description

This commit is contained in:
Patrick Schleizer 2019-08-14 07:01:25 +00:00
parent ff8c097943
commit a82448d46a
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

5
debian/control vendored
View File

@ -69,6 +69,11 @@ Description: enhances misc security settings
* The kernel now panics on oopses to prevent it from continuing running a
flawed process.
.
Requires every module to be signed before being loaded. Any module that is
unsigned or signed with an invalid key cannot be loaded. This makes it harder
to load a malicious module.
/etc/default/grub.d/40_only_allow_signed_modules.cfg
.
Uncommon network protocols are blacklisted:
These are rarely used and may have unknown vulnerabilities.
/etc/modprobe.d/uncommon-network-protocols.conf