Jump to content

Linux Privacy: Difference between revisions

From SameTeem
No edit summary
No edit summary
Line 12: Line 12:


Restart.
Restart.
== Systemd-resolved ==
=== DNS over TLS ===
[[nano]] /etc/systemd/resolved.conf
DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net
FallbackDNS=1.1.1.1#cloudflare-dns.com 9.9.9.9#dns.quad9.net 8.8.8.8#dns.google 2606:4700:4700::1111#cloudflare-dns.com 2620:fe::9#dns.quad9.net 2001:4860:4860::8888#dns.google


== Apache ==
== Apache ==

Revision as of 05:08, 10 May 2026

Environment Variables

sudo nano /etc/environment
DO_NOT_TRACK=1
DOTNET_CLI_TELEMETRY_OPTOUT=1 
SAM_CLI_TELEMETRY=0 
AZURE_CORE_COLLECT_TELEMETRY=0 
GATSBY_TELEMETRY_DISABLED=1 
HOMEBREW_NO_ANALYTICS=1 
NEXT_TELEMETRY_DISABLED=1
GH_TELEMETRY=false

Restart.

Systemd-resolved

DNS over TLS

nano /etc/systemd/resolved.conf
DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net 
FallbackDNS=1.1.1.1#cloudflare-dns.com 9.9.9.9#dns.quad9.net 8.8.8.8#dns.google 2606:4700:4700::1111#cloudflare-dns.com 2620:fe::9#dns.quad9.net 2001:4860:4860::8888#dns.google

Apache

Add or update the following to your main Apache config, this will limit your server to only serving pages with TLS 1.3. See [here](https://caniuse.com/tls1-3) for browser support. Older Windows 7 clients will need TLS 1.2 and ancient Windows XP era clients will need TLS 1.0/1.1

SSLProtocol             all -SSLv3 -TLSv1 -TLSv1.1 -TLSv1.2
SSLHonorCipherOrder     off
SSLSessionTickets       off
SSLUseStapling On
SSLStaplingCache "shmcb:logs/ssl_stapling(32768)"

Nginx

Add or update the following to your nginx server {} block, this will limit your server to only serving pages with TLS 1.3. See [here](https://caniuse.com/tls1-3) for browser support.

ssl_session_timeout 1d;
ssl_session_cache shared:MozSSL:10m;  # about 40000 sessions
ssl_session_tickets off;
ssl_protocols TLSv1.3;
ssl_prefer_server_ciphers off;

HTTP Testing

You can test your configuration, and possibly get extra information by testing with the following tools

Mozilla Observatory https://observatory.mozilla.org

Qualys SSL Labs Test https://www.ssllabs.com/ssltest/