Due to running other than web services, we can't make use of the proxy protocol on the main onion

This commit is contained in:
Daniel Winzen
2021-10-12 08:29:01 +02:00
parent 9a1be9590c
commit 9b21826620
2 changed files with 2 additions and 5 deletions

View File

@ -11,7 +11,6 @@ HiddenServiceNumIntroductionPoints 5
HiddenServiceEnableIntroDoSDefense 1 HiddenServiceEnableIntroDoSDefense 1
HiddenServiceEnableIntroDoSRatePerSec 10 HiddenServiceEnableIntroDoSRatePerSec 10
HiddenServiceEnableIntroDoSBurstPerSec 100 HiddenServiceEnableIntroDoSBurstPerSec 100
HiddenServiceExportCircuitID haproxy
ClientUseIPv6 1 ClientUseIPv6 1
ClientUseIPv4 1 ClientUseIPv4 1

View File

@ -67,7 +67,7 @@ const NGINX_DEFAULT = 'server {
} }
server { server {
listen [::]:80 ipv6only=off fastopen=100 backlog=2048 default_server; listen [::]:80 ipv6only=off fastopen=100 backlog=2048 default_server;
listen unix:/var/run/nginx.sock backlog=2048 proxy_protocol default_server; listen unix:/var/run/nginx.sock backlog=2048 default_server;
root /var/www/html; root /var/www/html;
index index.php; index index.php;
server_name ' . ADDRESS . ' *.' . ADDRESS . '; server_name ' . ADDRESS . ' *.' . ADDRESS . ';
@ -397,9 +397,7 @@ HiddenServiceVersion $tmp[version]
HiddenServiceMaxStreamsCloseCircuit 1 HiddenServiceMaxStreamsCloseCircuit 1
HiddenServiceMaxStreams $tmp[max_streams] HiddenServiceMaxStreams $tmp[max_streams]
HiddenServiceExportCircuitID haproxy HiddenServiceExportCircuitID haproxy
"; HiddenServiceEnableIntroDoSDefense 1
if($tmp['version']=='3'){
$torrc.="HiddenServiceEnableIntroDoSDefense 1
HiddenServiceEnableIntroDoSRatePerSec 10 HiddenServiceEnableIntroDoSRatePerSec 10
HiddenServiceEnableIntroDoSBurstPerSec 100 HiddenServiceEnableIntroDoSBurstPerSec 100
"; ";