From 20c24f5a035f01c8e96b73c53360420ed0f56b03 Mon Sep 17 00:00:00 2001 From: Jens Ahrensfeld Date: Mon, 20 Jul 2026 00:33:39 +0200 Subject: [PATCH] Fix accidental public-site lockout; document credential audit A stray /var/www/html/.htaccess (dated 2025-02-18, predating everything else in TODO.md) was silently requiring HTTP Basic Auth for jayfield.org and www.jayfield.org's shared DocumentRoot, 401ing every real visitor to the intentionally-public static site. Removed (backed up, not deleted). Also adds a README table auditing which public hostnames do/don't require credentials, prompted by checking this. --- README.md | 14 ++++++++++++++ TODO.md | 21 +++++++++++++++++++++ 2 files changed, 35 insertions(+) diff --git a/README.md b/README.md index 2de1cd7..b73dd9b 100644 --- a/README.md +++ b/README.md @@ -236,6 +236,20 @@ endpoint instead of a bespoke Apache-WebDAV + SFTP-upload pipeline: uses them anymore — reversible with `passwd -u` if SFTP is ever needed again. +## Public access / authentication overview + +Audited 2026-07-20 — which public hostnames require credentials: + +| Host | Requires credentials? | Notes | +|---|---|---| +| `jayfield.org` / `www.jayfield.org` | No (intentionally public static site) | Was accidentally 401'ing every visitor via a stray `.htaccess` — fixed, see `TODO.md` | +| `dyndns.jayfield.org` | Yes — HTTP Basic Auth | Vhost-level `` block, intentional | +| `mail.jayfield.org` | N/A — root is `403` (no content served there) | | +| `mail.jayfield.org/rspamd` | Yes — rspamd's own login page | | +| `cloud.jayfield.org` (Nextcloud) | Yes — redirects to `/login` | | +| `portainer.jayfield.org` | Yes — admin account already initialized (`/api/users/admin/check` → `204`, no open setup wizard) | | +| `web.jayfield.org` | No | Currently just the stock nginx welcome page (no real content deployed yet), so nothing sensitive is exposed — but worth revisiting before real content goes there if it's meant to stay public | + ## Open items / known quirks - **Intranet migration from `vlda-01` (files, Gitea, Jellyfin, Dogecoin diff --git a/TODO.md b/TODO.md index 2cd8acf..f383a4d 100644 --- a/TODO.md +++ b/TODO.md @@ -3,6 +3,27 @@ Outstanding hardening items (see `README.md` for the full service overview). Nothing here is urgent; all are low-risk, no-downtime changes. +- [x] **Public static site (`jayfield.org`/`www.jayfield.org`) was 401'ing every visitor** — done 2026-07-20 + Found while auditing which services are reachable without credentials: + a stray `/var/www/html/.htaccess` (`AuthType Basic`, same + `AuthName "Restricted Content"`/`AuthUserFile /etc/apache2/.htpasswd` + as the intentional `dyndns.jayfield.org` protection) was silently + requiring login for the DocumentRoot both `jayfield.org` and + `www.jayfield.org` share — `/var/www` has `AllowOverride all`, so it + took effect with no vhost-level directive needed. File was dated + 2025-02-18 (`index.html`/`apache.html` themselves are from 2022) — + predates every other change in this doc by well over a year, almost + certainly a forgotten leftover rather than intentional, and + contradicts `README.md`'s own description of both as a public static + site. + Fixed: moved to `/root/removed-configs-backup/htaccess-var-www-html.` + (recoverable, not deleted — same convention as this file's other + removed-config backups). No Apache reload needed (`.htaccess` is + read per-request). Verified both `jayfield.org` and + `www.jayfield.org` now return `200` with real page content; + `dyndns.jayfield.org`'s own (intentional, vhost-level) Basic Auth is + untouched and still returns `401` without credentials. + - [x] **Lock down the dyndns TSIG key file permissions** — done 2026-07-19 `/etc/bind/dyndns.jayfield.org.key` was `644` (world-readable), holding the shared secret that authenticates dynamic DNS updates for