Linux Privacy: Difference between revisions
Created page with "== Environment Variables == sudo nano /etc/environmen DOTNET_CLI_TELEMETRY_OPTOUT=1 SAM_CLI_TELEMETRY=0 AZURE_CORE_COLLECT_TELEMETRY=0 GATSBY_TELEMETRY_DISABLED=1 HOMEBREW_NO_ANALYTICS=1 DO_NOT_TRACK=1 Restart." |
|||
| (7 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
== Environment Variables == | == Environment Variables == | ||
sudo [[nano]] /etc/environment | |||
DO_NOT_TRACK=1 | |||
DOTNET_CLI_TELEMETRY_OPTOUT=1 | DOTNET_CLI_TELEMETRY_OPTOUT=1 | ||
SAM_CLI_TELEMETRY=0 | SAM_CLI_TELEMETRY=0 | ||
| Line 8: | Line 8: | ||
GATSBY_TELEMETRY_DISABLED=1 | GATSBY_TELEMETRY_DISABLED=1 | ||
HOMEBREW_NO_ANALYTICS=1 | HOMEBREW_NO_ANALYTICS=1 | ||
NEXT_TELEMETRY_DISABLED=1 | |||
GH_TELEMETRY=false | |||
Restart. | Restart. | ||
== Systemd-resolved == | |||
=== DNS over TLS === | |||
sudo [[nano]] /etc/systemd/resolved.conf | |||
Add/edit | |||
DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net | |||
FallbackDNS=1.1.1.1#cloudflare-dns.com 9.9.9.9#dns.quad9.net 8.8.8.8#dns.google 2606:4700:4700::1111#cloudflare-dns.com 2620:fe::9#dns.quad9.net 2001:4860:4860::8888#dns.google | |||
DNSOverTLS=yes | |||
=== DNSSEC === | |||
This will only benefit you if the domain owner has set up DNSSEC, but those domains records can be cryptographically confirmed to be authentic. | |||
sudo [[nano]] /etc/systemd/resolved.conf | |||
Add/edit | |||
DNSSEC=yes | |||
== Apache == | |||
Add or update the following to your main Apache config, this will limit your server to only serving pages with TLS 1.3. See <nowiki>https://caniuse.com/tls1-3</nowiki> for browser support. Older Windows 7 clients will need TLS 1.2 and ancient Windows XP era clients will need TLS 1.0/1.1 | |||
sudo [[nano]] /etc/apache2/conf-enabled/security.conf | |||
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 -TLSv1.2 | |||
SSLHonorCipherOrder off | |||
SSLSessionTickets off | |||
SSLUseStapling On | |||
SSLStaplingCache "shmcb:logs/ssl_stapling(32768)" | |||
== Nginx == | |||
Add or update the following to your nginx server {} block, this will limit your server to only serving pages with TLS 1.3. See [here](<nowiki>https://caniuse.com/tls1-3</nowiki>) for browser support. | |||
ssl_session_timeout 1d; | |||
ssl_session_cache shared:MozSSL:10m; # about 40000 sessions | |||
ssl_session_tickets off; | |||
ssl_protocols TLSv1.3; | |||
ssl_prefer_server_ciphers off; | |||
== HTTP Testing == | |||
You can test your configuration, and possibly get extra information by testing with the following tools | |||
Mozilla Observatory https://observatory.mozilla.org | |||
Qualys SSL Labs Test https://www.ssllabs.com/ssltest/ | |||
Latest revision as of 05:14, 10 May 2026
Environment Variables
sudo nano /etc/environment
DO_NOT_TRACK=1 DOTNET_CLI_TELEMETRY_OPTOUT=1 SAM_CLI_TELEMETRY=0 AZURE_CORE_COLLECT_TELEMETRY=0 GATSBY_TELEMETRY_DISABLED=1 HOMEBREW_NO_ANALYTICS=1 NEXT_TELEMETRY_DISABLED=1 GH_TELEMETRY=false
Restart.
Systemd-resolved
DNS over TLS
sudo nano /etc/systemd/resolved.conf
Add/edit
DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net FallbackDNS=1.1.1.1#cloudflare-dns.com 9.9.9.9#dns.quad9.net 8.8.8.8#dns.google 2606:4700:4700::1111#cloudflare-dns.com 2620:fe::9#dns.quad9.net 2001:4860:4860::8888#dns.google
DNSOverTLS=yes
DNSSEC
This will only benefit you if the domain owner has set up DNSSEC, but those domains records can be cryptographically confirmed to be authentic.
sudo nano /etc/systemd/resolved.conf
Add/edit
DNSSEC=yes
Apache
Add or update the following to your main Apache config, this will limit your server to only serving pages with TLS 1.3. See https://caniuse.com/tls1-3 for browser support. Older Windows 7 clients will need TLS 1.2 and ancient Windows XP era clients will need TLS 1.0/1.1
sudo nano /etc/apache2/conf-enabled/security.conf
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 -TLSv1.2 SSLHonorCipherOrder off SSLSessionTickets off SSLUseStapling On SSLStaplingCache "shmcb:logs/ssl_stapling(32768)"
Nginx
Add or update the following to your nginx server {} block, this will limit your server to only serving pages with TLS 1.3. See [here](https://caniuse.com/tls1-3) for browser support.
ssl_session_timeout 1d; ssl_session_cache shared:MozSSL:10m; # about 40000 sessions ssl_session_tickets off; ssl_protocols TLSv1.3; ssl_prefer_server_ciphers off;
HTTP Testing
You can test your configuration, and possibly get extra information by testing with the following tools
Mozilla Observatory https://observatory.mozilla.org
Qualys SSL Labs Test https://www.ssllabs.com/ssltest/