From 2649e2fbcc54208d3c013588853a5ed4a1a24b4f Mon Sep 17 00:00:00 2001 From: oqyude Date: Sat, 10 Oct 2026 17:15:18 +0300 Subject: [PATCH] =?UTF-8?q?fix(vds-nftables):=20open=20port=2080=20?= =?UTF-8?q?=E2=80=94=20ACME=20HTTP-01=20challenge=20+=20nginx=20HTTP?= =?UTF-8?q?=E2=86=92HTTPS?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Previous T3 fix (5796786) replaced the original SYN rate-limit on {80,443} with explicit accepts for only 22 and 443. This accidentally dropped port 80, which broke: 1. ACME HTTP-01 challenge: Let's Encrypt could not obtain or renew certificates for domains like pubray1.zeroq.su. The cert directory /var/lib/acme/ has no pubray1.zeroq.su/ entry, confirming the cert was never obtained under the new ruleset. 2. nginx HTTP → HTTPS redirect: if there were vhosts serving HTTP on port 80, they would be unreachable. Original vds.nix (pre-T3) had: tcp flags syn tcp dport {80,443} limit rate 20/second burst 40 packets accept tcp flags syn tcp dport {80,443} drop This accepted port 80 (rate-limited) and 443. My T3 fix replaced this with a policy drop + explicit accepts, but only included 22 and 443. Port 80 was missing. Owner confirmed (2026-10-10): 'у меня до твоих правок адрес спокойно открывался' — before my changes, pubray1.zeroq.su was opening fine. My T3 fix broke it by closing port 80. Fix: add tcp dport 80 accept to the nftables ruleset. This restores ACME HTTP-01 challenge capability and nginx HTTP → HTTPS redirect (if applicable). --- configurations/vds.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/configurations/vds.nix b/configurations/vds.nix index fabf8a8..f45a4d9 100644 --- a/configurations/vds.nix +++ b/configurations/vds.nix @@ -119,6 +119,12 @@ # SSH (22) — open on all interfaces (owner: no iifname restriction) tcp dport 22 accept + # HTTP (80) — needed for ACME HTTP-01 challenge (LE cert renewal) + # and for HTTP → HTTPS redirect if nginx vhost is configured. + # ADDED 2026-10-10: previous T3 fix accidentally dropped port 80, + # breaking pubray1.zeroq.su cert renewal. + tcp dport 80 accept + # Xray REALITY inbound (treca acts as relay from sapphira via XHTTP) tcp dport 443 accept