Skip to content

Conversation

@tgoeg
Copy link
Contributor

@tgoeg tgoeg commented Oct 28, 2024

Nextcloud won't log failed login attempts in log levels > 2. Added this to the documentation, and, while at it, improved the fail2ban guide in a few other places.

See nextcloud/server#48826 as well.

☑️ Resolves

🖼️ Screenshots

2024-10-28_131057_screenshot

Nextcloud won't log failed login attempts in log levels > 2.
Added this to the documentation, and, while at it, improved the fail2ban guide in a few other places.

Fixes nextcloud#12327.

Signed-off-by: tgoeg <[email protected]>
@github-actions
Copy link
Contributor

Hello there,
Thank you so much for taking the time and effort to create a pull request to our Nextcloud project.

We hope that the review process is going smooth and is helpful for you. We want to ensure your pull request is reviewed to your satisfaction. If you have a moment, our community management team would very much appreciate your feedback on your experience with this PR review process.

Your feedback is valuable to us as we continuously strive to improve our community developer experience. Please take a moment to complete our short survey by clicking on the following link: https://cloud.nextcloud.com/apps/forms/s/i9Ago4EQRZ7TWxjfmeEpPkf6

Thank you for contributing to Nextcloud and we hope to hear from you soon!

(If you believe you should not receive this message, you can add yourself to the blocklist.)

Copy link
Contributor

@susnux susnux left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Makes sense

@susnux susnux requested a review from nickvergessen November 12, 2024 23:15
Nextcloud logs failed login attempts in ``nextcloud.log`` with log level ``2``,
so you need to define a ``loglevel`` of ``2`` or less in ``config.php``.

Make sure your ``nextcloud.log`` is writeable by your webserver user, possibly by
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In theory the nextcloud.log is owned by the webserver user anyway, as it's the one creating and writing it?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only in theory :-)
Mine is not, as the whole installation is owned by a specific linux user as I never let the www-data user own its own executables (r/w), as that opens up the possibility for exploits to change the application's code.
Most admins I know do it this way.

@nickvergessen
Copy link
Member

Thanks a lot!

@nickvergessen nickvergessen merged commit 95e8ae8 into nextcloud:master Nov 13, 2024
@welcome
Copy link

welcome bot commented Nov 13, 2024

Thanks for your first pull request and welcome to the community! Feel free to keep them coming! If you are looking for issues to tackle then have a look at this selection: https://github.com/nextcloud/documentation/issues?q=is%3Aopen+is%3Aissue+label%3A%22good+first+issue%22

@nickvergessen
Copy link
Member

/backport to stable30

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fail2ban instructions in hardening guide miss needed loglevel and some details

3 participants