1 # key (6) for accessing server variables + diff --git a/cloud/templates/ntp.conf.rhel.tmpl b/cloud/templates/ntp.conf.rhel.tmpl new file mode 100644 index 00000000..62b47764 --- /dev/null +++ b/cloud/templates/ntp.conf.rhel.tmpl @@ -0,0 +1,61 @@ +## template:jinja + +# For more information about this file, see the man pages +# ntp.conf(5), ntp_acc(5), ntp_auth(5), ntp_clock(5), ntp_misc(5), ntp_mon(5). + +driftfile /var/lib/ntp/drift + +# Permit time synchronization with our time source, but do not +# permit the source to query or modify the service on this system. +restrict default kod nomodify notrap nopeer noquery +restrict -6 default kod nomodify notrap nopeer noquery + +# Permit all access over the loopback interface. This could +# be tightened as well, but to do so would effect some of +# the administrative functions. +restrict 127.0.0.1 +restrict -6 ::1 + +# Hosts on local network are less restricted. +#restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap + +# Use public servers from the pool.ntp.org project. +# Please consider joining the pool (http://www.pool.ntp.org/join.html). +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +#broadcast 192.168.1.255 autokey # broadcast server +#broadcastclient # broadcast client +#broadcast 224.0.1.1 autokey # multicast server +#multicastclient 224.0.1.1 # multicast client +#manycastserver 239.255.254.254 # manycast server +#manycastclient 239.255.254.254 autokey # manycast client + +# Enable public key cryptography. +#crypto + +includefile /etc/ntp/crypto/pw + +# Key file containing the keys and key identifiers used when operating +# with symmetric key cryptography. +keys /etc/ntp/keys + +# Specify the key identifiers which are trusted. +#trustedkey 4 8 42 + +# Specify the key identifier to use with the ntpdc utility. +#requestkey 8 + +# Specify the key identifier to use with the ntpq utility. +#controlkey 8 + +# Enable writing of statistics records. +#statistics clockstats cryptostats loopstats peerstats diff --git a/cloud/templates/ntp.conf.sles.tmpl b/cloud/templates/ntp.conf.sles.tmpl new file mode 100644 index 00000000..f3ab565f --- /dev/null +++ b/cloud/templates/ntp.conf.sles.tmpl @@ -0,0 +1,88 @@ +## template:jinja + +## +## Radio and modem clocks by convention have addresses in the +## form 127.127.t.u, where t is the clock type and u is a unit +## number in the range 0-3. +## +## Most of these clocks require support in the form of a +## serial port or special bus peripheral. The particular +## device is normally specified by adding a soft link +## /dev/device-u to the particular hardware device involved, +## where u correspond to the unit number above. +## +## Generic DCF77 clock on serial port (Conrad DCF77) +## Address: 127.127.8.u +## Serial Port: /dev/refclock-u +## +## (create soft link /dev/refclock-0 to the particular ttyS?) +## +# server 127.127.8.0 mode 5 prefer + +## +## Undisciplined Local Clock. This is a fake driver intended for backup +## and when no outside source of synchronized time is available. +## +# server 127.127.1.0 # local clock (LCL) +# fudge 127.127.1.0 stratum 10 # LCL is unsynchronized + +## +## Add external Servers using +## # rcntpd addserver +## The servers will only be added to the currently running instance, not +## to /etc/ntp.conf. +## +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Access control configuration; see /usr/share/doc/packages/ntp/html/accopt.html for +# details. The web page +# might also be helpful. +# +# Note that "restrict" applies to both servers and clients, so a configuration +# that might be intended to block requests from certain clients could also end +# up blocking replies from your own upstream servers. + +# By default, exchange time with everybody, but don't allow configuration. +restrict -4 default notrap nomodify nopeer noquery +restrict -6 default notrap nomodify nopeer noquery + +# Local users may interrogate the ntp server more closely. +restrict 127.0.0.1 +restrict ::1 + +# Clients from this (example!) subnet have unlimited access, but only if +# cryptographically authenticated. +#restrict 192.168.123.0 mask 255.255.255.0 notrust + +## +## Miscellaneous stuff +## + +driftfile /var/lib/ntp/drift/ntp.drift # path for drift file + +logfile /var/log/ntp # alternate log file +# logconfig =syncstatus + sysevents +# logconfig =all + +# statsdir /tmp/ # directory for statistics files +# filegen peerstats file peerstats type day enable +# filegen loopstats file loopstats type day enable +# filegen clockstats file clockstats type day enable + +# +# Authentication stuff +# +keys /etc/ntp.keys # path for keys file +trustedkey 1 # define trusted keys +requestkey 1 # key (7) for accessing server variables +controlkey 1 # key (6) for accessing server variables + diff --git a/cloud/templates/ntp.conf.ubuntu.tmpl b/cloud/templates/ntp.conf.ubuntu.tmpl new file mode 100644 index 00000000..862a4fbd --- /dev/null +++ b/cloud/templates/ntp.conf.ubuntu.tmpl @@ -0,0 +1,75 @@ +## template:jinja + +# /etc/ntp.conf, configuration for ntpd; see ntp.conf(5) for help + +driftfile /var/lib/ntp/ntp.drift + +# Enable this if you want statistics to be logged. +#statsdir /var/log/ntpstats/ + +statistics loopstats peerstats clockstats +filegen loopstats file loopstats type day enable +filegen peerstats file peerstats type day enable +filegen clockstats file clockstats type day enable + +# Specify one or more NTP servers. + +# Use servers from the NTP Pool Project. Approved by Ubuntu Technical Board +# on 2011-02-08 (LP: #104525). See http://www.pool.ntp.org/join.html for +# more information. +{% if pools %}# pools +{% endif %} +{% for pool in pools -%} +pool {{pool}} iburst +{% endfor %} +{%- if servers %}# servers +{% endif %} +{% for server in servers -%} +server {{server}} iburst +{% endfor %} + +# Use Ubuntu's ntp server as a fallback. +# pool ntp.ubuntu.com + +# Access control configuration; see /usr/share/doc/ntp-doc/html/accopt.html for +# details. The web page +# might also be helpful. +# +# Note that "restrict" applies to both servers and clients, so a configuration +# that might be intended to block requests from certain clients could also end +# up blocking replies from your own upstream servers. + +# By default, exchange time with everybody, but don't allow configuration. +restrict -4 default kod notrap nomodify nopeer noquery limited +restrict -6 default kod notrap nomodify nopeer noquery limited + +# Local users may interrogate the ntp server more closely. +restrict 127.0.0.1 +restrict ::1 + +# Needed for adding pool entries +restrict source notrap nomodify noquery + +# Clients from this (example!) subnet have unlimited access, but only if +# cryptographically authenticated. +#restrict 192.168.123.0 mask 255.255.255.0 notrust + + +# If you want to provide time to your local subnet, change the next line. +# (Again, the address is an example only.) +#broadcast 192.168.123.255 + +# If you want to listen to time broadcasts on your local subnet, de-comment the +# next lines. Please do this only if you trust everybody on the network! +#disable auth +#broadcastclient + +#Changes recquired to use pps synchonisation as explained in documentation: +#http://www.ntp.org/ntpfaq/NTP-s-config-adv.htm#AEN3918 + +#server 127.127.8.1 mode 135 prefer # Meinberg GPS167 with PPS +#fudge 127.127.8.1 time1 0.0042 # relative to PPS for my hardware + +#server 127.127.22.1 # ATOM(PPS) +#fudge 127.127.22.1 flag3 1 # enable PPS API + diff --git a/cloud/templates/resolv.conf.tmpl b/cloud/templates/resolv.conf.tmpl new file mode 100644 index 00000000..f870be67 --- /dev/null +++ b/cloud/templates/resolv.conf.tmpl @@ -0,0 +1,38 @@ +## template:jinja +# Your system has been configured with 'manage-resolv-conf' set to true. +# As a result, cloud-init has written this file with configuration data +# that it has been provided. Cloud-init, by default, will write this file +# a single time (PER_ONCE). +# +{% if nameservers is defined %} +{% for server in nameservers %} +nameserver {{server}} +{% endfor %} + +{% endif -%} +{% if searchdomains is defined %} +search {% for search in searchdomains %}{{search}} {% endfor %} + +{% endif %} +{% if domain is defined %} +domain {{domain}} +{% endif %} +{% if sortlist is defined %} + +sortlist {% for sort in sortlist %}{{sort}} {% endfor %} +{% endif %} +{# + Flags and options are required to be on the + same line preceded by "options" keyword +#} +{% if options or flags %} + +options +{%- for flag in flags %} + {{flag-}} +{% endfor %} + +{%- for key, value in options.items()|sort %} + {{key}}:{{value-}} +{% endfor %} +{% endif %} diff --git a/cloud/templates/sources.list.debian.tmpl b/cloud/templates/sources.list.debian.tmpl new file mode 100644 index 00000000..e7ef9ed1 --- /dev/null +++ b/cloud/templates/sources.list.debian.tmpl @@ -0,0 +1,30 @@ +## template:jinja +## Note, this file is written by cloud-init on first boot of an instance +## modifications made here will not survive a re-bundle. +## if you wish to make changes you can: +## a.) add 'apt_preserve_sources_list: true' to /etc/cloud/cloud.cfg +## or do the same in user-data +## b.) add sources in /etc/apt/sources.list.d +## c.) make changes to template file /etc/cloud/templates/sources.list.debian.tmpl +### + +# See http://www.debian.org/releases/stable/i386/release-notes/ch-upgrading.html +# for how to upgrade to newer versions of the distribution. +deb {{mirror}} {{codename}} main +deb-src {{mirror}} {{codename}} main + +## Major bug fix updates produced after the final release of the +## distribution. +deb {{security}} {{codename}}/updates main +deb-src {{security}} {{codename}}/updates main +deb {{mirror}} {{codename}}-updates main +deb-src {{mirror}} {{codename}}-updates main + +## Uncomment the following two lines to add software from the 'backports' +## repository. +## +## N.B. software from this repository may not have been tested as +## extensively as that contained in the main release, although it includes +## newer versions of some applications which may provide useful features. +deb {{mirror}} {{codename}}-backports main +deb-src {{mirror}} {{codename}}-backports main diff --git a/cloud/templates/sources.list.ubuntu.tmpl b/cloud/templates/sources.list.ubuntu.tmpl new file mode 100644 index 00000000..edb92f13 --- /dev/null +++ b/cloud/templates/sources.list.ubuntu.tmpl @@ -0,0 +1,58 @@ +## template:jinja +## Note, this file is written by cloud-init on first boot of an instance +## modifications made here will not survive a re-bundle. +## if you wish to make changes you can: +## a.) add 'apt_preserve_sources_list: true' to /etc/cloud/cloud.cfg +## or do the same in user-data +## b.) add sources in /etc/apt/sources.list.d +## c.) make changes to template file /etc/cloud/templates/sources.list.tmpl + +# See http://help.ubuntu.com/community/UpgradeNotes for how to upgrade to +# newer versions of the distribution. +deb {{mirror}} {{codename}} main restricted +# deb-src {{mirror}} {{codename}} main restricted + +## Major bug fix updates produced after the final release of the +## distribution. +deb {{mirror}} {{codename}}-updates main restricted +# deb-src {{mirror}} {{codename}}-updates main restricted + +## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu +## team. Also, please note that software in universe WILL NOT receive any +## review or updates from the Ubuntu security team. +deb {{mirror}} {{codename}} universe +# deb-src {{mirror}} {{codename}} universe +deb {{mirror}} {{codename}}-updates universe +# deb-src {{mirror}} {{codename}}-updates universe + +## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu +## team, and may not be under a free licence. Please satisfy yourself as to +## your rights to use the software. Also, please note that software in +## multiverse WILL NOT receive any review or updates from the Ubuntu +## security team. +deb {{mirror}} {{codename}} multiverse +# deb-src {{mirror}} {{codename}} multiverse +deb {{mirror}} {{codename}}-updates multiverse +# deb-src {{mirror}} {{codename}}-updates multiverse + +## N.B. software from this repository may not have been tested as +## extensively as that contained in the main release, although it includes +## newer versions of some applications which may provide useful features. +## Also, please note that software in backports WILL NOT receive any review +## or updates from the Ubuntu security team. +deb {{mirror}} {{codename}}-backports main restricted universe multiverse +# deb-src {{mirror}} {{codename}}-backports main restricted universe multiverse + +## Uncomment the following two lines to add software from Canonical's +## 'partner' repository. +## This software is not part of Ubuntu, but is offered by Canonical and the +## respective vendors as a service to Ubuntu users. +# deb http://archive.canonical.com/ubuntu {{codename}} partner +# deb-src http://archive.canonical.com/ubuntu {{codename}} partner + +deb {{security}} {{codename}}-security main restricted +# deb-src {{security}} {{codename}}-security main restricted +deb {{security}} {{codename}}-security universe +# deb-src {{security}} {{codename}}-security universe +deb {{security}} {{codename}}-security multiverse +# deb-src {{security}} {{codename}}-security multiverse diff --git a/cloud/templates/timesyncd.conf.tmpl b/cloud/templates/timesyncd.conf.tmpl new file mode 100644 index 00000000..6b98301d --- /dev/null +++ b/cloud/templates/timesyncd.conf.tmpl @@ -0,0 +1,8 @@ +## template:jinja +# cloud-init generated file +# See timesyncd.conf(5) for details. + +[Time] +{% if servers or pools -%} +NTP={% for host in servers|list + pools|list %}{{ host }} {% endfor -%} +{% endif -%} diff --git a/console-setup/cached_Lat15-Fixed16.psf.gz b/console-setup/cached_Lat15-Fixed16.psf.gz new file mode 100644 index 00000000..8d002b7c Binary files /dev/null and b/console-setup/cached_Lat15-Fixed16.psf.gz differ diff --git a/console-setup/cached_Lat15-VGA16.psf.gz b/console-setup/cached_Lat15-VGA16.psf.gz new file mode 100644 index 00000000..c643688d Binary files /dev/null and b/console-setup/cached_Lat15-VGA16.psf.gz differ diff --git a/console-setup/cached_UTF-8_del.kmap.gz b/console-setup/cached_UTF-8_del.kmap.gz new file mode 100644 index 00000000..806a6f69 Binary files /dev/null and b/console-setup/cached_UTF-8_del.kmap.gz differ diff --git a/console-setup/cached_setup_font.sh b/console-setup/cached_setup_font.sh new file mode 100755 index 00000000..ad5d1eec --- /dev/null +++ b/console-setup/cached_setup_font.sh @@ -0,0 +1,19 @@ +#!/bin/sh + +setfont '/usr/share/consolefonts/Lat15-VGA16.psf.gz' + +if ls /dev/fb* >/dev/null 2>/dev/null; then + for i in /dev/vcs[0-9]*; do + { : + setfont '/usr/share/consolefonts/Lat15-VGA16.psf.gz' + } < /dev/tty${i#/dev/vcs} > /dev/tty${i#/dev/vcs} + done +fi + +mkdir -p /run/console-setup +> /run/console-setup/font-loaded +for i in /dev/vcs[0-9]*; do + { : +printf '\033%%G' + } < /dev/tty${i#/dev/vcs} > /dev/tty${i#/dev/vcs} +done diff --git a/console-setup/cached_setup_keyboard.sh b/console-setup/cached_setup_keyboard.sh new file mode 100755 index 00000000..30b46c1b --- /dev/null +++ b/console-setup/cached_setup_keyboard.sh @@ -0,0 +1,13 @@ +#!/bin/sh + +if [ -f /run/console-setup/keymap_loaded ]; then + rm /run/console-setup/keymap_loaded + exit 0 +fi +kbd_mode '-u' < '/dev/tty1' +kbd_mode '-u' < '/dev/tty2' +kbd_mode '-u' < '/dev/tty3' +kbd_mode '-u' < '/dev/tty4' +kbd_mode '-u' < '/dev/tty5' +kbd_mode '-u' < '/dev/tty6' +loadkeys '/etc/console-setup/cached_UTF-8_del.kmap.gz' > '/dev/null' diff --git a/console-setup/cached_setup_terminal.sh b/console-setup/cached_setup_terminal.sh new file mode 100755 index 00000000..494e3638 --- /dev/null +++ b/console-setup/cached_setup_terminal.sh @@ -0,0 +1,5 @@ +#!/bin/sh + +{ : +printf '\033%%G' +} < /dev/tty${1#vcs} > /dev/tty${1#vcs} diff --git a/console-setup/compose.ARMSCII-8.inc b/console-setup/compose.ARMSCII-8.inc new file mode 100644 index 00000000..ca8d3c91 --- /dev/null +++ b/console-setup/compose.ARMSCII-8.inc @@ -0,0 +1 @@ +# Compose sequences for ARMSCII-8 diff --git a/console-setup/compose.CP1251.inc b/console-setup/compose.CP1251.inc new file mode 100644 index 00000000..4fb90dac --- /dev/null +++ b/console-setup/compose.CP1251.inc @@ -0,0 +1 @@ +# Compose sequences for CP1251 diff --git a/console-setup/compose.CP1255.inc b/console-setup/compose.CP1255.inc new file mode 100644 index 00000000..93e6a7b3 --- /dev/null +++ b/console-setup/compose.CP1255.inc @@ -0,0 +1 @@ +# Compose sequences for CP1255 diff --git a/console-setup/compose.CP1256.inc b/console-setup/compose.CP1256.inc new file mode 100644 index 00000000..a792b8ca --- /dev/null +++ b/console-setup/compose.CP1256.inc @@ -0,0 +1 @@ +# Compose sequences for CP1256 diff --git a/console-setup/compose.GEORGIAN-ACADEMY.inc b/console-setup/compose.GEORGIAN-ACADEMY.inc new file mode 100644 index 00000000..33869fd3 --- /dev/null +++ b/console-setup/compose.GEORGIAN-ACADEMY.inc @@ -0,0 +1 @@ +# Compose sequences for GEORGIAN-ACADEMY diff --git a/console-setup/compose.GEORGIAN-PS.inc b/console-setup/compose.GEORGIAN-PS.inc new file mode 100644 index 00000000..a4d20c47 --- /dev/null +++ b/console-setup/compose.GEORGIAN-PS.inc @@ -0,0 +1 @@ +# Compose sequences for GEORGIAN-PS diff --git a/console-setup/compose.IBM1133.inc b/console-setup/compose.IBM1133.inc new file mode 100644 index 00000000..93696454 --- /dev/null +++ b/console-setup/compose.IBM1133.inc @@ -0,0 +1 @@ +# Compose sequences for IBM1133 diff --git a/console-setup/compose.ISIRI-3342.inc b/console-setup/compose.ISIRI-3342.inc new file mode 100644 index 00000000..242f739b --- /dev/null +++ b/console-setup/compose.ISIRI-3342.inc @@ -0,0 +1 @@ +# Compose sequences for ISIRI-3342 diff --git a/console-setup/compose.ISO-8859-1.inc b/console-setup/compose.ISO-8859-1.inc new file mode 100644 index 00000000..a285ddfc --- /dev/null +++ b/console-setup/compose.ISO-8859-1.inc @@ -0,0 +1,155 @@ +# Compose sequences for ISO-8859-1 +compose '!' '!' to '' +compose '!' '^' to '' +compose '!' 'p' to '' +compose '!' 's' to '' +compose '"' '"' to '' +compose '"' 'A' to '' +compose '"' 'E' to '' +compose '"' 'I' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'a' to '' +compose '"' 'e' to '' +compose '"' 'i' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '"' 'y' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose '(' 'c' to '' +compose '(' 'r' to '' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' '0' to '' +compose '*' 'A' to '' +compose '*' 'a' to '' +compose '+' '+' to '#' +compose '+' '-' to '' +compose ',' ',' to '' +compose ',' '-' to '' +compose ',' 'C' to '' +compose ',' 'c' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '+' to '' +compose '-' ',' to '' +compose '-' '-' to '' +compose '-' ':' to '' +compose '-' 'A' to '' +compose '-' 'D' to '' +compose '-' 'N' to '' +compose '-' 'O' to '' +compose '-' '^' to '' +compose '-' 'a' to '' +compose '-' 'd' to '' +compose '-' 'l' to '' +compose '-' 'n' to '' +compose '-' 'o' to '' +compose '-' 'y' to '' +compose '.' '.' to '' +compose '.' '^' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' 'O' to '' +compose '/' '^' to '|' +compose '/' 'c' to '' +compose '/' 'o' to '' +compose '/' 'u' to '' +compose '1' '2' to '' +compose '1' '4' to '' +compose '3' '4' to '' +compose ':' '-' to '' +compose '<' '/' to '\\' +compose '<' '<' to '' +compose '=' 'l' to '' +compose '=' 'y' to '' +compose '>' '>' to '' +compose '>' 'A' to '' +compose '>' 'E' to '' +compose '>' 'I' to '' +compose '>' 'O' to '' +compose '>' 'U' to '' +compose '>' 'a' to '' +compose '>' 'e' to '' +compose '>' 'i' to '' +compose '>' 'o' to '' +compose '>' 'u' to '' +compose '?' '?' to '' +compose 'A' 'E' to '' +compose 'A' 'O' to '' +compose 'T' 'H' to '' +compose '\'' 'A' to '' +compose '\'' 'C' to '' +compose '\'' 'E' to '' +compose '\'' 'I' to '' +compose '\'' 'O' to '' +compose '\'' 'U' to '' +compose '\'' 'Y' to '' +compose '\'' '\'' to '' +compose '\'' 'a' to '' +compose '\'' 'c' to '' +compose '\'' 'e' to '' +compose '\'' 'i' to '' +compose '\'' 'o' to '' +compose '\'' 'u' to '' +compose '\'' 'y' to '' +compose '^' '!' to '' +compose '^' '-' to '' +compose '^' '.' to '' +compose '^' '/' to '|' +compose '^' '0' to '' +compose '^' '1' to '' +compose '^' '2' to '' +compose '^' '3' to '' +compose '^' 'A' to '' +compose '^' 'E' to '' +compose '^' 'I' to '' +compose '^' 'O' to '' +compose '^' 'U' to '' +compose '^' '_' to '' +compose '^' 'a' to '' +compose '^' 'e' to '' +compose '^' 'i' to '' +compose '^' 'o' to '' +compose '^' 'u' to '' +compose '_' '^' to '' +compose '_' '_' to '' +compose '_' 'a' to '' +compose '_' 'o' to '' +compose '`' 'A' to '' +compose '`' 'E' to '' +compose '`' 'I' to '' +compose '`' 'O' to '' +compose '`' 'U' to '' +compose '`' 'a' to '' +compose '`' 'e' to '' +compose '`' 'i' to '' +compose '`' 'o' to '' +compose '`' 'u' to '' +compose 'a' 'e' to '' +compose 'a' 'o' to '' +compose 'a' 't' to '@' +compose 'c' '0' to '' +compose 'c' 'o' to '' +compose 'o' 'c' to '' +compose 'o' 'x' to '' +compose 'r' 'o' to '' +compose 's' '0' to '' +compose 's' '1' to '' +compose 's' '2' to '' +compose 's' '3' to '' +compose 's' 'o' to '' +compose 't' 'h' to '' +compose 'v' 'b' to '' +compose 'v' 'l' to '|' +compose 'x' '0' to '' +compose 'x' 'o' to '' +compose '|' 'c' to '' +compose '|' '|' to '' +compose '~' 'A' to '' +compose '~' 'N' to '' +compose '~' 'O' to '' +compose '~' 'a' to '' +compose '~' 'n' to '' +compose '~' 'o' to '' diff --git a/console-setup/compose.ISO-8859-10.inc b/console-setup/compose.ISO-8859-10.inc new file mode 100644 index 00000000..7ca7b107 --- /dev/null +++ b/console-setup/compose.ISO-8859-10.inc @@ -0,0 +1 @@ +# Compose sequences for ISO-8859-10 diff --git a/console-setup/compose.ISO-8859-11.inc b/console-setup/compose.ISO-8859-11.inc new file mode 100644 index 00000000..add3f6ad --- /dev/null +++ b/console-setup/compose.ISO-8859-11.inc @@ -0,0 +1 @@ +# Compose sequences for ISO-8859-11 diff --git a/console-setup/compose.ISO-8859-13.inc b/console-setup/compose.ISO-8859-13.inc new file mode 100644 index 00000000..5b45a261 --- /dev/null +++ b/console-setup/compose.ISO-8859-13.inc @@ -0,0 +1,161 @@ +# Compose sequences for ISO-8859-13 +compose '!' '^' to '' +compose '!' 'p' to '' +compose '!' 's' to '' +compose '"' '<' to '' +compose '"' '>' to '' +compose '"' 'A' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'a' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose '(' 'c' to '' +compose '(' 'r' to '' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' '0' to '' +compose '*' 'A' to '' +compose '*' 'a' to '' +compose '+' '+' to '#' +compose '+' '-' to '' +compose ',' '-' to '' +compose ',' '>' to '' +compose ',' 'A' to '' +compose ',' 'E' to '' +compose ',' 'G' to '' +compose ',' 'I' to '' +compose ',' 'K' to '' +compose ',' 'L' to '' +compose ',' 'N' to '' +compose ',' 'R' to '' +compose ',' 'U' to '' +compose ',' 'a' to '' +compose ',' 'e' to '' +compose ',' 'g' to '' +compose ',' 'i' to '' +compose ',' 'k' to '' +compose ',' 'l' to '' +compose ',' 'n' to '' +compose ',' 'r' to '' +compose ',' 'u' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '+' to '' +compose '-' ',' to '' +compose '-' '-' to '' +compose '-' ':' to '' +compose '-' 'A' to '' +compose '-' 'E' to '' +compose '-' 'I' to '' +compose '-' 'L' to '' +compose '-' 'O' to '' +compose '-' 'U' to '' +compose '-' 'a' to '' +compose '-' 'e' to '' +compose '-' 'i' to '' +compose '-' 'l' to '' +compose '-' 'o' to '' +compose '-' 'u' to '' +compose '.' '.' to '' +compose '.' 'A' to '' +compose '.' 'E' to '' +compose '.' 'Z' to '' +compose '.' '^' to '' +compose '.' 'a' to '' +compose '.' 'e' to '' +compose '.' 'z' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' 'L' to '' +compose '/' 'O' to '' +compose '/' '^' to '|' +compose '/' 'c' to '' +compose '/' 'l' to '' +compose '/' 'o' to '' +compose '/' 'u' to '' +compose '1' '2' to '' +compose '1' '4' to '' +compose '3' '4' to '' +compose ':' '-' to '' +compose ';' 'A' to '' +compose ';' 'E' to '' +compose ';' 'I' to '' +compose ';' 'U' to '' +compose ';' 'a' to '' +compose ';' 'e' to '' +compose ';' 'i' to '' +compose ';' 'u' to '' +compose '<' '"' to '' +compose '<' '/' to '\\' +compose '<' '<' to '' +compose '<' 'C' to '' +compose '<' 'S' to '' +compose '<' 'Z' to '' +compose '<' '\'' to '`' +compose '<' 'c' to '' +compose '<' 's' to '' +compose '<' 'z' to '' +compose '=' 'l' to '' +compose '>' '"' to '' +compose '>' ',' to '' +compose '>' '>' to '' +compose '>' '\'' to '' +compose '?' '?' to '' +compose 'A' 'E' to '' +compose 'A' 'O' to '' +compose '\'' '<' to '`' +compose '\'' '>' to '' +compose '\'' 'C' to '' +compose '\'' 'E' to '' +compose '\'' 'N' to '' +compose '\'' 'O' to '' +compose '\'' 'S' to '' +compose '\'' 'Z' to '' +compose '\'' '\'' to '' +compose '\'' 'c' to '' +compose '\'' 'e' to '' +compose '\'' 'n' to '' +compose '\'' 'o' to '' +compose '\'' 's' to '' +compose '\'' 'z' to '' +compose '^' '!' to '' +compose '^' '.' to '' +compose '^' '/' to '|' +compose '^' '0' to '' +compose '^' '1' to '' +compose '^' '2' to '' +compose '^' '3' to '' +compose '_' 'A' to '' +compose '_' 'E' to '' +compose '_' 'I' to '' +compose '_' 'O' to '' +compose '_' 'U' to '' +compose '_' 'a' to '' +compose '_' 'e' to '' +compose '_' 'i' to '' +compose '_' 'o' to '' +compose '_' 'u' to '' +compose 'a' 'e' to '' +compose 'a' 'o' to '' +compose 'a' 't' to '@' +compose 'c' '0' to '' +compose 'c' 'o' to '' +compose 'm' 'u' to '' +compose 'o' 'c' to '' +compose 'o' 'x' to '' +compose 'r' 'o' to '' +compose 's' '0' to '' +compose 's' '1' to '' +compose 's' '2' to '' +compose 's' '3' to '' +compose 's' 'o' to '' +compose 'v' 'b' to '' +compose 'x' '0' to '' +compose 'x' 'o' to '' +compose '|' 'c' to '' +compose '|' '|' to '' +compose '~' 'O' to '' +compose '~' 'o' to '' diff --git a/console-setup/compose.ISO-8859-14.inc b/console-setup/compose.ISO-8859-14.inc new file mode 100644 index 00000000..e2835df6 --- /dev/null +++ b/console-setup/compose.ISO-8859-14.inc @@ -0,0 +1,130 @@ +# Compose sequences for ISO-8859-14 +compose '!' 'p' to '' +compose '!' 's' to '' +compose '"' 'A' to '' +compose '"' 'E' to '' +compose '"' 'I' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'W' to '' +compose '"' 'Y' to '' +compose '"' 'a' to '' +compose '"' 'e' to '' +compose '"' 'i' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '"' 'w' to '' +compose '"' 'y' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' 'A' to '' +compose '*' 'a' to '' +compose '+' '+' to '#' +compose ',' 'C' to '' +compose ',' 'c' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '-' to '' +compose '-' 'A' to '' +compose '-' 'N' to '' +compose '-' 'O' to '' +compose '-' 'a' to '' +compose '-' 'l' to '' +compose '-' 'n' to '' +compose '-' 'o' to '' +compose '.' 'B' to '' +compose '.' 'D' to '' +compose '.' 'F' to '' +compose '.' 'G' to '' +compose '.' 'M' to '' +compose '.' 'P' to '' +compose '.' 'S' to '' +compose '.' 'T' to '' +compose '.' 'b' to '' +compose '.' 'c' to '' +compose '.' 'd' to '' +compose '.' 'f' to '' +compose '.' 'g' to '' +compose '.' 'm' to '' +compose '.' 'p' to '' +compose '.' 's' to '' +compose '.' 't' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' 'O' to '' +compose '/' '^' to '|' +compose '/' 'o' to '' +compose '<' '/' to '\\' +compose '=' 'l' to '' +compose '>' 'A' to '' +compose '>' 'E' to '' +compose '>' 'I' to '' +compose '>' 'O' to '' +compose '>' 'U' to '' +compose '>' 'a' to '' +compose '>' 'e' to '' +compose '>' 'i' to '' +compose '>' 'o' to '' +compose '>' 'u' to '' +compose 'A' 'E' to '' +compose '\'' 'A' to '' +compose '\'' 'E' to '' +compose '\'' 'I' to '' +compose '\'' 'O' to '' +compose '\'' 'U' to '' +compose '\'' 'W' to '' +compose '\'' 'Y' to '' +compose '\'' 'a' to '' +compose '\'' 'e' to '' +compose '\'' 'i' to '' +compose '\'' 'o' to '' +compose '\'' 'u' to '' +compose '\'' 'w' to '' +compose '\'' 'y' to '' +compose '^' '/' to '|' +compose '^' 'A' to '' +compose '^' 'E' to '' +compose '^' 'I' to '' +compose '^' 'O' to '' +compose '^' 'U' to '' +compose '^' 'W' to '' +compose '^' 'Y' to '' +compose '^' 'a' to '' +compose '^' 'e' to '' +compose '^' 'i' to '' +compose '^' 'o' to '' +compose '^' 'u' to '' +compose '^' 'w' to '' +compose '^' 'y' to '' +compose '`' 'A' to '' +compose '`' 'E' to '' +compose '`' 'I' to '' +compose '`' 'O' to '' +compose '`' 'U' to '' +compose '`' 'W' to '' +compose '`' 'Y' to '' +compose '`' 'a' to '' +compose '`' 'e' to '' +compose '`' 'i' to '' +compose '`' 'o' to '' +compose '`' 'u' to '' +compose '`' 'w' to '' +compose '`' 'y' to '' +compose 'a' 'e' to '' +compose 'a' 't' to '@' +compose 'c' '0' to '' +compose 'c' 'o' to '' +compose 'o' 'c' to '' +compose 'r' '0' to '' +compose 'r' 'o' to '' +compose 's' '0' to '' +compose 's' 'o' to '' +compose 'v' 'l' to '|' +compose '~' 'A' to '' +compose '~' 'N' to '' +compose '~' 'O' to '' +compose '~' 'a' to '' +compose '~' 'n' to '' +compose '~' 'o' to '' diff --git a/console-setup/compose.ISO-8859-15.inc b/console-setup/compose.ISO-8859-15.inc new file mode 100644 index 00000000..79c92ed8 --- /dev/null +++ b/console-setup/compose.ISO-8859-15.inc @@ -0,0 +1,153 @@ +# Compose sequences for ISO-8859-15 +compose '!' '!' to '' +compose '!' 'p' to '' +compose '!' 's' to '' +compose '"' '"' to '"' +compose '"' 'A' to '' +compose '"' 'E' to '' +compose '"' 'I' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'Y' to '' +compose '"' 'a' to '' +compose '"' 'e' to '' +compose '"' 'i' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '"' 'y' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose '(' 'c' to '' +compose '(' 'r' to '' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' '0' to '' +compose '*' 'A' to '' +compose '*' 'a' to '' +compose '+' '+' to '#' +compose '+' '-' to '' +compose ',' '-' to '' +compose ',' 'C' to '' +compose ',' 'c' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '+' to '' +compose '-' ',' to '' +compose '-' '-' to '' +compose '-' ':' to '' +compose '-' 'A' to '' +compose '-' 'D' to '' +compose '-' 'N' to '' +compose '-' 'O' to '' +compose '-' '^' to '' +compose '-' 'a' to '' +compose '-' 'd' to '' +compose '-' 'l' to '' +compose '-' 'n' to '' +compose '-' 'o' to '' +compose '-' 'y' to '' +compose '.' '.' to '' +compose '.' '^' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' 'O' to '' +compose '/' '^' to '|' +compose '/' 'c' to '' +compose '/' 'o' to '' +compose '/' 'u' to '' +compose ':' '-' to '' +compose '<' '/' to '\\' +compose '<' '<' to '' +compose '<' 'S' to '' +compose '<' 'Z' to '' +compose '<' 's' to '' +compose '<' 'z' to '' +compose '=' 'c' to '' +compose '=' 'l' to '' +compose '=' 'y' to '' +compose '>' '>' to '' +compose '>' 'A' to '' +compose '>' 'E' to '' +compose '>' 'I' to '' +compose '>' 'O' to '' +compose '>' 'U' to '' +compose '>' 'a' to '' +compose '>' 'e' to '' +compose '>' 'i' to '' +compose '>' 'o' to '' +compose '>' 'u' to '' +compose '?' '?' to '' +compose 'A' 'E' to '' +compose 'A' 'O' to '' +compose 'O' 'E' to '' +compose 'T' 'H' to '' +compose '\'' 'A' to '' +compose '\'' 'C' to '' +compose '\'' 'E' to '' +compose '\'' 'I' to '' +compose '\'' 'O' to '' +compose '\'' 'U' to '' +compose '\'' 'Y' to '' +compose '\'' '\'' to '\'' +compose '\'' 'a' to '' +compose '\'' 'c' to '' +compose '\'' 'e' to '' +compose '\'' 'i' to '' +compose '\'' 'o' to '' +compose '\'' 'u' to '' +compose '\'' 'y' to '' +compose '^' '-' to '' +compose '^' '.' to '' +compose '^' '/' to '|' +compose '^' '0' to '' +compose '^' '1' to '' +compose '^' '2' to '' +compose '^' '3' to '' +compose '^' 'A' to '' +compose '^' 'E' to '' +compose '^' 'I' to '' +compose '^' 'O' to '' +compose '^' 'U' to '' +compose '^' '_' to '' +compose '^' 'a' to '' +compose '^' 'e' to '' +compose '^' 'i' to '' +compose '^' 'o' to '' +compose '^' 'u' to '' +compose '_' '^' to '' +compose '_' '_' to '' +compose '_' 'a' to '' +compose '_' 'o' to '' +compose '`' 'A' to '' +compose '`' 'E' to '' +compose '`' 'I' to '' +compose '`' 'O' to '' +compose '`' 'U' to '' +compose '`' 'a' to '' +compose '`' 'e' to '' +compose '`' 'i' to '' +compose '`' 'o' to '' +compose '`' 'u' to '' +compose 'a' 'e' to '' +compose 'a' 'o' to '' +compose 'a' 't' to '@' +compose 'c' '0' to '' +compose 'c' 'o' to '' +compose 'e' '=' to '' +compose 'o' 'c' to '' +compose 'o' 'e' to '' +compose 'r' 'o' to '' +compose 's' '0' to '' +compose 's' '1' to '' +compose 's' '2' to '' +compose 's' '3' to '' +compose 's' 'o' to '' +compose 't' 'h' to '' +compose 'v' 'l' to '|' +compose '|' 'c' to '' +compose '~' 'A' to '' +compose '~' 'N' to '' +compose '~' 'O' to '' +compose '~' 'a' to '' +compose '~' 'n' to '' +compose '~' 'o' to '' diff --git a/console-setup/compose.ISO-8859-16.inc b/console-setup/compose.ISO-8859-16.inc new file mode 100644 index 00000000..96c38aea --- /dev/null +++ b/console-setup/compose.ISO-8859-16.inc @@ -0,0 +1 @@ +# Compose sequences for ISO-8859-16 diff --git a/console-setup/compose.ISO-8859-2.inc b/console-setup/compose.ISO-8859-2.inc new file mode 100644 index 00000000..6692ee34 --- /dev/null +++ b/console-setup/compose.ISO-8859-2.inc @@ -0,0 +1,124 @@ +# Compose sequences for ISO-8859-2 +compose '!' 'p' to '' +compose '!' 's' to '' +compose '"' '"' to '' +compose '"' 'A' to '' +compose '"' 'E' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'a' to '' +compose '"' 'e' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' '0' to '' +compose '*' 'U' to '' +compose '*' 'u' to '' +compose '+' '+' to '#' +compose ',' ',' to '' +compose ',' 'A' to '' +compose ',' 'C' to '' +compose ',' 'E' to '' +compose ',' 'S' to '' +compose ',' 'T' to '' +compose ',' 'a' to '' +compose ',' 'c' to '' +compose ',' 'e' to '' +compose ',' 's' to '' +compose ',' 't' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '-' to '' +compose '-' ':' to '' +compose '-' 'D' to '' +compose '-' 'd' to '' +compose '.' '.' to '' +compose '.' 'C' to '' +compose '.' 'E' to '' +compose '.' 'I' to '' +compose '.' 'U' to '' +compose '.' 'Z' to '' +compose '.' 'c' to '' +compose '.' 'e' to '' +compose '.' 'i' to '' +compose '.' 'u' to '' +compose '.' 'z' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' '^' to '|' +compose ':' '-' to '' +compose '<' '/' to '\\' +compose '<' '<' to '' +compose '<' 'C' to '' +compose '<' 'D' to '' +compose '<' 'E' to '' +compose '<' 'L' to '' +compose '<' 'N' to '' +compose '<' 'R' to '' +compose '<' 'S' to '' +compose '<' 'T' to '' +compose '<' 'Z' to '' +compose '<' 'c' to '' +compose '<' 'd' to '' +compose '<' 'e' to '' +compose '<' 'l' to '' +compose '<' 'n' to '' +compose '<' 'r' to '' +compose '<' 's' to '' +compose '<' 't' to '' +compose '<' 'z' to '' +compose '>' 'A' to '' +compose '>' 'I' to '' +compose '>' 'O' to '' +compose '>' 'a' to '' +compose '>' 'i' to '' +compose '>' 'o' to '' +compose 'A' 'U' to '' +compose 'L' '-' to '' +compose 'O' 'E' to '' +compose 'Z' '.' to '' +compose '\'' 'A' to '' +compose '\'' 'C' to '' +compose '\'' 'E' to '' +compose '\'' 'I' to '' +compose '\'' 'L' to '' +compose '\'' 'N' to '' +compose '\'' 'O' to '' +compose '\'' 'R' to '' +compose '\'' 'S' to '' +compose '\'' 'U' to '' +compose '\'' 'Y' to '' +compose '\'' 'Z' to '' +compose '\'' '\'' to '' +compose '\'' 'a' to '' +compose '\'' 'c' to '' +compose '\'' 'e' to '' +compose '\'' 'i' to '' +compose '\'' 'l' to '' +compose '\'' 'n' to '' +compose '\'' 'o' to '' +compose '\'' 'r' to '' +compose '\'' 's' to '' +compose '\'' 'u' to '' +compose '\'' 'y' to '' +compose '\'' 'z' to '' +compose '^' '/' to '|' +compose '^' 'A' to '' +compose '^' 'I' to '' +compose '^' 'O' to '' +compose '^' 'a' to '' +compose '^' 'i' to '' +compose '^' 'o' to '' +compose 'a' 'U' to '' +compose 'l' '-' to '' +compose 'o' 'e' to '' +compose 'o' 'x' to '' +compose 's' '0' to '' +compose 's' 'o' to '' +compose 'v' 'l' to '|' +compose 'x' '0' to '' +compose 'x' 'o' to '' +compose 'z' '.' to '' diff --git a/console-setup/compose.ISO-8859-3.inc b/console-setup/compose.ISO-8859-3.inc new file mode 100644 index 00000000..7e50b6c5 --- /dev/null +++ b/console-setup/compose.ISO-8859-3.inc @@ -0,0 +1,146 @@ +# Compose sequences for ISO-8859-3 +compose '!' 's' to '' +compose '"' '"' to '' +compose '"' 'A' to '' +compose '"' 'E' to '' +compose '"' 'I' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'Y' to '' +compose '"' 'a' to '' +compose '"' 'e' to '' +compose '"' 'i' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '"' 'y' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose '(' 'G' to '' +compose '(' 'U' to '' +compose '(' 'g' to '' +compose '(' 'r' to '' +compose '(' 'u' to '' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' '0' to '' +compose '+' '+' to '#' +compose ',' ',' to '' +compose ',' 'C' to '' +compose ',' 'S' to '' +compose ',' 'c' to '' +compose ',' 's' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '-' to '' +compose '-' ':' to '' +compose '-' 'A' to '' +compose '-' 'D' to '' +compose '-' 'H' to '' +compose '-' 'O' to '' +compose '-' 'a' to '' +compose '-' 'd' to '' +compose '-' 'h' to '' +compose '-' 'l' to '' +compose '-' 'o' to '' +compose '-' 'y' to '' +compose '.' '.' to '' +compose '.' 'C' to '' +compose '.' 'G' to '' +compose '.' 'I' to '' +compose '.' 'Z' to '' +compose '.' '^' to '' +compose '.' 'c' to '' +compose '.' 'g' to '' +compose '.' 'i' to '' +compose '.' 'z' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' '^' to '|' +compose '/' 'u' to '' +compose ':' '-' to '' +compose '<' '/' to '\\' +compose '=' 'c' to '' +compose '=' 'e' to '' +compose '=' 'l' to '' +compose '=' 'y' to '' +compose '>' 'A' to '' +compose '>' 'C' to '' +compose '>' 'E' to '' +compose '>' 'G' to '' +compose '>' 'H' to '' +compose '>' 'I' to '' +compose '>' 'J' to '' +compose '>' 'O' to '' +compose '>' 'S' to '' +compose '>' 'U' to '' +compose '>' 'a' to '' +compose '>' 'c' to '' +compose '>' 'e' to '' +compose '>' 'g' to '' +compose '>' 'h' to '' +compose '>' 'i' to '' +compose '>' 'j' to '' +compose '>' 'o' to '' +compose '>' 's' to '' +compose '>' 'u' to '' +compose 'G' 'U' to '' +compose '\'' 'A' to '' +compose '\'' 'E' to '' +compose '\'' 'I' to '' +compose '\'' 'O' to '' +compose '\'' 'U' to '' +compose '\'' 'Y' to '' +compose '\'' '\'' to '' +compose '\'' 'a' to '' +compose '\'' 'e' to '' +compose '\'' 'i' to '' +compose '\'' 'o' to '' +compose '\'' 'u' to '' +compose '\'' 'y' to '' +compose '^' '.' to '' +compose '^' '/' to '|' +compose '^' '0' to '' +compose '^' '2' to '' +compose '^' '3' to '' +compose '^' 'A' to '' +compose '^' 'C' to '' +compose '^' 'E' to '' +compose '^' 'G' to '' +compose '^' 'H' to '' +compose '^' 'I' to '' +compose '^' 'J' to '' +compose '^' 'O' to '' +compose '^' 'S' to '' +compose '^' 'U' to '' +compose '^' 'a' to '' +compose '^' 'c' to '' +compose '^' 'e' to '' +compose '^' 'g' to '' +compose '^' 'h' to '' +compose '^' 'i' to '' +compose '^' 'j' to '' +compose '^' 'o' to '' +compose '^' 's' to '' +compose '^' 'u' to '' +compose '`' 'A' to '' +compose '`' 'E' to '' +compose '`' 'I' to '' +compose '`' 'O' to '' +compose '`' 'U' to '' +compose '`' 'a' to '' +compose '`' 'e' to '' +compose '`' 'i' to '' +compose '`' 'o' to '' +compose '`' 'u' to '' +compose 'g' 'U' to '' +compose 'r' 'o' to '' +compose 's' '0' to '' +compose 's' '2' to '' +compose 's' '3' to '' +compose 's' 'o' to '' +compose 'u' 'u' to '' +compose 'v' 'l' to '|' +compose '~' 'A' to '' +compose '~' 'O' to '' +compose '~' 'a' to '' +compose '~' 'o' to '' diff --git a/console-setup/compose.ISO-8859-4.inc b/console-setup/compose.ISO-8859-4.inc new file mode 100644 index 00000000..4598a22a --- /dev/null +++ b/console-setup/compose.ISO-8859-4.inc @@ -0,0 +1,121 @@ +# Compose sequences for ISO-8859-4 +compose '!' 's' to '' +compose '"' '"' to '' +compose '"' 'A' to '' +compose '"' 'E' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'a' to '' +compose '"' 'e' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '*' '0' to '' +compose '*' 'A' to '' +compose '*' 'a' to '' +compose ',' ',' to '' +compose ',' 'A' to '' +compose ',' 'E' to '' +compose ',' 'G' to '' +compose ',' 'I' to '' +compose ',' 'K' to '' +compose ',' 'L' to '' +compose ',' 'N' to '' +compose ',' 'R' to '' +compose ',' 'U' to '' +compose ',' 'a' to '' +compose ',' 'e' to '' +compose ',' 'g' to '' +compose ',' 'i' to '' +compose ',' 'k' to '' +compose ',' 'l' to '' +compose ',' 'n' to '' +compose ',' 'r' to '' +compose ',' 'u' to '' +compose '-' '-' to '' +compose '-' ':' to '' +compose '-' 'A' to '' +compose '-' 'D' to '' +compose '-' 'E' to '' +compose '-' 'I' to '' +compose '-' 'O' to '' +compose '-' 'U' to '' +compose '-' '^' to '' +compose '-' 'a' to '' +compose '-' 'd' to '' +compose '-' 'e' to '' +compose '-' 'i' to '' +compose '-' 'o' to '' +compose '-' 'u' to '' +compose '.' '.' to '' +compose '.' 'E' to '' +compose '.' 'e' to '' +compose '/' 'O' to '' +compose '/' 'T' to '' +compose '/' 'o' to '' +compose '/' 't' to '' +compose ':' '-' to '' +compose '<' '<' to '' +compose '<' 'C' to '' +compose '<' 'S' to '' +compose '<' 'Z' to '' +compose '<' 'c' to '' +compose '<' 's' to '' +compose '<' 'z' to '' +compose '>' 'A' to '' +compose '>' 'I' to '' +compose '>' 'O' to '' +compose '>' 'U' to '' +compose '>' 'a' to '' +compose '>' 'i' to '' +compose '>' 'o' to '' +compose '>' 'u' to '' +compose 'A' 'E' to '' +compose 'N' 'G' to '' +compose 'T' '-' to '' +compose '\'' 'A' to '' +compose '\'' 'E' to '' +compose '\'' 'I' to '' +compose '\'' 'U' to '' +compose '\'' '\'' to '' +compose '\'' 'a' to '' +compose '\'' 'e' to '' +compose '\'' 'i' to '' +compose '\'' 'u' to '' +compose '^' '-' to '' +compose '^' 'A' to '' +compose '^' 'I' to '' +compose '^' 'O' to '' +compose '^' 'U' to '' +compose '^' '_' to '' +compose '^' 'a' to '' +compose '^' 'i' to '' +compose '^' 'o' to '' +compose '^' 'u' to '' +compose '_' 'A' to '' +compose '_' 'E' to '' +compose '_' 'I' to '' +compose '_' 'O' to '' +compose '_' 'U' to '' +compose '_' '^' to '' +compose '_' '_' to '' +compose '_' 'a' to '' +compose '_' 'e' to '' +compose '_' 'i' to '' +compose '_' 'o' to '' +compose '_' 'u' to '' +compose 'a' 'e' to '' +compose 'n' 'g' to '' +compose 'o' 'x' to '' +compose 's' '0' to '' +compose 's' 'o' to '' +compose 't' '-' to '' +compose 'x' '0' to '' +compose 'x' 'o' to '' +compose '~' 'A' to '' +compose '~' 'I' to '' +compose '~' 'O' to '' +compose '~' 'U' to '' +compose '~' 'a' to '' +compose '~' 'i' to '' +compose '~' 'o' to '' +compose '~' 'u' to '' diff --git a/console-setup/compose.ISO-8859-5.inc b/console-setup/compose.ISO-8859-5.inc new file mode 100644 index 00000000..90c4f07e --- /dev/null +++ b/console-setup/compose.ISO-8859-5.inc @@ -0,0 +1 @@ +# Compose sequences for ISO-8859-5 diff --git a/console-setup/compose.ISO-8859-6.inc b/console-setup/compose.ISO-8859-6.inc new file mode 100644 index 00000000..1a4f93fb --- /dev/null +++ b/console-setup/compose.ISO-8859-6.inc @@ -0,0 +1 @@ +# Compose sequences for ISO-8859-6 diff --git a/console-setup/compose.ISO-8859-7.inc b/console-setup/compose.ISO-8859-7.inc new file mode 100644 index 00000000..1aa936a8 --- /dev/null +++ b/console-setup/compose.ISO-8859-7.inc @@ -0,0 +1,52 @@ +# Compose sequences for ISO-8859-7 +compose '!' '^' to '' +compose '!' 's' to '' +compose '"' '"' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose '(' 'c' to '' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' '0' to '' +compose '+' '+' to '#' +compose '+' '-' to '' +compose ',' '-' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '+' to '' +compose '-' ',' to '' +compose '-' '-' to '' +compose '-' 'l' to '' +compose '.' '.' to '' +compose '.' '^' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' '^' to '|' +compose '1' '2' to '' +compose '<' '/' to '\\' +compose '<' '<' to '' +compose '<' '\'' to '' +compose '=' 'l' to '' +compose '>' '>' to '' +compose '>' '\'' to '' +compose '\'' '<' to '' +compose '\'' '>' to '' +compose '\'' '\'' to '' +compose '^' '!' to '' +compose '^' '.' to '' +compose '^' '/' to '|' +compose '^' '0' to '' +compose '^' '2' to '' +compose '^' '3' to '' +compose 'a' 't' to '@' +compose 'c' '0' to '' +compose 'c' 'o' to '' +compose 'o' 'c' to '' +compose 's' '0' to '' +compose 's' '2' to '' +compose 's' '3' to '' +compose 's' 'o' to '' +compose 'v' 'b' to '' +compose 'v' 'l' to '|' +compose '|' '|' to '' +compose '~' '~' to '' diff --git a/console-setup/compose.ISO-8859-8.inc b/console-setup/compose.ISO-8859-8.inc new file mode 100644 index 00000000..1fbb453c --- /dev/null +++ b/console-setup/compose.ISO-8859-8.inc @@ -0,0 +1 @@ +# Compose sequences for ISO-8859-8 diff --git a/console-setup/compose.ISO-8859-9.inc b/console-setup/compose.ISO-8859-9.inc new file mode 100644 index 00000000..e642e1b7 --- /dev/null +++ b/console-setup/compose.ISO-8859-9.inc @@ -0,0 +1,156 @@ +# Compose sequences for ISO-8859-9 +compose '!' '!' to '' +compose '!' 'p' to '' +compose '!' 's' to '' +compose '"' '"' to '' +compose '"' 'A' to '' +compose '"' 'E' to '' +compose '"' 'I' to '' +compose '"' 'O' to '' +compose '"' 'U' to '' +compose '"' 'Y' to '' +compose '"' 'a' to '' +compose '"' 'e' to '' +compose '"' 'i' to '' +compose '"' 'o' to '' +compose '"' 'u' to '' +compose '"' 'y' to '' +compose '(' '(' to '[' +compose '(' '-' to '{' +compose '(' 'G' to '' +compose '(' 'c' to '' +compose '(' 'g' to '' +compose '(' 'r' to '' +compose ')' ')' to ']' +compose ')' '-' to '}' +compose '*' '0' to '' +compose '*' 'A' to '' +compose '*' 'a' to '' +compose '+' '+' to '#' +compose '+' '-' to '' +compose ',' ',' to '' +compose ',' '-' to '' +compose ',' 'C' to '' +compose ',' 'S' to '' +compose ',' 'c' to '' +compose ',' 's' to '' +compose '-' '(' to '{' +compose '-' ')' to '}' +compose '-' '+' to '' +compose '-' ',' to '' +compose '-' '-' to '' +compose '-' ':' to '' +compose '-' 'A' to '' +compose '-' 'D' to '' +compose '-' 'N' to '' +compose '-' 'O' to '' +compose '-' '^' to '' +compose '-' 'a' to '' +compose '-' 'd' to '' +compose '-' 'l' to '' +compose '-' 'n' to '' +compose '-' 'o' to '' +compose '-' 'y' to '' +compose '.' '.' to '' +compose '.' 'I' to '' +compose '.' '^' to '' +compose '.' 'i' to '' +compose '/' '/' to '\\' +compose '/' '<' to '\\' +compose '/' 'O' to '' +compose '/' '^' to '|' +compose '/' 'c' to '' +compose '/' 'o' to '' +compose '/' 'u' to '' +compose ':' '-' to '' +compose '<' '/' to '\\' +compose '<' '<' to '' +compose '<' 'Z' to '' +compose '<' 'z' to '' +compose '=' 'c' to '' +compose '=' 'e' to '' +compose '=' 'l' to '' +compose '=' 'y' to '' +compose '>' '>' to '' +compose '>' 'A' to '' +compose '>' 'E' to '' +compose '>' 'I' to '' +compose '>' 'O' to '' +compose '>' 'U' to '' +compose '>' 'a' to '' +compose '>' 'e' to '' +compose '>' 'i' to '' +compose '>' 'o' to '' +compose '>' 'u' to '' +compose '?' '?' to '' +compose 'A' 'E' to '' +compose 'G' 'U' to '' +compose 'T' 'H' to '' +compose '\'' 'A' to '' +compose '\'' 'E' to '' +compose '\'' 'I' to '' +compose '\'' 'O' to '' +compose '\'' 'U' to '' +compose '\'' 'Y' to '' +compose '\'' '\'' to '' +compose '\'' 'a' to '' +compose '\'' 'e' to '' +compose '\'' 'i' to '' +compose '\'' 'o' to '' +compose '\'' 'u' to '' +compose '\'' 'y' to '' +compose '^' '-' to '' +compose '^' '.' to '' +compose '^' '/' to '|' +compose '^' '0' to '' +compose '^' '1' to '' +compose '^' '2' to '' +compose '^' '3' to '' +compose '^' 'A' to '' +compose '^' 'E' to '' +compose '^' 'I' to '' +compose '^' 'O' to '' +compose '^' 'U' to '' +compose '^' '_' to '' +compose '^' 'a' to '' +compose '^' 'e' to '' +compose '^' 'i' to '' +compose '^' 'o' to '' +compose '^' 'u' to '' +compose '_' '^' to '' +compose '_' '_' to '' +compose '_' 'a' to '' +compose '_' 'o' to '' +compose '`' 'A' to '' +compose '`' 'E' to '' +compose '`' 'I' to '' +compose '`' 'O' to '' +compose '`' 'U' to '' +compose '`' 'a' to '' +compose '`' 'e' to '' +compose '`' 'i' to '' +compose '`' 'o' to '' +compose '`' 'u' to '' +compose 'a' 'e' to '' +compose 'c' '0' to '' +compose 'c' 'o' to '' +compose 'g' 'U' to '' +compose 'o' 'c' to '' +compose 'o' 'e' to '' +compose 'r' 'o' to '' +compose 's' '0' to '' +compose 's' '1' to '' +compose 's' '2' to '' +compose 's' '3' to '' +compose 's' 'o' to '' +compose 't' 'h' to '' +compose 'v' 'Z' to '' +compose 'v' 'l' to '|' +compose 'v' 'z' to '' +compose '|' 'c' to '' +compose '~' 'A' to '' +compose '~' 'N' to '' +compose '~' 'O' to '' +compose '~' 'a' to '' +compose '~' 'n' to '' +compose '~' 'o' to '' diff --git a/console-setup/compose.KOI8-R.inc b/console-setup/compose.KOI8-R.inc new file mode 100644 index 00000000..da0c7aee --- /dev/null +++ b/console-setup/compose.KOI8-R.inc @@ -0,0 +1 @@ +# Compose sequences for KOI8-R diff --git a/console-setup/compose.KOI8-U.inc b/console-setup/compose.KOI8-U.inc new file mode 100644 index 00000000..38e91277 --- /dev/null +++ b/console-setup/compose.KOI8-U.inc @@ -0,0 +1 @@ +# Compose sequences for KOI8-U diff --git a/console-setup/compose.TIS-620.inc b/console-setup/compose.TIS-620.inc new file mode 100644 index 00000000..4b229cc7 --- /dev/null +++ b/console-setup/compose.TIS-620.inc @@ -0,0 +1 @@ +# Compose sequences for TIS-620 diff --git a/console-setup/compose.VISCII.inc b/console-setup/compose.VISCII.inc new file mode 100644 index 00000000..b9576aba --- /dev/null +++ b/console-setup/compose.VISCII.inc @@ -0,0 +1 @@ +# Compose sequences for VISCII diff --git a/console-setup/remap.inc b/console-setup/remap.inc new file mode 100644 index 00000000..a5475c66 --- /dev/null +++ b/console-setup/remap.inc @@ -0,0 +1,32 @@ +# The content of this file will be appended to the keyboard layout. +# The following is an example how to make Alt+j switch to to the next +# console and Alt+k switch to the previous console. + +# Uncomment the following lines for Linux. Notice that everything is +# replicated for all possible values of the modifiers shiftl, shiftr +# and ctrll (shiftl and shiftr are used for groups 1..4 of XKB and +# ctrll is used to fix the broken CapsLock when Linux console is in +# Unicode mode). + +# alt keycode 36 = Incr_Console +# shiftl alt keycode 36 = Incr_Console +# shiftr alt keycode 36 = Incr_Console +# shiftr shiftl alt keycode 36 = Incr_Console +# ctrll alt keycode 36 = Incr_Console +# ctrll shiftl alt keycode 36 = Incr_Console +# ctrll shiftr alt keycode 36 = Incr_Console +# ctrll shiftr shiftl alt keycode 36 = Incr_Console +# +# alt keycode 37 = Decr_Console +# shiftl alt keycode 37 = Decr_Console +# shiftr alt keycode 37 = Decr_Console +# shiftr shiftl alt keycode 37 = Decr_Console +# ctrll alt keycode 37 = Decr_Console +# ctrll shiftl alt keycode 37 = Decr_Console +# ctrll shiftr alt keycode 37 = Decr_Console +# ctrll shiftr shiftl alt keycode 37 = Decr_Console + +# For the same result on FreeBSD uncomment the following lines: + +# 036 'j' 'J' nl nl nscr nscr nl nl C +# 037 'k' 'K' vt vt pscr pscr nl nl C diff --git a/cron.d/.placeholder b/cron.d/.placeholder new file mode 100644 index 00000000..76cb8d07 --- /dev/null +++ b/cron.d/.placeholder @@ -0,0 +1,2 @@ +# DO NOT EDIT OR REMOVE +# This file is a simple placeholder to keep dpkg from removing this directory diff --git a/cron.d/e2scrub_all b/cron.d/e2scrub_all new file mode 100644 index 00000000..711b0b29 --- /dev/null +++ b/cron.d/e2scrub_all @@ -0,0 +1,2 @@ +30 3 * * 0 root test -e /run/systemd/system || SERVICE_MODE=1 /usr/lib/x86_64-linux-gnu/e2fsprogs/e2scrub_all_cron +10 3 * * * root test -e /run/systemd/system || SERVICE_MODE=1 /sbin/e2scrub_all -A -r diff --git a/cron.d/kernel b/cron.d/kernel new file mode 100644 index 00000000..e9894a54 --- /dev/null +++ b/cron.d/kernel @@ -0,0 +1,2 @@ +20 23 * * * root /sbin/fstrim -a > /dev/null 2>&1 +20 23 * * * root /usr/sbin/fstrim -a > /dev/null 2>&1 diff --git a/cron.d/php b/cron.d/php new file mode 100644 index 00000000..84e5d10d --- /dev/null +++ b/cron.d/php @@ -0,0 +1,14 @@ +# /etc/cron.d/php@PHP_VERSION@: crontab fragment for PHP +# This purges session files in session.save_path older than X, +# where X is defined in seconds as the largest value of +# session.gc_maxlifetime from all your SAPI php.ini files +# or 24 minutes if not defined. The script triggers only +# when session.save_handler=files. +# +# WARNING: The scripts tries hard to honour all relevant +# session PHP options, but if you do something unusual +# you have to disable this script and take care of your +# sessions yourself. + +# Look for and purge old sessions every 30 minutes +09,39 * * * * root [ -x /usr/lib/php/sessionclean ] && if [ ! -d /run/systemd/system ]; then /usr/lib/php/sessionclean; fi diff --git a/cron.daily/.placeholder b/cron.daily/.placeholder new file mode 100644 index 00000000..76cb8d07 --- /dev/null +++ b/cron.daily/.placeholder @@ -0,0 +1,2 @@ +# DO NOT EDIT OR REMOVE +# This file is a simple placeholder to keep dpkg from removing this directory diff --git a/cron.daily/apt-compat b/cron.daily/apt-compat new file mode 100755 index 00000000..b0b55376 --- /dev/null +++ b/cron.daily/apt-compat @@ -0,0 +1,55 @@ +#!/bin/sh + +set -e + +# Systemd systems use a systemd timer unit which is preferable to +# run. We want to randomize the apt update and unattended-upgrade +# runs as much as possible to avoid hitting the mirrors all at the +# same time. The systemd time is better at this than the fixed +# cron.daily time +if [ -d /run/systemd/system ]; then + exit 0 +fi + +check_power() +{ + # laptop check, on_ac_power returns: + # 0 (true) System is on main power + # 1 (false) System is not on main power + # 255 (false) Power status could not be determined + # Desktop systems always return 255 it seems + if which on_ac_power >/dev/null 2>&1; then + if on_ac_power; then + : + elif [ $? -eq 1 ]; then + return 1 + fi + fi + return 0 +} + +# sleep for a random interval of time (default 30min) +# (some code taken from cron-apt, thanks) +random_sleep() +{ + RandomSleep=1800 + eval $(apt-config shell RandomSleep APT::Periodic::RandomSleep) + if [ $RandomSleep -eq 0 ]; then + return + fi + if [ -z "$RANDOM" ] ; then + # A fix for shells that do not have this bash feature. + RANDOM=$(( $(dd if=/dev/urandom bs=2 count=1 2> /dev/null | cksum | cut -d' ' -f1) % 32767 )) + fi + TIME=$(($RANDOM % $RandomSleep)) + sleep $TIME +} + +# delay the job execution by a random amount of time +random_sleep + +# ensure we don't do this on battery +check_power || exit 0 + +# run daily job +exec /usr/lib/apt/apt.systemd.daily diff --git a/cron.daily/dpkg b/cron.daily/dpkg new file mode 100755 index 00000000..11124f7d --- /dev/null +++ b/cron.daily/dpkg @@ -0,0 +1,42 @@ +#!/bin/sh + +dbdir=/var/lib/dpkg + +# Backup the 7 last versions of dpkg databases containing user data. +if cd /var/backups ; then + # We backup all relevant database files if any has changed, so that + # the rotation number always contains an internally consistent set. + dbchanged=no + dbfiles="arch status diversions statoverride" + for db in $dbfiles ; do + if ! [ -s "dpkg.${db}.0" ] && ! [ -s "$dbdir/$db" ]; then + # Special case the files not existing or being empty as being equal. + continue + elif ! cmp -s "dpkg.${db}.0" "$dbdir/$db"; then + dbchanged=yes + break + fi + done + if [ "$dbchanged" = "yes" ] ; then + for db in $dbfiles ; do + if [ -e "$dbdir/$db" ]; then + cp -p "$dbdir/$db" "dpkg.$db" + else + touch "dpkg.$db" + fi + savelog -c 7 "dpkg.$db" >/dev/null + done + fi + + # The alternatives database is independent from the dpkg database. + dbalt=alternatives + + # XXX: Ideally we'd use --warning=none instead of discarding stderr, but + # as of GNU tar 1.27.1, it does not seem to work reliably (see #749307). + if ! test -e ${dbalt}.tar.0 || + ! tar -df ${dbalt}.tar.0 -C $dbdir $dbalt >/dev/null 2>&1 ; + then + tar -cf ${dbalt}.tar -C $dbdir $dbalt >/dev/null 2>&1 + savelog -c 7 ${dbalt}.tar >/dev/null + fi +fi diff --git a/cron.daily/etckeeper b/cron.daily/etckeeper new file mode 100755 index 00000000..eb74401a --- /dev/null +++ b/cron.daily/etckeeper @@ -0,0 +1,8 @@ +#!/bin/sh +set -e +if [ -e /etc/etckeeper/daily ] && [ -e /etc/etckeeper/etckeeper.conf ]; then + . /etc/etckeeper/etckeeper.conf + if [ "$AVOID_DAILY_AUTOCOMMITS" != "1" ]; then + /etc/etckeeper/daily + fi +fi diff --git a/cron.daily/logrotate b/cron.daily/logrotate new file mode 100755 index 00000000..1ac15700 --- /dev/null +++ b/cron.daily/logrotate @@ -0,0 +1,18 @@ +#!/bin/sh + +# skip in favour of systemd timer +if [ -d /run/systemd/system ]; then + exit 0 +fi + +# this cronjob persists removals (but not purges) +if [ ! -x /usr/sbin/logrotate ]; then + exit 0 +fi + +/usr/sbin/logrotate /etc/logrotate.conf +EXITVALUE=$? +if [ $EXITVALUE != 0 ]; then + /usr/bin/logger -t logrotate "ALERT exited abnormally with [$EXITVALUE]" +fi +exit $EXITVALUE diff --git a/cron.daily/man-db b/cron.daily/man-db new file mode 100755 index 00000000..1342bc68 --- /dev/null +++ b/cron.daily/man-db @@ -0,0 +1,43 @@ +#!/bin/sh +# +# man-db cron daily + +set -e + +if [ -d /run/systemd/system ]; then + # Skip in favour of systemd timer. + exit 0 +fi + +iosched_idle= +# Don't try to change I/O priority in a vserver or OpenVZ. +if ! egrep -q '(envID|VxID):.*[1-9]' /proc/self/status && \ + ([ ! -d /proc/vz ] || [ -d /proc/bc ]); then + iosched_idle='--iosched idle' +fi + +if ! [ -d /var/cache/man ]; then + # Recover from deletion, per FHS. + install -d -o man -g man -m 0755 /var/cache/man +fi + +# expunge old catman pages which have not been read in a week +if [ -d /var/cache/man ]; then + cd / + start-stop-daemon --start --pidfile /dev/null --startas /bin/sh \ + --oknodo --chuid man $iosched_idle -- -c \ + "find /var/cache/man -type f -name '*.gz' -atime +6 -print0 | \ + xargs -r0 rm -f" +fi + +# regenerate man database +if [ -x /usr/bin/mandb ]; then + # --pidfile /dev/null so it always starts; mandb isn't really a daemon, + # but we want to start it like one. + start-stop-daemon --start --pidfile /dev/null \ + --startas /usr/bin/mandb --oknodo --chuid man \ + $iosched_idle \ + -- --no-purge --quiet +fi + +exit 0 diff --git a/cron.hourly/.placeholder b/cron.hourly/.placeholder new file mode 100644 index 00000000..76cb8d07 --- /dev/null +++ b/cron.hourly/.placeholder @@ -0,0 +1,2 @@ +# DO NOT EDIT OR REMOVE +# This file is a simple placeholder to keep dpkg from removing this directory diff --git a/cron.monthly/.placeholder b/cron.monthly/.placeholder new file mode 100644 index 00000000..76cb8d07 --- /dev/null +++ b/cron.monthly/.placeholder @@ -0,0 +1,2 @@ +# DO NOT EDIT OR REMOVE +# This file is a simple placeholder to keep dpkg from removing this directory diff --git a/cron.weekly/.placeholder b/cron.weekly/.placeholder new file mode 100644 index 00000000..76cb8d07 --- /dev/null +++ b/cron.weekly/.placeholder @@ -0,0 +1,2 @@ +# DO NOT EDIT OR REMOVE +# This file is a simple placeholder to keep dpkg from removing this directory diff --git a/cron.weekly/man-db b/cron.weekly/man-db new file mode 100755 index 00000000..6e3ad83a --- /dev/null +++ b/cron.weekly/man-db @@ -0,0 +1,34 @@ +#!/bin/sh +# +# man-db cron weekly + +set -e + +if [ -d /run/systemd/system ]; then + # Skip in favour of systemd timer. + exit 0 +fi + +iosched_idle= +# Don't try to change I/O priority in a vserver or OpenVZ. +if ! egrep -q '(envID|VxID):.*[1-9]' /proc/self/status && \ + ([ ! -d /proc/vz ] || [ -d /proc/bc ]); then + iosched_idle='--iosched idle' +fi + +if ! [ -d /var/cache/man ]; then + # Recover from deletion, per FHS. + install -d -o man -g man -m 0755 /var/cache/man +fi + +# regenerate man database +if [ -x /usr/bin/mandb ]; then + # --pidfile /dev/null so it always starts; mandb isn't really a daemon, + # but we want to start it like one. + start-stop-daemon --start --pidfile /dev/null \ + --startas /usr/bin/mandb --oknodo --chuid man \ + $iosched_idle \ + -- --quiet +fi + +exit 0 diff --git a/crontab b/crontab new file mode 100644 index 00000000..c89cc0be --- /dev/null +++ b/crontab @@ -0,0 +1,22 @@ +# /etc/crontab: system-wide crontab +# Unlike any other crontab you don't have to run the `crontab' +# command to install the new version when you edit this file +# and files in /etc/cron.d. These files also have username fields, +# that none of the other crontabs do. + +SHELL=/bin/sh +PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin + +# Example of job definition: +# .---------------- minute (0 - 59) +# | .------------- hour (0 - 23) +# | | .---------- day of month (1 - 31) +# | | | .------- month (1 - 12) OR jan,feb,mar,apr ... +# | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat +# | | | | | +# * * * * * user-name command to be executed +17 * * * * root cd / && run-parts --report /etc/cron.hourly +25 6 * * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.daily ) +47 6 * * 7 root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.weekly ) +52 6 1 * * root test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.monthly ) +# diff --git a/cruft/filters-unex/etckeeper b/cruft/filters-unex/etckeeper new file mode 100644 index 00000000..edd5f33a --- /dev/null +++ b/cruft/filters-unex/etckeeper @@ -0,0 +1,13 @@ +/etc/.etckeeper +/etc/.gitignore +/etc/.git +/etc/.git/** +/etc/.hgignore +/etc/.hg +/etc/.hg/** +/etc/.bzrignore +/etc/.bzr +/etc/.bzr/** +/etc/.darcsignore +/etc/_darcs +/etc/_darcs/** diff --git a/debconf.conf b/debconf.conf new file mode 100644 index 00000000..549c1d59 --- /dev/null +++ b/debconf.conf @@ -0,0 +1,83 @@ +# This is the main config file for debconf. It tells debconf where to +# store data. The format of this file is a set of stanzas. Each stanza +# except the first sets up a database for debconf to use. For details, see +# debconf.conf(5) (in the debconf-doc package). +# +# So first things first. This first stanza gives the names of two databases. + +# Debconf will use this database to store the data you enter into it, +# and some other dynamic data. +Config: configdb +# Debconf will use this database to store static template data. +Templates: templatedb + +# World-readable, and accepts everything but passwords. +Name: config +Driver: File +Mode: 644 +Reject-Type: password +Filename: /var/cache/debconf/config.dat + +# Not world readable (the default), and accepts only passwords. +Name: passwords +Driver: File +Mode: 600 +Backup: false +Required: false +Accept-Type: password +Filename: /var/cache/debconf/passwords.dat + +# Set up the configdb database. By default, it consists of a stack of two +# databases, one to hold passwords and one for everything else. +Name: configdb +Driver: Stack +Stack: config, passwords + +# Set up the templatedb database, which is a single flat text file +# by default. +Name: templatedb +Driver: File +Mode: 644 +Filename: /var/cache/debconf/templates.dat + +# Well that was pretty straightforward, and it will be enough for most +# people's needs, but debconf's database drivers can be used to do much +# more interesting things. For example, suppose you want to use config +# data from another host, which is mounted over nfs or perhaps the database +# is accessed via LDAP. You don't want to write to the remote debconf database, +# just read from it, so you still need a local database for local changes. +# +# A remote NFS mounted database, read-only. It is optional; if debconf +# fails to use it it will not abort. +#Name: remotedb +#Driver: DirTree +#Directory: /mnt/otherhost/var/cache/debconf/config +#Readonly: true +#Required: false +# +# A remote LDAP database. It is also read-only. The password is really +# only necessary if the database is not accessible anonymously. +# Option KeyByKey instructs the backend to retrieve keys from the LDAP +# server individually (when they are requested), instead of loading all +# keys at startup. The default is 0, and should only be enabled if you +# want to track accesses to individual keys on the LDAP server side. +#Name: remotedb +#Driver: LDAP +#Server: remotehost +#BaseDN: cn=debconf,dc=domain,dc=com +#BindDN: uid=admin,dc=domain,dc=com +#BindPasswd: secret +#KeyByKey: 0 +# +# A stack consisting of two databases. Values will be read from +# the first database in the stack to contain a value. In this example, +# writes always go to the first database. +#Name: fulldb +#Driver: Stack +#Stack: configdb, remotedb +# +# In this example, we'd use Config: fulldb at the top of the file +# to make it use the combination of the databases. +# +# Even more complex and interesting setups are possible, see the +# debconf.conf(5) page for details. diff --git a/debian_version b/debian_version new file mode 100644 index 00000000..8bb42223 --- /dev/null +++ b/debian_version @@ -0,0 +1 @@ +11.3 diff --git a/default/console-setup b/default/console-setup new file mode 100644 index 00000000..2e997bc5 --- /dev/null +++ b/default/console-setup @@ -0,0 +1,16 @@ +# CONFIGURATION FILE FOR SETUPCON + +# Consult the console-setup(5) manual page. + +ACTIVE_CONSOLES="/dev/tty[1-6]" + +CHARMAP="UTF-8" + +CODESET="Lat15" +FONTFACE="VGA" +FONTSIZE="8x16" + +VIDEOMODE= + +# The following is an example how to use a braille font +# FONT='lat9w-08.psf.gz brl-8x8.psf' diff --git a/default/cron b/default/cron new file mode 100644 index 00000000..f62b7be8 --- /dev/null +++ b/default/cron @@ -0,0 +1,28 @@ +# Cron configuration options + +# Whether to read the system's default environment files (if present) +# If set to "yes", cron will set a proper mail charset from the +# locale information. If set to something other than 'yes', the default +# charset 'C' (canonical name: ANSI_X3.4-1968) will be used. +# +# This has no effect on tasks running under cron; their environment can +# only be changed via PAM or from within the crontab; see crontab(5). +READ_ENV="yes" + +# Extra options for cron, see cron(8) +# +# For example, to enable LSB name support in /etc/cron.d/, use +# EXTRA_OPTS='-l' +# +# Or, to log standard messages, plus jobs with exit status != 0: +# EXTRA_OPTS='-L 5' +# +# For quick reference, the currently available log levels are: +# 0 no logging (errors are logged regardless) +# 1 log start of jobs +# 2 log end of jobs +# 4 log jobs with exit status != 0 +# 8 log the process identifier of child process (in all logs) +# +#EXTRA_OPTS="" + diff --git a/default/dbus b/default/dbus new file mode 100644 index 00000000..4bc8e1b6 --- /dev/null +++ b/default/dbus @@ -0,0 +1,7 @@ +# This is a configuration file for /etc/init.d/dbus; it allows you to +# perform common modifications to the behavior of the dbus daemon +# startup without editing the init script (and thus getting prompted +# by dpkg on upgrades). We all love dpkg prompts. + +# Parameters to pass to dbus. +PARAMS="" diff --git a/default/fail2ban b/default/fail2ban new file mode 100644 index 00000000..35bb3771 --- /dev/null +++ b/default/fail2ban @@ -0,0 +1,39 @@ +# This file is part of Fail2Ban. +# +# Fail2Ban is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 2 of the License, or +# (at your option) any later version. +# +# Fail2Ban is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with Fail2Ban; if not, write to the Free Software +# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA +# +# Author: Cyril Jaquier +# +# $Revision$ + +# Command line options for Fail2Ban. Refer to "fail2ban-client -h" for +# valid options. +FAIL2BAN_OPTS="" + +# Run fail2ban as a different user. If not set, fail2ban +# will run as root. +# +# The user is not created automatically. +# The user can be created e.g. with +# useradd --system --no-create-home --home-dir / --groups adm fail2ban +# Log files are readable by group adm by default. Adding the fail2ban +# user to this group allows it to read the logfiles. +# +# Another manual step that needs to be taken is to allow write access +# for fail2ban user to fail2ban log files. The /etc/init.d/fail2ban +# script will change the ownership when starting fail2ban. Logrotate +# needs to be configured separately, see /etc/logrotate.d/fail2ban. +# +# FAIL2BAN_USER="fail2ban" diff --git a/default/grub b/default/grub new file mode 100644 index 00000000..8bebc362 --- /dev/null +++ b/default/grub @@ -0,0 +1,33 @@ +# If you change this file, run 'update-grub' afterwards to update +# /boot/grub/grub.cfg. +# For full documentation of the options in this file, see: +# info -f grub -n 'Simple configuration' + +GRUB_DEFAULT=0 +GRUB_TIMEOUT=5 +GRUB_DISTRIBUTOR=`lsb_release -i -s 2> /dev/null || echo Debian` +GRUB_CMDLINE_LINUX_DEFAULT="quiet" +GRUB_CMDLINE_LINUX="net.ifnames=0 video=1024x768" + +# Uncomment to enable BadRAM filtering, modify to suit your needs +# This works with Linux (no patch required) and with any kernel that obtains +# the memory map information from GRUB (GNU Mach, kernel of FreeBSD ...) +#GRUB_BADRAM="0x01234567,0xfefefefe,0x89abcdef,0xefefefef" + +# Uncomment to disable graphical terminal (grub-pc only) +#GRUB_TERMINAL=console + +# The resolution used on graphical terminal +# note that you can use only modes which your graphic card supports via VBE +# you can see them in real GRUB with the command `vbeinfo' +GRUB_GFXMODE=1024x768 +GRUB_GFXMODE_LINUX=keep + +# Uncomment if you don't want GRUB to pass "root=UUID=xxx" parameter to Linux +#GRUB_DISABLE_LINUX_UUID=true + +# Uncomment to disable generation of recovery mode menu entries +#GRUB_DISABLE_RECOVERY="true" + +# Uncomment to get a beep at grub start +#GRUB_INIT_TUNE="480 440 1" diff --git a/default/grub.d/init-select.cfg b/default/grub.d/init-select.cfg new file mode 100644 index 00000000..7fbfff80 --- /dev/null +++ b/default/grub.d/init-select.cfg @@ -0,0 +1,7 @@ +# Work around a bug in the obsolete init-select package which broke +# grub-mkconfig when init-select was removed but not purged. This file does +# nothing and will be removed in a later release. +# +# See: +# https://bugs.debian.org/858528 +# https://bugs.debian.org/863801 diff --git a/default/hwclock b/default/hwclock new file mode 100644 index 00000000..44b04312 --- /dev/null +++ b/default/hwclock @@ -0,0 +1,2 @@ +# Settings for the hwclock init script. +# See hwclock(5) for supported settings. diff --git a/default/keyboard b/default/keyboard new file mode 100644 index 00000000..30e034fb --- /dev/null +++ b/default/keyboard @@ -0,0 +1,5 @@ +XKBMODEL="pc105" +XKBLAYOUT="us" +XKBOPTIONS="terminate:ctrl_alt_bksp" +BACKSPACE="guess" +XKBVARIANT="" diff --git a/default/locale b/default/locale new file mode 100644 index 00000000..01ec548f --- /dev/null +++ b/default/locale @@ -0,0 +1 @@ +LANG=en_US.UTF-8 diff --git a/default/networking b/default/networking new file mode 100644 index 00000000..96553592 --- /dev/null +++ b/default/networking @@ -0,0 +1,31 @@ +# Configuration for networking init script being run during +# the boot sequence + +# Set to 'no' to skip interfaces configuration on boot +#CONFIGURE_INTERFACES=yes + +# Don't configure these interfaces. Shell wildcards supported/ +#EXCLUDE_INTERFACES= + +# Set to 'yes' to enable additional verbosity +#VERBOSE=no + +# Method to wait for the network to become online, +# for services that depend on a working network: +# - ifup: wait for ifup to have configured an interface. +# - route: wait for a route to a given address to appear. +# - ping/ping6: wait for a host to respond to ping packets. +# - none: don't wait. +#WAIT_ONLINE_METHOD=ifup + +# Which interface to wait for. +# If none given, wait for all auto interfaces, or if there are none, +# wait for at least one hotplug interface. +#WAIT_ONLINE_IFACE= + +# Which address to wait for for route, ping and ping6 methods. +# If none is given for route, it waits for a default gateway. +#WAIT_ONLINE_ADDRESS= + +# Timeout in seconds for waiting for the network to come online. +#WAIT_ONLINE_TIMEOUT=300 diff --git a/default/nginx b/default/nginx new file mode 100644 index 00000000..09b8fd0a --- /dev/null +++ b/default/nginx @@ -0,0 +1,10 @@ +# Note: You may want to look at the following page before setting the ULIMIT. +# http://wiki.nginx.org/CoreModule#worker_rlimit_nofile +# Set the ulimit variable if you need defaults to change. +# Example: ULIMIT="-n 4096" +#ULIMIT="-n 4096" + +# Define the stop schedule for nginx +# see the start-stop-daemon --retry documentation for more information +# +#STOP_SCHEDULE="QUIT/5/TERM/5/KILL/5" diff --git a/default/nss b/default/nss new file mode 100644 index 00000000..c43e88b9 --- /dev/null +++ b/default/nss @@ -0,0 +1,37 @@ +# /etc/default/nss +# This file can theoretically contain a bunch of customization variables +# for Name Service Switch in the GNU C library. For now there are only +# four variables: +# +# NETID_AUTHORITATIVE +# If set to TRUE, the initgroups() function will accept the information +# from the netid.byname NIS map as authoritative. This can speed up the +# function significantly if the group.byname map is large. The content +# of the netid.byname map is used AS IS. The system administrator has +# to make sure it is correctly generated. +#NETID_AUTHORITATIVE=TRUE +# +# SERVICES_AUTHORITATIVE +# If set to TRUE, the getservbyname{,_r}() function will assume +# services.byservicename NIS map exists and is authoritative, particularly +# that it contains both keys with /proto and without /proto for both +# primary service names and service aliases. The system administrator +# has to make sure it is correctly generated. +#SERVICES_AUTHORITATIVE=TRUE +# +# SETENT_BATCH_READ +# If set to TRUE, various setXXent() functions will read the entire +# database at once and then hand out the requests one by one from +# memory with every getXXent() call. Otherwise each getXXent() call +# might result into a network communication with the server to get +# the next entry. +#SETENT_BATCH_READ=TRUE +# +# ADJUNCT_AS_SHADOW +# If set to TRUE, the passwd routines in the NIS NSS module will not +# use the passwd.adjunct.byname tables to fill in the password data +# in the passwd structure. This is a security problem if the NIS +# server cannot be trusted to send the passwd.adjuct table only to +# privileged clients. Instead the passwd.adjunct.byname table is +# used to synthesize the shadow.byname table if it does not exist. +ADJUNCT_AS_SHADOW=TRUE diff --git a/default/redis-server b/default/redis-server new file mode 100644 index 00000000..f98f6c1c --- /dev/null +++ b/default/redis-server @@ -0,0 +1,7 @@ +# redis-server configure options + +# ULIMIT: Call ulimit -n with this argument prior to invoking Redis itself. +# This may be required for high-concurrency environments. Redis itself cannot +# alter its limits as it is not being run as root. (default: 65536) +# +ULIMIT=65536 diff --git a/default/rsync b/default/rsync new file mode 100644 index 00000000..424b1c0f --- /dev/null +++ b/default/rsync @@ -0,0 +1,47 @@ +# defaults file for rsync daemon mode +# +# This file is only used for init.d based systems! +# If this system uses systemd, you can specify options etc. for rsync +# in daemon mode by copying /lib/systemd/system/rsync.service to +# /etc/systemd/system/rsync.service and modifying the copy; add required +# options to the ExecStart line. + +# start rsync in daemon mode from init.d script? +# only allowed values are "true", "false", and "inetd" +# Use "inetd" if you want to start the rsyncd from inetd, +# all this does is prevent the init.d script from printing a message +# about not starting rsyncd (you still need to modify inetd's config yourself). +RSYNC_ENABLE=false + +# which file should be used as the configuration file for rsync. +# This file is used instead of the default /etc/rsyncd.conf +# Warning: This option has no effect if the daemon is accessed +# using a remote shell. When using a different file for +# rsync you might want to symlink /etc/rsyncd.conf to +# that file. +# RSYNC_CONFIG_FILE= + +# what extra options to give rsync --daemon? +# that excludes the --daemon; that's always done in the init.d script +# Possibilities are: +# --address=123.45.67.89 (bind to a specific IP address) +# --port=8730 (bind to specified port; default 873) +RSYNC_OPTS='' + +# run rsyncd at a nice level? +# the rsync daemon can impact performance due to much I/O and CPU usage, +# so you may want to run it at a nicer priority than the default priority. +# Allowed values are 0 - 19 inclusive; 10 is a reasonable value. +RSYNC_NICE='' + +# run rsyncd with ionice? +# "ionice" does for IO load what "nice" does for CPU load. +# As rsync is often used for backups which aren't all that time-critical, +# reducing the rsync IO priority will benefit the rest of the system. +# See the manpage for ionice for allowed options. +# -c3 is recommended, this will run rsync IO at "idle" priority. Uncomment +# the next line to activate this. +# RSYNC_IONICE='-c3' + +# Don't forget to create an appropriate config file, +# else the daemon will not start. diff --git a/default/ssh b/default/ssh new file mode 100644 index 00000000..30404222 --- /dev/null +++ b/default/ssh @@ -0,0 +1,5 @@ +# Default settings for openssh-server. This file is sourced by /bin/sh from +# /etc/init.d/ssh. + +# Options to pass to sshd +SSHD_OPTS= diff --git a/default/useradd b/default/useradd new file mode 100644 index 00000000..e32955a7 --- /dev/null +++ b/default/useradd @@ -0,0 +1,37 @@ +# Default values for useradd(8) +# +# The SHELL variable specifies the default login shell on your +# system. +# Similar to DSHELL in adduser. However, we use "sh" here because +# useradd is a low level utility and should be as general +# as possible +SHELL=/bin/sh +# +# The default group for users +# 100=users on Debian systems +# Same as USERS_GID in adduser +# This argument is used when the -n flag is specified. +# The default behavior (when -n and -g are not specified) is to create a +# primary user group with the same name as the user being added to the +# system. +# GROUP=100 +# +# The default home directory. Same as DHOME for adduser +# HOME=/home +# +# The number of days after a password expires until the account +# is permanently disabled +# INACTIVE=-1 +# +# The default expire date +# EXPIRE= +# +# The SKEL variable specifies the directory containing "skeletal" user +# files; in other words, files such as a sample .profile that will be +# copied to the new user's home directory when it is created. +# SKEL=/etc/skel +# +# Defines whether the mail spool should be created while +# creating the account +# CREATE_MAIL_SPOOL=yes + diff --git a/deluser.conf b/deluser.conf new file mode 100644 index 00000000..fff8d813 --- /dev/null +++ b/deluser.conf @@ -0,0 +1,20 @@ +# /etc/deluser.conf: `deluser' configuration. + +# Remove home directory and mail spool when user is removed +REMOVE_HOME = 0 + +# Remove all files on the system owned by the user to be removed +REMOVE_ALL_FILES = 0 + +# Backup files before removing them. This options has only an effect if +# REMOVE_HOME or REMOVE_ALL_FILES is set. +BACKUP = 0 + +# target directory for the backup file +BACKUP_TO = "." + +# delete a group even there are still users in this group +ONLY_IF_EMPTY = 0 + +# exclude these filesystem types when searching for files of a user to backup +EXCLUDE_FSTYPES = "(proc|sysfs|usbfs|devpts|tmpfs|afs)" diff --git a/dhcp/debug b/dhcp/debug new file mode 100644 index 00000000..593e7df2 --- /dev/null +++ b/dhcp/debug @@ -0,0 +1,38 @@ +# +# The purpose of this script is just to show the variables that are +# available to all the scripts in this directory. All these scripts are +# called from dhclient-script, which exports all the variables shown +# before. If you want to debug a problem with your DHCP setup you can +# enable this script and take a look at /tmp/dhclient-script.debug. + +# To enable this script set the following variable to "yes" +RUN="no" + +if [ "$RUN" = "yes" ]; then + echo "$(date): entering ${1%/*}, dumping variables." \ + >> /tmp/dhclient-script.debug + + # loop over the 4 possible prefixes: (empty), cur_, new_, old_ + for prefix in '' 'cur_' 'new_' 'old_'; do + # loop over the DHCP variables passed to dhclient-script + for basevar in reason interface medium alias_ip_address \ + ip_address host_name network_number subnet_mask \ + broadcast_address routers static_routes \ + rfc3442_classless_static_routes \ + domain_name domain_search domain_name_servers \ + netbios_name_servers netbios_scope \ + ntp_servers \ + ip6_address ip6_prefix ip6_prefixlen \ + dhcp6_domain_search dhcp6_name_servers ; do + var="${prefix}${basevar}" + eval "content=\$$var" + + # show only variables with values set + if [ -n "${content}" ]; then + echo "$var='${content}'" >> /tmp/dhclient-script.debug + fi + done + done + + echo '--------------------------' >> /tmp/dhclient-script.debug +fi diff --git a/dhcp/dhclient-enter-hooks.d/debug b/dhcp/dhclient-enter-hooks.d/debug new file mode 120000 index 00000000..ee34fdcc --- /dev/null +++ b/dhcp/dhclient-enter-hooks.d/debug @@ -0,0 +1 @@ +../debug \ No newline at end of file diff --git a/dhcp/dhclient-exit-hooks.d/debug b/dhcp/dhclient-exit-hooks.d/debug new file mode 120000 index 00000000..ee34fdcc --- /dev/null +++ b/dhcp/dhclient-exit-hooks.d/debug @@ -0,0 +1 @@ +../debug \ No newline at end of file diff --git a/dhcp/dhclient-exit-hooks.d/hook-dhclient b/dhcp/dhclient-exit-hooks.d/hook-dhclient new file mode 100755 index 00000000..02122f37 --- /dev/null +++ b/dhcp/dhclient-exit-hooks.d/hook-dhclient @@ -0,0 +1,27 @@ +#!/bin/sh +# This file is part of cloud-init. See LICENSE file for license information. + +# This script writes DHCP lease information into the cloud-init run directory +# It is sourced, not executed. For more information see dhclient-script(8). + +is_azure() { + local dmi_path="/sys/class/dmi/id/board_vendor" vendor="" + if [ -e "$dmi_path" ] && read vendor < "$dmi_path"; then + [ "$vendor" = "Microsoft Corporation" ] && return 0 + fi + return 1 +} + +is_enabled() { + # only execute hooks if cloud-init is enabled and on azure + [ -e /run/cloud-init/enabled ] || return 1 + is_azure +} + +if is_enabled; then + case "$reason" in + BOUND) cloud-init dhclient-hook up "$interface";; + DOWN|RELEASE|REBOOT|STOP|EXPIRE) + cloud-init dhclient-hook down "$interface";; + esac +fi diff --git a/dhcp/dhclient-exit-hooks.d/rfc3442-classless-routes b/dhcp/dhclient-exit-hooks.d/rfc3442-classless-routes new file mode 100644 index 00000000..1ef7b8a2 --- /dev/null +++ b/dhcp/dhclient-exit-hooks.d/rfc3442-classless-routes @@ -0,0 +1,78 @@ +# set classless routes based on the format specified in RFC3442 +# e.g.: +# new_rfc3442_classless_static_routes='24 192 168 10 192 168 1 1 8 10 10 17 66 41' +# specifies the routes: +# 192.168.10.0/24 via 192.168.1.1 +# 10.0.0.0/8 via 10.10.17.66.41 + +RUN="yes" + + +if [ "$RUN" = "yes" ]; then + if [ -n "$new_rfc3442_classless_static_routes" ]; then + if [ "$reason" = "BOUND" ] || [ "$reason" = "REBOOT" ]; then + + set -- $new_rfc3442_classless_static_routes + + while [ $# -gt 0 ]; do + net_length=$1 + via_arg='' + + case $net_length in + 32|31|30|29|28|27|26|25) + if [ $# -lt 9 ]; then + return 1 + fi + net_address="${2}.${3}.${4}.${5}" + gateway="${6}.${7}.${8}.${9}" + shift 9 + ;; + 24|23|22|21|20|19|18|17) + if [ $# -lt 8 ]; then + return 1 + fi + net_address="${2}.${3}.${4}.0" + gateway="${5}.${6}.${7}.${8}" + shift 8 + ;; + 16|15|14|13|12|11|10|9) + if [ $# -lt 7 ]; then + return 1 + fi + net_address="${2}.${3}.0.0" + gateway="${4}.${5}.${6}.${7}" + shift 7 + ;; + 8|7|6|5|4|3|2|1) + if [ $# -lt 6 ]; then + return 1 + fi + net_address="${2}.0.0.0" + gateway="${3}.${4}.${5}.${6}" + shift 6 + ;; + 0) # default route + if [ $# -lt 5 ]; then + return 1 + fi + net_address="0.0.0.0" + gateway="${2}.${3}.${4}.${5}" + shift 5 + ;; + *) # error + return 1 + ;; + esac + + # take care of link-local routes + if [ "${gateway}" != '0.0.0.0' ]; then + via_arg="via ${gateway}" + fi + + # set route (ip detects host routes automatically) + ip -4 route add "${net_address}/${net_length}" \ + ${via_arg} dev "${interface}" >/dev/null 2>&1 + done + fi + fi +fi diff --git a/dhcp/dhclient-exit-hooks.d/timesyncd b/dhcp/dhclient-exit-hooks.d/timesyncd new file mode 100644 index 00000000..bb98cab0 --- /dev/null +++ b/dhcp/dhclient-exit-hooks.d/timesyncd @@ -0,0 +1,52 @@ +TIMESYNCD_CONF=/run/systemd/timesyncd.conf.d/01-dhclient.conf + +timesyncd_servers_setup_remove() { + if [ ! -d /run/systemd/system ]; then + return + fi + if [ ! -x /lib/systemd/systemd-timesyncd ]; then + return + fi + + if [ -e $TIMESYNCD_CONF ]; then + rm -f $TIMESYNCD_CONF + systemctl try-restart systemd-timesyncd.service || true + fi +} + +timesyncd_servers_setup_add() { + if [ ! -d /run/systemd/system ]; then + return + fi + if [ ! -x /lib/systemd/systemd-timesyncd ]; then + return + fi + + if [ -e $TIMESYNCD_CONF ] && [ "$new_ntp_servers" = "$old_ntp_servers" ]; then + return + fi + + if [ -z "$new_ntp_servers" ]; then + timesyncd_servers_setup_remove + return + fi + + mkdir -p $(dirname $TIMESYNCD_CONF) + cat < ${TIMESYNCD_CONF}.new +# NTP server entries received from DHCP server +[Time] +NTP=$new_ntp_servers +EOF + mv ${TIMESYNCD_CONF}.new ${TIMESYNCD_CONF} + systemctl try-restart systemd-timesyncd.service || true +} + + +case $reason in + BOUND|RENEW|REBIND|REBOOT) + timesyncd_servers_setup_add + ;; + EXPIRE|FAIL|RELEASE|STOP) + timesyncd_servers_setup_remove + ;; +esac diff --git a/dhcp/dhclient.conf b/dhcp/dhclient.conf new file mode 100644 index 00000000..b85301b1 --- /dev/null +++ b/dhcp/dhclient.conf @@ -0,0 +1,54 @@ +# Configuration file for /sbin/dhclient. +# +# This is a sample configuration file for dhclient. See dhclient.conf's +# man page for more information about the syntax of this file +# and a more comprehensive list of the parameters understood by +# dhclient. +# +# Normally, if the DHCP server provides reasonable information and does +# not leave anything out (like the domain name, for example), then +# few changes must be made to this file, if any. +# + +option rfc3442-classless-static-routes code 121 = array of unsigned integer 8; + +send host-name = gethostname(); +request subnet-mask, broadcast-address, time-offset, routers, + domain-name, domain-name-servers, domain-search, host-name, + dhcp6.name-servers, dhcp6.domain-search, dhcp6.fqdn, dhcp6.sntp-servers, + netbios-name-servers, netbios-scope, interface-mtu, + rfc3442-classless-static-routes, ntp-servers; + +#send dhcp-client-identifier 1:0:a0:24:ab:fb:9c; +#send dhcp-lease-time 3600; +#supersede domain-name "fugue.com home.vix.com"; +#prepend domain-name-servers 127.0.0.1; +#require subnet-mask, domain-name-servers; +#timeout 60; +#retry 60; +#reboot 10; +#select-timeout 5; +#initial-interval 2; +#script "/sbin/dhclient-script"; +#media "-link0 -link1 -link2", "link0 link1"; +#reject 192.33.137.209; + +#alias { +# interface "eth0"; +# fixed-address 192.5.5.213; +# option subnet-mask 255.255.255.255; +#} + +#lease { +# interface "eth0"; +# fixed-address 192.33.137.200; +# medium "link0 link1"; +# option host-name "andare.swiftmedia.com"; +# option subnet-mask 255.255.255.0; +# option broadcast-address 192.33.137.255; +# option routers 192.33.137.250; +# option domain-name-servers 127.0.0.1; +# renew 2 2000/1/12 00:00:01; +# rebind 2 2000/1/12 00:00:01; +# expire 2 2000/1/12 00:00:01; +#} diff --git a/dictionaries-common/default.aff b/dictionaries-common/default.aff new file mode 120000 index 00000000..3be1bad6 --- /dev/null +++ b/dictionaries-common/default.aff @@ -0,0 +1 @@ +/usr/lib/ispell/american.aff \ No newline at end of file diff --git a/dictionaries-common/default.hash b/dictionaries-common/default.hash new file mode 120000 index 00000000..e9d3a0fb --- /dev/null +++ b/dictionaries-common/default.hash @@ -0,0 +1 @@ +/usr/lib/ispell/american.hash \ No newline at end of file diff --git a/dictionaries-common/ispell-default b/dictionaries-common/ispell-default new file mode 120000 index 00000000..f4b786ea --- /dev/null +++ b/dictionaries-common/ispell-default @@ -0,0 +1 @@ +/var/cache/dictionaries-common/ispell-default \ No newline at end of file diff --git a/dictionaries-common/words b/dictionaries-common/words new file mode 120000 index 00000000..1d20e7ed --- /dev/null +++ b/dictionaries-common/words @@ -0,0 +1 @@ +/usr/share/dict/american-english \ No newline at end of file diff --git a/discover-modprobe.conf b/discover-modprobe.conf new file mode 100644 index 00000000..713c3e63 --- /dev/null +++ b/discover-modprobe.conf @@ -0,0 +1,13 @@ + +# $Progeny$ + +# Load modules for the following device types. Specify "all" +# to detect all device types. +types="all" + +# Don't ever load the foo, bar, or baz modules. +#skip="foo bar baz" + +# Lines below this point have been automatically added by +# discover-modprobe(8) to disable the loading of modules that have +# previously crashed the machine: diff --git a/discover.conf.d/00discover b/discover.conf.d/00discover new file mode 100644 index 00000000..69ec3a19 --- /dev/null +++ b/discover.conf.d/00discover @@ -0,0 +1,15 @@ + + + + + + + + + + + + + + + diff --git a/dkimkeys/README.PrivateKeys b/dkimkeys/README.PrivateKeys new file mode 100644 index 00000000..1e9104aa --- /dev/null +++ b/dkimkeys/README.PrivateKeys @@ -0,0 +1,14 @@ +This directory is for storing private keys associated with DKIM signing with +opendkim. + +Here is advice from upstream + +(4) Store the private key in a safe place. We generally use a path like + /var/db/dkim/SELECTOR.key.pem (where "SELECTOR" is the name you chose). + The /var/db/dkim directory and the associated .pem file should be owned by + the user that will be executing the filter (preferably not the + superuser) and be mode 0700 and 0600 respectively. + +In Debian, we use /etc/dkimkeys by default and the directory permissions and +ownership are set correctly. Ensure that the private key is owned by the +opendkim user and the permissions are 0600. diff --git a/dkms/framework.conf b/dkms/framework.conf new file mode 100644 index 00000000..852f3b7c --- /dev/null +++ b/dkms/framework.conf @@ -0,0 +1,28 @@ +## This configuration file modifies the behavior of +## DKMS (Dynamic Kernel Module Support) and is sourced +## in by DKMS every time it is run. + +## Source Tree Location (default: /usr/src) +# source_tree="/usr/src" + +## DKMS Tree Location (default: /var/lib/dkms) +# dkms_tree="/var/lib/dkms" + +## Install Tree Location (default: /lib/modules) +# install_tree="/lib/modules" + +## tmp Location (default: /tmp) +# tmp_location="/tmp" + +## verbosity setting (verbose will be active if you set it to a non-null value) +# verbose="" + +## symlink kernel modules (will be active if you set it to a non-null value) +## This creates symlinks from the install_tree into the dkms_tree instead of +## copying the modules. This preserves some space on the costs of being less +## safe. +# symlink_modules="" + +## Automatic installation and upgrade for all installed kernels (if set to a +## non-null value) +# autoinstall_all_kernels="" diff --git a/dkms/template-dkms-mkbmdeb/Makefile b/dkms/template-dkms-mkbmdeb/Makefile new file mode 100644 index 00000000..210b9984 --- /dev/null +++ b/dkms/template-dkms-mkbmdeb/Makefile @@ -0,0 +1,18 @@ +#/usr/bin/make +SRC = $(DESTDIR)/usr/src +SHARE = $(DESTDIR)/usr/share/$(NAME)-dkms + +all: + +clean: + +install: + +#tarball, possibly with binaries +ifeq ("$(wildcard $(NAME)-$(VERSION).dkms.tar.gz)", "$(NAME)-$(VERSION).dkms.tar.gz") + tar zxvf "$(NAME)-$(VERSION).dkms.tar.gz" + install -d "$(DESTDIR)/lib/modules/$(KVER)/updates/dkms/" + install -m 644 dkms_main_tree/$(KVER)/$(KARCH)/module/*.ko "$(DESTDIR)/lib/modules/$(KVER)/updates/dkms/" + rm -rf dkms_main_tree/ dkms_binaries_only/ +endif + diff --git a/dkms/template-dkms-mkbmdeb/debian/README.Debian b/dkms/template-dkms-mkbmdeb/debian/README.Debian new file mode 100644 index 00000000..f8495d91 --- /dev/null +++ b/dkms/template-dkms-mkbmdeb/debian/README.Debian @@ -0,0 +1,5 @@ +MODULE_NAME DKMS module for Debian + +This package was automatically generated by the DKMS system, +for distribution on Debian based operating systems. + diff --git a/dkms/template-dkms-mkbmdeb/debian/changelog b/dkms/template-dkms-mkbmdeb/debian/changelog new file mode 100644 index 00000000..b6cc91d8 --- /dev/null +++ b/dkms/template-dkms-mkbmdeb/debian/changelog @@ -0,0 +1,6 @@ +DEBIAN_PACKAGE-dkms-bin (MODULE_VERSION) stable; urgency=low + + * Automatically packaged by DKMS. + + -- Dynamic Kernel Modules Support Team DATE_STAMP + diff --git a/dkms/template-dkms-mkbmdeb/debian/compat b/dkms/template-dkms-mkbmdeb/debian/compat new file mode 100644 index 00000000..7f8f011e --- /dev/null +++ b/dkms/template-dkms-mkbmdeb/debian/compat @@ -0,0 +1 @@ +7 diff --git a/dkms/template-dkms-mkbmdeb/debian/control b/dkms/template-dkms-mkbmdeb/debian/control new file mode 100644 index 00000000..ef239751 --- /dev/null +++ b/dkms/template-dkms-mkbmdeb/debian/control @@ -0,0 +1,14 @@ +Source: DEBIAN_PACKAGE-dkms-bin +Section: misc +Priority: optional +Maintainer: Dynamic Kernel Modules Support Team +Build-Depends: debhelper (>= 7), dkms +Standards-Version: 3.8.1 + +Package: DEBIAN_PACKAGE-modules-KERNEL_VERSION +Architecture: DEBIAN_BUILD_ARCH +Depends: ${misc:Depends}, linux-image-KERNEL_VERSION +Provides: DEBIAN_PACKAGE-modules +Description: DEBIAN_PACKAGE binary drivers for linux-image-KERNEL_VERSION + This package contains DEBIAN_PACKAGE drivers for the KERNEL_VERSION Linux kernel, + built from DEBIAN_PACKAGE-dkms for the DEBIAN_BUILD_ARCH architecture. diff --git a/dkms/template-dkms-mkbmdeb/debian/copyright b/dkms/template-dkms-mkbmdeb/debian/copyright new file mode 100644 index 00000000..ad983f3d --- /dev/null +++ b/dkms/template-dkms-mkbmdeb/debian/copyright @@ -0,0 +1,2 @@ + +This copyright has not been completed by the author of this package. diff --git a/dkms/template-dkms-mkbmdeb/debian/rules b/dkms/template-dkms-mkbmdeb/debian/rules new file mode 100755 index 00000000..5cd07317 --- /dev/null +++ b/dkms/template-dkms-mkbmdeb/debian/rules @@ -0,0 +1,58 @@ +#!/usr/bin/make -f +# -*- makefile -*- + +# Uncomment this to turn on verbose mode. +#export DH_VERBOSE=1 + +DEB_NAME=DEBIAN_PACKAGE +NAME=MODULE_NAME +VERSION=MODULE_VERSION +KVER=KERNEL_VERSION + +configure: configure-stamp +configure-stamp: + dh_testdir + touch configure-stamp + + +build: build-stamp + +build-stamp: configure-stamp + dh_testdir + $(MAKE) + touch $@ + +clean: + dh_testdir + dh_testroot + rm -f build-stamp configure-stamp + -$(MAKE) clean + dh_clean + +install: build + dh_testdir + dh_testroot + dh_prep + dh_installdirs + $(MAKE) DESTDIR=$(CURDIR)/debian/$(DEB_NAME)-modules-$(KVER) NAME=$(NAME) VERSION=$(VERSION) install + +binary-arch: build install + +binary-indep: build install + dh_testdir + dh_testroot + dh_link + dh_strip + dh_compress + dh_installmodules + dh_installdocs + dh_installchangelogs + dh_fixperms + dh_installdeb + dh_shlibdeps + dh_gencontrol + dh_md5sums + dh_builddeb + +binary: binary-indep binary-arch +.PHONY: build clean binary-indep binary-arch binary install configure diff --git a/dkms/template-dkms-mkdeb/Makefile b/dkms/template-dkms-mkdeb/Makefile new file mode 100644 index 00000000..57e13d83 --- /dev/null +++ b/dkms/template-dkms-mkdeb/Makefile @@ -0,0 +1,28 @@ +#/usr/bin/make +SRC = $(DESTDIR)/usr/src +SHARE = $(DESTDIR)/usr/share/$(NAME)-dkms + +all: + +clean: + +install: + +#source tree +ifeq ("$(wildcard $(NAME)-$(VERSION))", "$(NAME)-$(VERSION)") + install -d "$(SRC)" + cp -a $(NAME)-$(VERSION) $(SRC) + chmod 644 -R "$(SRC)/$(NAME)-$(VERSION)" +endif + +#tarball, possibly with binaries +ifeq ("$(wildcard $(NAME)-$(VERSION).dkms.tar.gz)", "$(NAME)-$(VERSION).dkms.tar.gz") + install -d "$(SHARE)" + install -m 644 $(NAME)-$(VERSION).dkms.tar.gz "$(SHARE)" +endif + +#postinst, only if we are supporting legacy mode +ifeq ("$(wildcard common.postinst)", "common.postinst") + install -d "$(SHARE)" + install -m 755 $(PREFIX)/usr/lib/dkms/common.postinst $(SHARE)/postinst +endif diff --git a/dkms/template-dkms-mkdeb/debian/README.Debian b/dkms/template-dkms-mkdeb/debian/README.Debian new file mode 100644 index 00000000..f8495d91 --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/README.Debian @@ -0,0 +1,5 @@ +MODULE_NAME DKMS module for Debian + +This package was automatically generated by the DKMS system, +for distribution on Debian based operating systems. + diff --git a/dkms/template-dkms-mkdeb/debian/changelog b/dkms/template-dkms-mkdeb/debian/changelog new file mode 100644 index 00000000..2434da03 --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/changelog @@ -0,0 +1,6 @@ +DEBIAN_PACKAGE-dkms (MODULE_VERSION) stable; urgency=low + + * Automatically packaged by DKMS. + + -- Dynamic Kernel Modules Support Team DATE_STAMP + diff --git a/dkms/template-dkms-mkdeb/debian/compat b/dkms/template-dkms-mkdeb/debian/compat new file mode 100644 index 00000000..7f8f011e --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/compat @@ -0,0 +1 @@ +7 diff --git a/dkms/template-dkms-mkdeb/debian/control b/dkms/template-dkms-mkdeb/debian/control new file mode 100644 index 00000000..e561c006 --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/control @@ -0,0 +1,11 @@ +Source: DEBIAN_PACKAGE-dkms +Section: misc +Priority: optional +Maintainer: Dynamic Kernel Modules Support Team +Build-Depends: debhelper (>= 7), dkms +Standards-Version: 3.8.1 + +Package: DEBIAN_PACKAGE-dkms +Architecture: all +Depends: dkms (>= 1.95), ${misc:Depends} +Description: DEBIAN_PACKAGE driver in DKMS format. diff --git a/dkms/template-dkms-mkdeb/debian/copyright b/dkms/template-dkms-mkdeb/debian/copyright new file mode 100644 index 00000000..ad983f3d --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/copyright @@ -0,0 +1,2 @@ + +This copyright has not been completed by the author of this package. diff --git a/dkms/template-dkms-mkdeb/debian/dirs b/dkms/template-dkms-mkdeb/debian/dirs new file mode 100644 index 00000000..b601f22c --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/dirs @@ -0,0 +1 @@ +usr/src diff --git a/dkms/template-dkms-mkdeb/debian/postinst b/dkms/template-dkms-mkdeb/debian/postinst new file mode 100755 index 00000000..c4ad0da4 --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/postinst @@ -0,0 +1,49 @@ +#!/bin/sh +# Copyright (C) 2002-2005 Flavio Stanchina +# Copyright (C) 2005-2006 Aric Cyr +# Copyright (C) 2007 Mario Limonciello +# Copyright (C) 2009 Alberto Milone + +set -e + +NAME=MODULE_NAME +PACKAGE_NAME=$NAME-dkms +DEB_NAME=$(echo $PACKAGE_NAME | sed 's,_,-,') +CVERSION=`dpkg-query -W -f='${Version}' $DEB_NAME | awk -F "-" '{print $1}' | cut -d\: -f2` +ARCH=`dpkg --print-architecture` + +dkms_configure () { + for POSTINST in /usr/lib/dkms/common.postinst "/usr/share/$PACKAGE_NAME/postinst"; do + if [ -f "$POSTINST" ]; then + "$POSTINST" "$NAME" "$CVERSION" "/usr/share/$PACKAGE_NAME" "$ARCH" "$2" + return $? + fi + echo "WARNING: $POSTINST does not exist." >&2 + done + echo "ERROR: DKMS version is too old and $PACKAGE_NAME was not" >&2 + echo "built with legacy DKMS support." >&2 + echo "You must either rebuild $PACKAGE_NAME with legacy postinst" >&2 + echo "support or upgrade DKMS to a more current version." >&2 + return 1 +} + +case "$1" in + configure) + dkms_configure + ;; + + abort-upgrade|abort-remove|abort-deconfigure) + ;; + + *) + echo "postinst called with unknown argument \`$1'" >&2 + exit 1 + ;; +esac + +# dh_installdeb will replace this with shell code automatically +# generated by other debhelper scripts. + +#DEBHELPER# + +exit 0 diff --git a/dkms/template-dkms-mkdeb/debian/prerm b/dkms/template-dkms-mkdeb/debian/prerm new file mode 100755 index 00000000..f42d2931 --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/prerm @@ -0,0 +1,28 @@ +#!/bin/sh + +NAME=MODULE_NAME +VERSION=MODULE_VERSION + +set -e + +case "$1" in + remove|upgrade|deconfigure) + if [ "`dkms status -m $NAME`" ]; then + dkms remove -m $NAME -v $VERSION --all + fi + ;; + + failed-upgrade) + ;; + + *) + echo "prerm called with unknown argument \`$1'" >&2 + exit 1 + ;; +esac + +#DEBHELPER# + +exit 0 + + diff --git a/dkms/template-dkms-mkdeb/debian/rules b/dkms/template-dkms-mkdeb/debian/rules new file mode 100755 index 00000000..7426e582 --- /dev/null +++ b/dkms/template-dkms-mkdeb/debian/rules @@ -0,0 +1,54 @@ +#!/usr/bin/make -f +# -*- makefile -*- + +# Uncomment this to turn on verbose mode. +#export DH_VERBOSE=1 + +DEB_NAME=DEBIAN_PACKAGE +NAME=MODULE_NAME +VERSION=MODULE_VERSION + +configure: configure-stamp +configure-stamp: + dh_testdir + touch configure-stamp + + +build: build-stamp + +build-stamp: configure-stamp + dh_testdir + $(MAKE) + touch $@ + +clean: + dh_testdir + dh_testroot + rm -f build-stamp configure-stamp + -$(MAKE) clean + dh_clean + +install: build + dh_testdir + dh_testroot + dh_prep + dh_installdirs + $(MAKE) DESTDIR=$(CURDIR)/debian/$(DEB_NAME)-dkms NAME=$(NAME) VERSION=$(VERSION) install + +binary-arch: build install + +binary-indep: build install + dh_testdir + dh_testroot + dh_link + dh_strip + dh_compress + dh_fixperms + dh_installdeb + dh_shlibdeps + dh_gencontrol + dh_md5sums + dh_builddeb + +binary: binary-indep binary-arch +.PHONY: build clean binary-indep binary-arch binary install configure diff --git a/dkms/template-dkms-mkdsc b/dkms/template-dkms-mkdsc new file mode 120000 index 00000000..7b791213 --- /dev/null +++ b/dkms/template-dkms-mkdsc @@ -0,0 +1 @@ +template-dkms-mkdeb \ No newline at end of file diff --git a/dovecot/conf.d/10-ssl.conf b/dovecot/conf.d/10-ssl.conf new file mode 100644 index 00000000..9535c9a5 --- /dev/null +++ b/dovecot/conf.d/10-ssl.conf @@ -0,0 +1,71 @@ +## +## SSL settings +## + +# SSL/TLS support: yes, no, required. +ssl = yes + +# PEM encoded X.509 SSL/TLS certificate and private key. They're opened before +# dropping root privileges, so keep the key file unreadable by anyone but +# root. Included doc/mkcert.sh can be used to easily generate self-signed +# certificate, just make sure to update the domains in dovecot-openssl.cnf +#ssl_cert = :]path[;