Merge remote-tracking branch 'origin/master'

This commit is contained in:
Patrick Schleizer 2020-01-15 15:53:36 -05:00
commit 7211f6e019
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48
2 changed files with 4 additions and 2 deletions

5
debian/control vendored
View File

@ -117,8 +117,9 @@ Description: enhances misc security settings
* The vivid kernel module is blacklisted as it's only required for testing
and has been the cause of multiple vulnerabilities.
.
* An initramfs hook sets the sysctl values in /etc/sysctl.d before init
is executed so sysctl hardening is enabled as early as possible.
* An initramfs hook sets the sysctl values in /etc/sysctl.conf and
/etc/sysctl.d before init is executed so sysctl hardening is enabled
as early as possible.
.
* The kernel panics on oopses to prevent it from continuing to run a flawed
process and to deter brute forcing.

View File

@ -15,4 +15,5 @@ prereqs)
;;
esac
sysctl -p ${rootmnt}/etc/sysctl.conf
sysctl -p ${rootmnt}/etc/sysctl.d/*.conf