it-systeme

christoph ender it operations · networking · software development

about

Hi there! These pages are intended to share notes and experiences from my work as an IT freelancer – yes, you can hire me – working in OPs, networking and development.
→ read more …

contact

mobile: +49 (0)171 1592365
e-mail: christoph.ender@it-sys-ce.de
pgp: 0fe1e446f585711c3d56d45154f51a402f3c6660 2f3c6660
mastodon: @chrender@mastodon.social

latest blog entry: “wireguard-before-ssh”

It's time. After several incidents – terrapin, openssh/xz and the signalhandler/race-condition – all within the timespan of a single year, I've started rolling out servers which have their ssh port bound to a wireguard interface. Which means that without authenticating and connecting via wireguard first, the ssh port is not accessible from the public internet.

→ read more …