NNTP Server
The NNTP Content Server
Section titled “The NNTP Content Server”The NNTP content server provides access to publicly exposed message conferences and areas over either secure NNTPS (NNTP over TLS or nttps://) and/or non-secure NNTP (nntp://).
Configuration
Section titled “Configuration”The following keys are available within the contentServers.nntp configuration block:
| Item | Required | Description |
|---|---|---|
nntp | No | Configuration block for non-secure NNTP. See Non-Secure NNTP Configuration. |
nntps | No | Configuration block for secure NNTP. See Secure Configuration (NNTPS) |
publicMessageConferences | Yes | A map of conference tags to area tags that are publicly exposed over NNTP. Anonymous users will gain read-only access to these areas. |
allowPosts | No | Allow posting from authenticated users. See Write Access. Default is false. |
Non-Secure Configuration
Section titled “Non-Secure Configuration”Under contentServers.nntp.nntp the following configuration is allowed:
| Item | Required | Description |
|---|---|---|
enabled | Yes | Set to true to enable non-secure NNTP access. |
port | No | Override the default port of 8119. |
Secure Configuration (NNTPS)
Section titled “Secure Configuration (NNTPS)”Under contentServers.nntp.nntps the following configuration is allowed:
| Item | Required | Description |
|---|---|---|
enabled | Yes | Set to true to enable secure NNTPS access. |
port | No | Override the default port of 8565. |
certPem | No | Override the default certificate file path of ./config/nntps_cert.pem |
keyPem | No | Override the default certificate key file path of ./config/nntps_key.pem |
Certificates and Keys
Section titled “Certificates and Keys”In order to use secure NNTPS, a TLS certificate and key pair must be provided. You may generate your own but most clients will not trust them. A certificate and key from a trusted Certificate Authority is recommended. Let’s Encrypt provides free TLS certificates. Certificates and private keys must be in PEM format.
Generating a Certificate & Key Pair
Section titled “Generating a Certificate & Key Pair”An example of generating your own cert/key pair:
openssl req -newkey rsa:2048 -nodes -keyout ./config/nntps_key.pem -x509 -days 3050 -out ./config/nntps_cert.pemWrite Access
Section titled “Write Access”Authenticated users may write messages to a group given the following are true:
allowPostsis set totrue- They are connected securely (NNTPS). This is a strict requirement due to how NNTP authenticates in plain-text otherwise.
- The authenticated user has write ACS to the target message conference and area.
Example Configuration
Section titled “Example Configuration”contentServers: { nntp: { allowPosts: true
publicMessageConferences: { fsxnet: [ // Expose these areas of fsxNet "fsx_gen", "fsx_bbs" ] }
nntp: { enabled: true }
nntps: { enabled: true
// These could point to Let's Encrypt provided pairs for example: certPem: /path/to/some/tls_cert.pem keyPem: /path/to/some/tls_private_key.pem } }}