qusal/salt/kicksecure-minimal
2024-02-02 10:05:46 +01:00
..
files fix: less intrusive kicksecure default install 2024-02-01 17:40:26 +01:00
clone.sls chore: copyright update 2024-01-29 16:49:54 +01:00
clone.top chore: copyright update 2024-01-29 16:49:54 +01:00
create.sls chore: copyright update 2024-01-29 16:49:54 +01:00
create.top chore: copyright update 2024-01-29 16:49:54 +01:00
init.top chore: copyright update 2024-01-29 16:49:54 +01:00
install-developers.sls fix: move custom kicksecure settings to dev state 2024-02-02 10:05:46 +01:00
install-developers.top fix: less intrusive kicksecure default install 2024-02-01 17:40:26 +01:00
install-repo.sls chore: copyright update 2024-01-29 16:49:54 +01:00
install-repo.top chore: copyright update 2024-01-29 16:49:54 +01:00
install.sls fix: move custom kicksecure settings to dev state 2024-02-02 10:05:46 +01:00
install.top chore: copyright update 2024-01-29 16:49:54 +01:00
prefs.sls chore: copyright update 2024-01-29 16:49:54 +01:00
prefs.top chore: copyright update 2024-01-29 16:49:54 +01:00
README.md fix: move custom kicksecure settings to dev state 2024-02-02 10:05:46 +01:00
template.jinja chore: copyright update 2024-01-29 16:49:54 +01:00

kicksecure-minimal

Kicksecure Minimal Template in Qubes OS.

Table of Contents

Description

Creates the Kicksecure Minimal template as well as a Disposable Template based on it.

Installation

  • Top:
qubesctl top.enable kicksecure-minimal
qubesctl --targets=kicksecure-17-minimal state.apply
qubesctl top.disable kicksecure-minimal
qubesctl state.apply kicksecure-minimal.prefs
  • State:
qubesctl state.apply kicksecure-minimal.create
qubesctl --skip-dom0 --targets=kicksecure-17-minimal state.apply kicksecure-minimal.install
qubesctl state.apply kicksecure-minimal.prefs

If you want to help improve Kicksecure integration on Qubes, install packages that are known to be broken on Qubes and can break the boot of the Kicksecure Qube, to report bugs upstream (get a terminal with qvm-console-dispvm):

qubesctl --skip-dom0 --targets=kicksecure-17-minimal state.apply kicksecure-minimal.install-developers

Usage

AppVMs and StandaloneVMs can be based on this template.

Kicksecure Developers

This is intended for Kicksecure Developers to test known to be broken hardening measures. It is not intended for other developers or users.

After you have ran the developers SaltFile, when reporting bugs upstream, share the following information of the customizations made by this formula:

  • hardened-malloc:
libhardened_malloc.so
  • hide-hardware-info:
sysfs_whitelist=0
cpuionfo_whitelist=0
  • permission-hardener:
whitelists_disable_all=true