Hello MIAB Team,
i hope you are well and safe.
I have “hardened” my MIAB servers by opening only mandatory ports to the world : 25 and 80, all others ports are behind restrictive IP (smtp, imap, ssh, https), since their creations. This drastically reduced CPU workload for fail2ban.
1 month ago, I installed crowdsec (free licensed used) on my servers to secure them more.
I can see in reports that there are more 70.000 attacks blocked by this tool : http scan + http Bruteforce (this is only coming from port 80).
Could you please confirm which Challenge is used by MIAB for SSL Certificate creation/renew with Let’s Encrypt ? is it DNS-01 or HTTP ?
if DNS-01 challenge (i hope but have doubt), there are no reason to expose port 80 to the world.
if HTTP Challenge used, is it plane to update to DNS-01 ?
Best regards
François