Commit Graph

1122 Commits

Author SHA1 Message Date
Patrick Schleizer
1188a44f47
port to python 3.7 2020-04-04 16:49:30 -04:00
Patrick Schleizer
a2c932aa5a
bumped changelog version 2020-04-02 07:58:51 -04:00
Patrick Schleizer
ae8c5fff3c
readme 2020-04-02 07:22:47 -04:00
Patrick Schleizer
a7f2a2a3b6
console lockdown: allow members of group sudo to use console
https://forums.whonix.org/t/etc-security-hardening/8592

https://github.com/Whonix/security-misc/pull/74#issuecomment-607748407

https://www.whonix.org/wiki/Dev/Strong_Linux_User_Account_Isolation#Console_Lockdown
2020-04-02 06:04:45 -04:00
Patrick Schleizer
7764ee0d20
comments 2020-04-02 05:58:16 -04:00
Patrick Schleizer
d9f2a0e4a1
remove 'Build-Depends: ronn' since no longer required 2020-04-01 17:34:59 -04:00
Patrick Schleizer
eda9c57a62
remove genmkfile 2020-04-01 16:57:33 -04:00
Patrick Schleizer
2609fe9c3e
add debian install file 2020-04-01 16:33:29 -04:00
Patrick Schleizer
d4b2baa9b6
bumped changelog version 2020-04-01 10:58:16 -04:00
Patrick Schleizer
2ceea8d1fe
update copyright year 2020-04-01 08:49:59 -04:00
Patrick Schleizer
b6de867dec
bumped changelog version 2020-04-01 08:26:44 -04:00
Patrick Schleizer
ad022fc0b7
fix 2020-04-01 08:21:06 -04:00
Patrick Schleizer
354af7085b
bumped changelog version 2020-03-31 07:41:45 -04:00
Patrick Schleizer
814f613a2f
When using systemd-nspawn (chroot) then login requires console 'console' to be permitted. 2020-03-31 07:08:25 -04:00
Patrick Schleizer
a369a0a94d
bumped changelog version 2020-03-30 18:42:02 -04:00
Patrick Schleizer
c22adbd92f
notify if security-misc installation is forced 2020-03-30 18:39:23 -04:00
Patrick Schleizer
7ee5fc1b76
bumped changelog version 2020-03-30 17:16:46 -04:00
Patrick Schleizer
f663b5eff8
skip check if any non-root user is a member of group sudo and console if
environment variable `SECURITY_MISC_INSTALL` is set to `force`
2020-03-30 17:15:02 -04:00
Patrick Schleizer
bc22fc9fdb
skip check if any non-root user is a member of group sudo and console if file
/var/lib/security-misc/skip_install_check exists
2020-03-30 17:12:43 -04:00
Patrick Schleizer
d7a69628b1
bumped changelog version 2020-03-21 14:56:48 -04:00
Patrick Schleizer
5f0dd8270b
consistent use of quotes 2020-03-21 14:14:35 -04:00
Patrick Schleizer
66ea1a3a12
minor 2020-03-21 14:14:15 -04:00
Patrick Schleizer
23bd7ead59
remove trailing space 2020-03-21 14:12:42 -04:00
Patrick Schleizer
7c25fc517e
Merge remote-tracking branch 'origin/master' 2020-03-21 14:12:25 -04:00
Patrick Schleizer
1cbc7f6bed
Merge pull request #73 from madaidan/sysctl-initramfs
Only remount in sysctl-initramfs if already mounted read-only
2020-03-21 18:11:57 +00:00
madaidan
89ada11cf9
Only remount if already mounted read-only 2020-03-21 17:49:07 +00:00
Patrick Schleizer
20f0c574d5
Merge remote-tracking branch 'origin/master' 2020-03-21 13:28:43 -04:00
Patrick Schleizer
2938182ce6
Merge pull request #72 from madaidan/master
Fix sysctl-initramfs logs
2020-03-21 17:26:37 +00:00
madaidan
c8826d6702
Fix sysctl-initramfs logs 2020-03-21 17:15:25 +00:00
Patrick Schleizer
e4118cb21e
bumped changelog version 2020-03-12 04:43:08 -04:00
Patrick Schleizer
e6e7886a6e
Merge remote-tracking branch 'origin/master' 2020-03-11 09:08:41 -04:00
Patrick Schleizer
711e786be5
Merge pull request #70 from madaidan/userfaultfd
Fix unprivileged_userfaultfd
2020-03-11 13:06:23 +00:00
madaidan
4d0de87f79
Disable unprivileged userfaultfd use again 2020-03-08 17:49:49 +00:00
madaidan
efb2683cfc
Hide unprivileged_userfaultfd error 2020-03-08 17:49:12 +00:00
Patrick Schleizer
04a87f7029
bumped changelog version 2020-03-08 09:43:24 -04:00
Patrick Schleizer
284a491100
disable vm.unprivileged_userfaultfd=0 for now
because broken

https://forums.whonix.org/t/kernel-hardening/7296/406

reverts "Restrict the userfaultfd() syscall to root as it can make heap sprays easier."

https://duasynt.com/blog/linux-kernel-heap-spray
2020-03-08 08:07:10 -04:00
Patrick Schleizer
44351ec9b7
remove no longer needed code for installation of apparmor profiles 2020-03-07 21:44:19 -05:00
Patrick Schleizer
71ae623916
bumped changelog version 2020-03-05 08:36:27 -05:00
Patrick Schleizer
76eb9579a3
readme 2020-03-05 08:33:00 -05:00
Patrick Schleizer
15dde15a36
typo 2020-03-03 09:42:24 -05:00
Patrick Schleizer
8887af26d6
bumped changelog version 2020-03-03 09:19:49 -05:00
Patrick Schleizer
1dea4dbcf6
readme 2020-03-03 09:18:38 -05:00
Patrick Schleizer
cd19c2da00
fix lintian warning 2020-03-03 09:18:24 -05:00
Patrick Schleizer
7e3fedefb2
bumped changelog version 2020-03-03 09:12:50 -05:00
Patrick Schleizer
201d6b5efc
readme 2020-03-03 09:07:42 -05:00
Patrick Schleizer
63c6405ab7
Merge remote-tracking branch 'origin/master' 2020-02-29 07:34:46 -05:00
Patrick Schleizer
453aa8a4eb
Merge pull request #65 from madaidan/userfaultfd
Restrict the userfaultfd() syscall to root
2020-02-29 12:28:32 +00:00
Patrick Schleizer
e3e39f2235
Merge remote-tracking branch 'origin/master' 2020-02-29 05:01:41 -05:00
Patrick Schleizer
649ec5dfa1
pkexec wrapper: fix gdebi / synaptic
but at cost of checking for passwordless sudo /etc/suders /etc/sudoers.d
exceptions.

http://forums.whonix.org/t/cannot-use-pkexec/8129/53
2020-02-29 04:59:56 -05:00
Patrick Schleizer
32269d32b6
description 2020-02-29 04:59:15 -05:00