From 08d45d39fd6ee95fc414fc627f969c2dd76f9406 Mon Sep 17 00:00:00 2001 From: Auke Kok Date: Sat, 6 May 2017 22:12:30 -0700 Subject: [PATCH] Convert man page to `ronn` generated .md input format. --- Makefile.am | 5 +++- tallow.1 => tallow.1.md | 58 +++++++++++++++++++++++++---------------- 2 files changed, 39 insertions(+), 24 deletions(-) rename tallow.1 => tallow.1.md (53%) diff --git a/Makefile.am b/Makefile.am index 87ad31a..2c41bc1 100644 --- a/Makefile.am +++ b/Makefile.am @@ -8,10 +8,13 @@ sbin_PROGRAMS = tallow tallow_SOURCES = tallow.c tallow_LDADD = $(LIBSYSTEMD_LIBS) -EXTRA_DIST = AUTHORS COPYING INSTALL tallow.service.in +EXTRA_DIST = AUTHORS COPYING INSTALL tallow.service.in tallow.1.md dist_doc_DATA = tallow.conf dist_man_MANS = tallow.1 tallow.conf.5 DISTCHECK_CONFIGURE_FLAGS = \ --with-systemdsystemunitdir=$(DESTDIR)$(SYSTEMDSYSTEMUNITDIR) + +docs: tallow.1.md + ronn -r tallow.1.md diff --git a/tallow.1 b/tallow.1.md similarity index 53% rename from tallow.1 rename to tallow.1.md index 07b540c..ccba8d7 100644 --- a/tallow.1 +++ b/tallow.1.md @@ -1,41 +1,53 @@ -.TH tallow 1 "31 October 2012" ".1" "Tallow" -.SH NAME -Tallow \- Reduce log clutter due to ssh login attempts. -.SH SYNOPSIS -/usr/sbin/tallow -.SH DESCRIPTION -\fBtallow\fR is a daemon that watches the systemd journal for -messages from the \fBsshd\fR service. It parses the messages + +## tallow + +Reduce log clutter due to ssh login attempts. + +## SYNOPSIS + +`/usr/sbin/tallow` + +## DESCRIPTION + +`tallow` is a daemon that watches the systemd journal for +messages from the `sshd` service. It parses the messages and looks for attempted random logins such as failed logins to the root account and failed logins to invalid user accounts. -.PP + If such logins were detected, the offending IP address is stored in a list. Items from this list are regularly purged, but if the amount of times that a specific IP address is seen exceeds a threshold (default 3), an iptables(1) rule is inserted in the -\fBTALLOW\fR chain in the \fBfilter\fR netfilter table. The -rule will match all packets from the IP address and \fBDROP\dR +`TALLOW` chain in the `filter` netfilter table. The +rule will match all packets from the IP address and `DROP` them. -.PP + The system administrator needs to assure that all incoming packets -are routed through the \fBTALLOW\fR chain by inserting a rule -appropriately, e.g. \`iptables -I INPUT -j TALLOW\`. The \fBTALLOW\fR -chain may have to be created manually first with e.g. \`iptables -N -TALLOW\`. -.PP +are routed through the `TALLOW` chain by inserting a rule +appropriately, e.g. `iptables -I INPUT -j TALLOW`. The `TALLOW` +chain may have to be created manually first with e.g. `iptables -N +TALLOW`. + Care should be taken to assure that legitimate users are not blocked inadvertently. You may wish to list any valid IP address with the whitelist option in tallow.conf(5). Multiple addresses can be whitelisted. -.SH OPTIONS -The \fBtallow\fR daemon itself has no runtime configuration. All +## OPTIONS + +The `tallow` daemon itself has no runtime configuration. All configuration is done through the tallow.conf(5) config file. -.SH SEE ALSO + +## SEE ALSO + systemd-journald(1), iptables(1), tallow.conf(5) -.SH BUGS -\fBtallow\fR is \fBNOT A SECURITY SOLUTION\fR, nor does it protect + +## BUGS + +`tallow` is `NOT A SECURITY SOLUTION`, nor does it protect against random password logins. A attacker may still be able to logon to your systems if you allow password logins. -.SH AUTHOR + +## AUTHOR + Auke Kok