Patrick Schleizer
|
7309445ee5
|
comment
|
2023-11-06 16:52:27 -05:00 |
|
Patrick Schleizer
|
f09d97fc9e
|
whitelist VirtualBox
|
2023-11-06 16:50:19 -05:00 |
|
Patrick Schleizer
|
64c8c7a8d5
|
whitelist SSH
|
2023-11-06 16:47:31 -05:00 |
|
Patrick Schleizer
|
9682b51d54
|
whitelist virtualbox
|
2023-11-06 16:44:36 -05:00 |
|
Patrick Schleizer
|
a40b9bc095
|
comments
|
2023-11-06 16:40:22 -05:00 |
|
Patrick Schleizer
|
2c1a3da433
|
VirtualBoxVM matchwhitelist
|
2023-11-06 16:38:50 -05:00 |
|
Patrick Schleizer
|
4e96ffaabb
|
chrome-sandbox matchwhitelist
|
2023-11-06 16:37:19 -05:00 |
|
Patrick Schleizer
|
df5f3e8056
|
output
|
2023-11-06 16:36:22 -05:00 |
|
Patrick Schleizer
|
72f6e6bb9c
|
output
|
2023-11-06 16:28:23 -05:00 |
|
Patrick Schleizer
|
3bc831a1f7
|
lintian
|
2023-11-06 16:27:29 -05:00 |
|
Patrick Schleizer
|
fd1f38b2eb
|
remount-secure systemd unit
https://github.com/Kicksecure/security-misc/pull/152
|
2023-11-06 16:22:42 -05:00 |
|
Patrick Schleizer
|
79f9c1fb3a
|
add sysinit-post.target
https://github.com/Kicksecure/security-misc/pull/152
|
2023-11-06 15:48:09 -05:00 |
|
Patrick Schleizer
|
2de5ab4120
|
clarify scope of application specific hardening
fixes https://github.com/Kicksecure/security-misc/issues/154
|
2023-11-06 13:47:30 -05:00 |
|
Patrick Schleizer
|
5a96616b39
|
bumped changelog version
|
2023-11-05 21:13:14 -05:00 |
|
Patrick Schleizer
|
ad079ac5cc
|
readme
https://github.com/Kicksecure/security-misc/pull/152
|
2023-11-05 20:55:55 -05:00 |
|
Patrick Schleizer
|
be023c7722
|
readme
https://github.com/Kicksecure/security-misc/issues/159
|
2023-11-05 20:54:43 -05:00 |
|
Patrick Schleizer
|
e1f413c1ee
|
disable harden-module-loading.service for now
due to issues
https://github.com/Kicksecure/security-misc/issues/159
|
2023-11-05 20:53:26 -05:00 |
|
Patrick Schleizer
|
f2ea1abc9b
|
comment
|
2023-11-05 20:53:03 -05:00 |
|
Patrick Schleizer
|
95d1cfb4a0
|
Revert "remove no longer required remount-service systemd unit"
This reverts commit 479ab61a1d .
https://github.com/Kicksecure/security-misc/pull/152
|
2023-11-05 20:49:36 -05:00 |
|
Patrick Schleizer
|
24b4d59ce4
|
bumped changelog version
|
2023-11-05 20:14:33 -05:00 |
|
Patrick Schleizer
|
4482f1841c
|
newline
|
2023-11-05 20:13:14 -05:00 |
|
Patrick Schleizer
|
c5167c8f0d
|
fix systemd unit
https://github.com/Kicksecure/security-misc/issues/159
|
2023-11-05 20:12:03 -05:00 |
|
Patrick Schleizer
|
2571bbf315
|
duplicate
|
2023-11-05 18:42:25 -05:00 |
|
Patrick Schleizer
|
aa17087883
|
update path
|
2023-11-05 18:42:08 -05:00 |
|
Patrick Schleizer
|
d203e539aa
|
bumped changelog version
|
2023-11-05 18:17:59 -05:00 |
|
Patrick Schleizer
|
4ebab940c7
|
description too long, fixed
|
2023-11-05 17:56:35 -05:00 |
|
Patrick Schleizer
|
ad010ef5b4
|
debugging
|
2023-11-05 17:52:44 -05:00 |
|
Patrick Schleizer
|
826e76d037
|
bumped changelog version
|
2023-11-05 17:43:33 -05:00 |
|
Patrick Schleizer
|
3130a39d8c
|
set -e
|
2023-11-05 17:43:07 -05:00 |
|
Patrick Schleizer
|
18a2d814cc
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2023-11-05 17:42:28 -05:00 |
|
Patrick Schleizer
|
36f3c30440
|
Merge pull request #148 from monsieuremre/module-loading-hardening
Harden the loading of new modules to the kernel after install
|
2023-11-05 17:41:56 -05:00 |
|
Patrick Schleizer
|
4fda9d2e84
|
bumped changelog version
|
2023-11-05 16:46:18 -05:00 |
|
Patrick Schleizer
|
4219347f0a
|
fix permission-hardener config parsing issue
|
2023-11-05 16:43:44 -05:00 |
|
Patrick Schleizer
|
e72f79236b
|
refactoring
|
2023-11-05 16:41:41 -05:00 |
|
Patrick Schleizer
|
dea0d9a78a
|
fix permission-hardener config parsing issue
|
2023-11-05 16:40:49 -05:00 |
|
Patrick Schleizer
|
017ae18ad7
|
fix permission-hardener config parsing issue
|
2023-11-05 16:39:10 -05:00 |
|
Patrick Schleizer
|
65e3c14643
|
fix permission-hardener config parsing issue
|
2023-11-05 16:35:11 -05:00 |
|
Patrick Schleizer
|
40e536a9be
|
bumped changelog version
|
2023-11-05 16:04:03 -05:00 |
|
Patrick Schleizer
|
51decff2fd
|
exclude qfile-unpacker from permission hardener
|
2023-11-05 16:03:36 -05:00 |
|
Patrick Schleizer
|
52b6e92e00
|
bumped changelog version
|
2023-11-05 15:58:21 -05:00 |
|
Patrick Schleizer
|
1900c1ab07
|
pam exclude from permission-hardener
|
2023-11-05 15:57:49 -05:00 |
|
Patrick Schleizer
|
76e3a3c5f9
|
bumped changelog version
|
2023-11-05 15:29:38 -05:00 |
|
Patrick Schleizer
|
d4494fd3c3
|
disable remount-secure dracut modules
pending new systemd based implementation
https://github.com/Kicksecure/security-misc/pull/152
|
2023-11-05 15:27:09 -05:00 |
|
Patrick Schleizer
|
949c163370
|
bumped changelog version
|
2023-11-05 15:14:43 -05:00 |
|
Patrick Schleizer
|
4a19fbae0b
|
move permission-hardening to /usr/bin to make it more easily accessible
|
2023-11-05 15:13:01 -05:00 |
|
Patrick Schleizer
|
c75f80b29f
|
lower verbosity of permission hardener
fixes https://github.com/Kicksecure/security-misc/issues/158
|
2023-11-05 15:09:29 -05:00 |
|
Patrick Schleizer
|
0544657123
|
bumped changelog version
|
2023-11-05 14:56:06 -05:00 |
|
Patrick Schleizer
|
42be631023
|
readme
|
2023-11-05 14:54:05 -05:00 |
|
Patrick Schleizer
|
55ba5d4832
|
renamed: usr/lib/NetworkManager/conf.d/99_ipv6-privacy.conf -> usr/lib/NetworkManager/conf.d/80_ipv6-privacy.conf
renamed: usr/lib/NetworkManager/conf.d/99_randomize-mac.conf -> usr/lib/NetworkManager/conf.d/80_randomize-mac.conf
renamed: usr/lib/systemd/networkd.conf.d/99_ipv6-privacy-extensions.conf -> usr/lib/systemd/networkd.conf.d/80_ipv6-privacy-extensions.conf
|
2023-11-05 14:51:31 -05:00 |
|
Patrick Schleizer
|
eab5d7d4ec
|
cleanup
|
2023-11-05 14:50:13 -05:00 |
|