Linux Privacy: Difference between revisions
Appearance
No edit summary |
No edit summary |
||
| Line 12: | Line 12: | ||
Restart. | Restart. | ||
== Systemd-resolved == | |||
=== DNS over TLS === | |||
[[nano]] /etc/systemd/resolved.conf | |||
DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net | |||
FallbackDNS=1.1.1.1#cloudflare-dns.com 9.9.9.9#dns.quad9.net 8.8.8.8#dns.google 2606:4700:4700::1111#cloudflare-dns.com 2620:fe::9#dns.quad9.net 2001:4860:4860::8888#dns.google | |||
== Apache == | == Apache == | ||
Revision as of 05:08, 10 May 2026
Environment Variables
sudo nano /etc/environment
DO_NOT_TRACK=1 DOTNET_CLI_TELEMETRY_OPTOUT=1 SAM_CLI_TELEMETRY=0 AZURE_CORE_COLLECT_TELEMETRY=0 GATSBY_TELEMETRY_DISABLED=1 HOMEBREW_NO_ANALYTICS=1 NEXT_TELEMETRY_DISABLED=1 GH_TELEMETRY=false
Restart.
Systemd-resolved
DNS over TLS
nano /etc/systemd/resolved.conf
DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net FallbackDNS=1.1.1.1#cloudflare-dns.com 9.9.9.9#dns.quad9.net 8.8.8.8#dns.google 2606:4700:4700::1111#cloudflare-dns.com 2620:fe::9#dns.quad9.net 2001:4860:4860::8888#dns.google
Apache
Add or update the following to your main Apache config, this will limit your server to only serving pages with TLS 1.3. See [here](https://caniuse.com/tls1-3) for browser support. Older Windows 7 clients will need TLS 1.2 and ancient Windows XP era clients will need TLS 1.0/1.1
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 -TLSv1.2 SSLHonorCipherOrder off SSLSessionTickets off SSLUseStapling On SSLStaplingCache "shmcb:logs/ssl_stapling(32768)"
Nginx
Add or update the following to your nginx server {} block, this will limit your server to only serving pages with TLS 1.3. See [here](https://caniuse.com/tls1-3) for browser support.
ssl_session_timeout 1d; ssl_session_cache shared:MozSSL:10m; # about 40000 sessions ssl_session_tickets off; ssl_protocols TLSv1.3; ssl_prefer_server_ciphers off;
HTTP Testing
You can test your configuration, and possibly get extra information by testing with the following tools
Mozilla Observatory https://observatory.mozilla.org
Qualys SSL Labs Test https://www.ssllabs.com/ssltest/