-
-
Notifications
You must be signed in to change notification settings - Fork 607
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🔒️ Disable xmlrpc by default #1467
Conversation
Funny. I spent yesterday checking this out after seeing increased activity on a few of our servers. There is also https://github.com/ItinerisLtd/trellis-disable-xml-rpc. I do like being able to set this per site though as this PR implements |
There's also some new-ish fail2ban rules you can enable FYI: trellis/group_vars/all/security.yml Lines 16 to 22 in 5e47bd9
|
There are, thanks Ben 🙏 that's where we ended up yesterday with a Edit: added link to related discourse post |
Jetpack using this makes me slightly iffy about disabling it by default, but probably in favour anyway. Regardless, better to have the option built in. |
Jetpack does still use this, but you can whitelist their IP address ranges: https://jetpack.com/support/how-to-add-jetpack-ips-allowlist/
|
@PDowney: Thanks! So when Jetpack is used, |
That seems correct to me 👍 |
This PR disables
xmlrpc.php
by default