diff --git a/modules/fail2ban/module.json b/modules/fail2ban/module.json index df7d3bb..fcf27f3 100644 --- a/modules/fail2ban/module.json +++ b/modules/fail2ban/module.json @@ -28,13 +28,6 @@ "path": "/etc/fail2ban/action.d", "mode": "0755" }, - { - "id": "fail2ban-local", - "type": "file", - "path": "/etc/fail2ban/fail2ban.local", - "mode": "0644", - "content": "[Definition]\n\n# Where fail2ban writes its own log, declared rather than assumed. The recidive jail reads\n# this file to ban whoever keeps coming back, and the logrotate file this module ships\n# rotates it -- but nothing told fail2ban to write there. Where the package default stands,\n# fail2ban logs to the journal, the recidive jail finds no log file, and the whole service\n# refuses to start, taking the sshd jail with it.\n#\n# In .local, not in fail2ban.conf: that file belongs to the package.\nlogtarget = /var/log/fail2ban.log\n" - }, { "id": "jail-local", "type": "file", @@ -49,6 +42,14 @@ "mode": "0644", "content": "[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\nmaxretry = 5\n" }, + { + "id": "log", + "type": "file", + "path": "/var/log/fail2ban.log", + "mode": "0640", + "create-once": true, + "content": "" + }, { "id": "jail-recidive", "type": "file", @@ -77,7 +78,6 @@ "state": "running", "boot": "enabled", "restart-on": [ - "fail2ban-local", "jail-local", "jail-sshd", "jail-recidive",