X-Git-Url: https://jfr.im/git/irc/rqf/shadowircd.git/blobdiff_plain/54015b5fea2584a35aa605ebe37217010b448cff..d1275a8fd6d1fb76ef0eb67e2be48f5f7208202e:/doc/reference.conf diff --git a/doc/reference.conf b/doc/reference.conf index be0c3a1..0b64947 100755 --- a/doc/reference.conf +++ b/doc/reference.conf @@ -6,7 +6,7 @@ * * Written by ejb, wcampbel, db, leeh and others * - * $Id: reference.conf 3446 2007-05-14 22:21:16Z jilles $ + * $Id: reference.conf 3582 2007-11-17 21:55:48Z jilles $ */ /* IMPORTANT NOTES: @@ -41,23 +41,31 @@ * Charybdis contains several extensions that are not enabled by default. * To use them, uncomment the lines below. * - * Restrict channel creation to logged in users -- createauthonly.so - * Account bans (+b $a[:mask]) -- extb_account.so - * Banned from another channel (+b $j:mask) -- extb_canjoin.so - * Other-channel bans (+b $c:mask) -- extb_channel.so - * Extended ban (+b $x:mask) -- extb_extgecos.so - * Oper bans (+b $o) -- extb_oper.so - * Realname (gecos) bans (+b $r:mask) -- extb_realname.so - * Server bans (+b $s:mask) -- extb_server.so - * HURT system -- hurt.so - * Host mangling (umode +h) -- ip_cloaking.so - * Find channel forwards -- m_findforwards.so - * /identify support -- m_identify.so - * Opers cannot be invisible (umode +i) -- no_oper_invis.so - * Far connection notices (snomask +F) -- sno_farconnect.so - * Remote k/d/g/x line active notices -- sno_globalkline.so - * Remote oper up notices -- sno_globaloper.so + * Emulates channel mode +-O (oper only) (+-iI $o) -- chm_operonly_compat.so + * Emulates channel mode +-R (quiet unreg) (+-q $~a) -- chm_quietunreg_compat.so + * Emulates channel mode +-S (ssl only) (+-b $~z) -- chm_sslonly_compat.so + * Restrict channel creation to logged in users -- createauthonly.so + * Account bans (+b $a[:mask]) -- extb_account.so + * Banned from another channel (+b $j:mask) -- extb_canjoin.so + * Other-channel bans (+b $c:mask) -- extb_channel.so + * Extended ban (+b $x:mask) -- extb_extgecos.so + * Oper bans (+b $o) -- extb_oper.so + * Realname (gecos) bans (+b $r:mask) -- extb_realname.so + * Server bans (+b $s:mask) -- extb_server.so + * SSL bans (+b $z) -- extb_ssl.so + * HURT system -- hurt.so + * Host mangling (umode +h) -- ip_cloaking.so + * Find channel forwards -- m_findforwards.so + * /identify support -- m_identify.so + * Opers cannot be invisible (umode +i) -- no_oper_invis.so + * Far connection notices (snomask +F) -- sno_farconnect.so + * Remote k/d/x line active notices -- sno_globalkline.so + * Remote oper up notices -- sno_globaloper.so + * /whois notifications (snomask +W) -- sno_whois.so */ +#loadmodule "extensions/chm_operonly_compat.so"; +#loadmodule "extensions/chm_quietunreg_compat.so"; +#loadmodule "extensions/chm_sslonly_compat.so"; #loadmodule "extensions/createauthonly.so"; #loadmodule "extensions/extb_account.so"; #loadmodule "extensions/extb_canjoin.so"; @@ -66,6 +74,7 @@ #loadmodule "extensions/extb_oper.so"; #loadmodule "extensions/extb_realname.so"; #loadmodule "extensions/extb_server.so"; +#loadmodule "extensions/extb_ssl.so"; #loadmodule "extensions/hurt.so"; #loadmodule "extensions/ip_cloaking.so"; #loadmodule "extensions/m_findforwards.so"; @@ -74,22 +83,18 @@ #loadmodule "extensions/sno_farconnect.so"; #loadmodule "extensions/sno_globalkline.so"; #loadmodule "extensions/sno_globaloper.so"; +#loadmodule "extensions/sno_whois.so"; /* serverinfo {}: Contains information about the server. (OLD M:) */ serverinfo { /* name: the name of our server */ name = "hades.arpa"; - /* use ts6: whether we want to use the TS6 protocol to other servers - * or not. - */ - use_ts6 = yes; - /* sid: the unique server id of our server. This must be three * characters long. The first character must be a digit [0-9], the * remaining two chars may be letters [A-Z] or digits [0-9]. * - * This must be specified even if use_ts6 is set to no. + * This parameter must be specified for the server to start. */ sid = "42X"; @@ -118,13 +123,27 @@ serverinfo { * This should be an ipv6 IP only. */ #vhost6 = "3ffe:80e8:546::2"; + + /* ssl_private_key: our ssl private key */ + ssl_private_key = "etc/test.key"; + + /* ssl_cert: certificate for our ssl server */ + ssl_cert = "etc/test.cert"; + + /* ssl_dh_params: DH parameters, generate with openssl dhparam -out dh.pem 1024 */ + ssl_dh_params = "etc/dh.pem"; + + /* ssld_count: number of ssld processes you want to start, if you have a really busy + * server, using N-1 where N is the number of cpu/cpu cores you have might be useful + */ + ssld_count = 1; - /* max_clients: this should be set to the maximum amount of clients - * that the server should support. Note that you should leave some - * file descriptors free for log files, server connections, ident - * lookups (if enabled), exceed_limit clients, etc. + /* default max clients: the default maximum number of clients + * allowed to connect. This can be changed once ircd has started by + * issuing: + * /quote set maxclients */ - max_clients = 1024; + default_max_clients = 1024; }; /* admin {}: contains admin information about the server. (OLD A:) */ @@ -145,7 +164,6 @@ log { * - operlog: /oper usage * - foperlog: failed /oper usage * - serverlog: server connects/disconnects - * - glinelog: glines * - klinelog: klines, etc * - killlog: kills * - operspylog: operspy usage @@ -156,7 +174,6 @@ log { fname_operlog = "logs/operlog"; #fname_foperlog = "logs/foperlog"; fname_serverlog = "logs/serverlog"; - fname_glinelog = "logs/glinelog"; #fname_klinelog = "logs/klinelog"; fname_killlog = "logs/killlog"; fname_operspylog = "logs/operspylog"; @@ -246,26 +263,37 @@ listen { /* port: the specific port to listen on. if no host is specified * before, it will listen on all available IPs. * + * sslport: the specific port to listen ssl connections on. if no + * host is specified before, it will listen on all available IPs. + * * ports are seperated via a comma, a range may be specified using ".." */ /* port: listen on all available IPs, ports 5000 and 6665 to 6669 */ port = 5000, 6665 .. 6669; + + /* sslport: listen for ssl connections on all available IPs, port 9999 */ + sslport = 9999; /* host: set a specific IP/host the ports after the line will listen * on. This may be ipv4 or ipv6. */ host = "1.2.3.4"; port = 7000, 7001; + sslport = 9000, 9001; host = "3ffe:1234:a:b:c::d"; port = 7002; + sslport = 9002; }; /* auth {}: allow users to connect to the ircd (OLD I:) */ auth { - /* user: the user@host allowed to connect. multiple IPv4/IPv6 user - * lines are permitted per auth block. + /* user: the user@host allowed to connect. Multiple IPv4/IPv6 user + * lines are permitted per auth block. This is matched against the + * hostname and IP address (using :: shortening for IPv6 and + * prepending a 0 if it starts with a colon) and can also use CIDR + * masks. */ user = "*@172.16.0.0/12"; user = "*test@123D:B567:*"; @@ -289,7 +317,6 @@ auth { * exceed_limit (old > flag) | allow user to exceed class user limits * kline_exempt (old ^ flag) | exempt this user from k/g/xlines&dnsbls * dnsbl_exempt | exempt this user from dnsbls - * gline_exempt (old _ flag) | exempt this user from glines * spambot_exempt | exempt this user from spambot checks * shide_exempt | exempt this user from serverhiding * jupe_exempt | exempt this user from generating @@ -378,11 +405,10 @@ operator "god" { * global_kill: allows local and remote users to be * /KILL'd (OLD 'O' flag) * remote: allows remote SQUIT and CONNECT (OLD 'R' flag) - * kline: allows KILL, KLINE and DLINE (OLD 'K' flag) + * kline: allows KLINE and DLINE (OLD 'K' flag) * unkline: allows UNKLINE and UNDLINE (OLD 'U' flag) - * gline: allows GLINE (OLD 'G' flag) * nick_changes: allows oper to see nickchanges (OLD 'N' flag) - * via usermode +n + * via snomask +n * rehash: allows oper to REHASH config (OLD 'H' flag) * die: allows DIE and RESTART (OLD 'D' flag) * admin: gives admin privileges. admins @@ -392,13 +418,15 @@ operator "god" { * will not have the admin lines in * stats p and whois. * xline: allows use of /quote xline/unxline - * operwall: allows the oper to send operwalls [DEFAULT] + * resv: allows /quote resv/unresv and cmode +LP [DEFAULT] + * operwall: allows the oper to send/receive operwalls [DEFAULT] * oper_spy: allows 'operspy' features to see through +s * channels etc. see /quote help operspy * hidden_oper: hides the oper from /stats p (OLD UMODE +p) * remoteban: allows remote kline etc [DEFAULT] + * mass_notice: allows sending wallops and mass notices [DEFAULT] */ - flags = global_kill, remote, kline, unkline, gline, + flags = global_kill, remote, kline, unkline, die, rehash, admin, xline, operwall; }; @@ -443,11 +471,16 @@ connect "irc.uplink.com" { * autoconn - automatically connect to this server * compressed - compress traffic via ziplinks * topicburst - burst topics between servers + * ssl - ssl/tls encrypted server connections */ flags = compressed, topicburst; }; connect "ipv6.some.server" { + /* Hosts that are IPv6 addresses must be in :: shortened form + * if applicable. Addresses starting with a colon get an extra + * zero prepended, for example: 0::1 + */ host = "3ffd:dead:beef::1"; send_password = "password"; accept_password = "password"; @@ -460,6 +493,19 @@ connect "ipv6.some.server" { class = "server"; }; +connect "ssl.uplink.com" { + /* Example of ssl server-to-server connection, ssl flag doesn't need + * compressed flag, 'cause it uses own compression + */ + host = "192.168.0.1"; + send_password = "password"; + accept_password = "anotherpassword"; + port = 9999; + hub_mask = "*"; + class = "server"; + flags = ssl, topicburst; +}; + /* cluster {}; servers that we propagate things to automatically. * NOTE: This does NOT grant them privileges to apply anything locally, * you must add a seperate shared block for that. Clustering will @@ -534,6 +580,9 @@ shared { * all - allow oper/server to do all of above. * locops - allow locops - only used for servers who cluster * rehash - allow rehashing + * dline - allow setting perm/temp dlines + * tdline - allow setting temp dlines + * undline - allow removing dlines * none - disallow everything */ @@ -555,7 +604,7 @@ shared { flags = tkline; }; -/* exempt {}: IPs that are exempt from Dlines. (OLD d:) */ +/* exempt {}: IPs that are exempt from Dlines and rejectcache. (OLD d:) */ exempt { ip = "192.168.0.0/16"; @@ -654,18 +703,19 @@ channel { /* The serverhide block contains the options regarding serverhiding */ serverhide { - /* flatten links: this option will show all servers in /links appear - * that they are linked to this current server + /* flatten links: this option will hide various routing information + * and make all servers in /links appear that they are linked to + * this server. */ flatten_links = no; - /* links delay: how often to update the links file when it is - * flattened. + /* links delay: how long to wait before showing splits or new + * servers in a flattened /links output. */ links_delay = 5 minutes; - /* hidden: hide this server from a /links output on servers that - * support it. this allows hub servers to be hidden etc. + /* hidden: hide this server from a /links output on servers with + * flatten_links enabled. this allows hub servers to be hidden etc. */ hidden = no; @@ -694,17 +744,20 @@ serverhide { * ${nick} - the user's nickname * ${network-name} - the name of the network * - * Note: AHBL (the providers of the below BLs) request that they be + * Note: AHBL (the providers of the below *.ahbl.org BLs) request that they be * contacted, via email, at admins@2mbit.com before using these BLs. * See for more information. */ -#blacklist { +blacklist { + host = "dnsbl.dronebl.org"; + reject_reason = "${nick}, your IP (${ip}) is listed in DroneBL. For assistance, see http://dronebl.org/lookup_branded.do?ip=${ip}&network=${network-name}"; + # host = "ircbl.ahbl.org"; # reject_reason = "${nick}, your IP (${ip}) is listed in ${dnsbl-host} for having an open proxy. In order to protect ${network-name} from abuse, we are not allowing connections with open proxies to connect."; # # host = "tor.ahbl.org"; # reject_reason = "${nick}, your IP (${ip}) is listed as a TOR exit node. In order to protect ${network-name} from tor-based abuse, we are not allowing TOR exit nodes to connect to our network."; -#}; +}; /* * Alias blocks allow you to define custom commands. (Old m_sshortcut.c) @@ -755,11 +808,13 @@ alias "MS" { */ general { /* hide error messages: defines whether error messages from - * servers are hidden or not. These can sometimes contain IPs and - * can have an adverse effect on server ip hiding. Set to: + * servers that are not deemed fully safe are hidden or not. + * These can sometimes contain IPs and can have an adverse + * effect on server ip hiding. Set to: * yes: hide from opers and admin * opers: hide from opers only * no: do not hide error messages + * Admins on other servers count as opers. */ hide_error_messages = opers; @@ -824,12 +879,6 @@ general { */ dots_in_ident=2; - /* dot in ipv6: ircd-hybrid-6.0 and earlier will disallow hosts - * without a '.' in them. this will add one to the end. only needed - * for older servers. - */ - dot_in_ip6_addr = no; - /* min nonwildcard: the minimum non wildcard characters in k/d/g lines * placed via the server. klines hand placed are exempt from limits. * wildcard chars: '.' '*' '?' '@' @@ -897,7 +946,7 @@ general { */ kline_delay = 0 seconds; - /* kline reason: show the user the reason why they are k/d/glined + /* kline reason: show the user the reason why they are k/dlined * on exit. may give away who set k/dline when set via tcm. */ kline_with_reason = yes; @@ -1009,22 +1058,6 @@ general { /* no oper flood: increase flood limits for opers. */ no_oper_flood = yes; - /* glines: enable glines, network wide temp klines */ - glines = no; - - /* gline time: the amount of time a gline will remain before expiring */ - gline_time = 1 day; - - /* gline_min_cidr: If using a CIDR gline, the minimum length the - * mask must be - */ - gline_min_cidr = 16; - - /* idletime: the maximum amount of time a user may idle before - * they are disconnected - */ - idletime = 0; - /* REMOVE ME. The following line checks you've been reading. */ havent_read_conf = yes; @@ -1120,10 +1153,14 @@ general { /* reject duration: the amount of time to cache the rejection */ reject_duration = 5 minutes; - /* max_unknown_ip: maximum number of pending connections to the server - * that are allowed per IP address + /* throttle_duration: Amount of time that throttling will be applied to an IP + * address. */ - max_unknown_ip = 2; + throttle_duration = 60; + + /* throttle_count: Number of connections within throttle_duration that it takes + * for throttling to take effect */ + throttle_count = 4; }; modules {