mirror of
https://github.com/tasket/Qubes-VM-hardening.git
synced 2024-10-01 06:35:42 -04:00
22 lines
580 B
Bash
22 lines
580 B
Bash
#!/bin/sh
|
|
set -e
|
|
[ `id -u` -eq 0 ] || exit
|
|
|
|
echo "Disabling the pre-release service (if present)..."
|
|
systemctl disable vm-sudo-protect.service || true
|
|
|
|
echo "Installing vm-boot-protect.service..."
|
|
cp vm-boot-protect.sh /usr/lib/qubes/init
|
|
chmod +x /usr/lib/qubes/init/vm-boot-protect.sh
|
|
cp vm-boot-protect.service /lib/systemd/system
|
|
systemctl daemon-reload
|
|
systemctl enable vm-boot-protect.service
|
|
|
|
echo "Adding defaults in /etc/default/vms..."
|
|
# Careful... ownership & mode are not preserved here!
|
|
cp -rnv default/vms/* /etc/default/vms
|
|
|
|
echo
|
|
echo "vm-boot-protect installed!"
|
|
|