Commit Graph

994 Commits

Author SHA1 Message Date
Patrick Schleizer
627b95e0b3
bumped changelog version 2020-01-20 08:51:25 -05:00
Patrick Schleizer
fbe9b60d95
fix Whonix / Kicksecure
/var/lib/dpkg/tmp.ci/preinst: ERROR: No user is a member of group 'console'. Installation aborted.
/var/lib/dpkg/tmp.ci/preinst: ERROR: You probably want to run:

sudo adduser user console
2020-01-20 08:49:02 -05:00
Patrick Schleizer
960e1ff6e8
bumped changelog version 2020-01-17 03:32:57 -05:00
Patrick Schleizer
1304341868
readme 2020-01-17 03:10:56 -05:00
Patrick Schleizer
6f8d89c6c5
error handling 2020-01-15 15:54:06 -05:00
Patrick Schleizer
7211f6e019
Merge remote-tracking branch 'origin/master' 2020-01-15 15:53:36 -05:00
Patrick Schleizer
f6cc76acd7
Merge pull request #55 from madaidan/sysctl.conf
Process sysctl.conf in initramfs
2020-01-15 20:52:33 +00:00
madaidan
1df48a226d
Update control 2020-01-15 20:30:17 +00:00
madaidan
f7fde60b67
Process sysctl.conf too 2020-01-15 20:28:32 +00:00
Patrick Schleizer
e110ea0b84
bumped changelog version 2020-01-15 11:37:52 -05:00
Patrick Schleizer
0f17596aac
readme 2020-01-15 11:35:41 -05:00
Patrick Schleizer
0618b53464
fix lintian warning 2020-01-15 11:35:07 -05:00
Patrick Schleizer
47ce3bec75
bumped changelog version 2020-01-15 11:05:54 -05:00
Patrick Schleizer
73e830d0ac
readme 2020-01-15 10:08:57 -05:00
Patrick Schleizer
8ab4623f8e
Merge remote-tracking branch 'origin/master' 2020-01-15 06:06:39 -05:00
Patrick Schleizer
087465a0cd
Merge pull request #53 from madaidan/sysctl-initramfs
Set sysctl values in initramfs
2020-01-15 11:02:30 +00:00
Patrick Schleizer
528c5fc4c4
Merge branch 'master' into sysctl-initramfs 2020-01-15 11:02:03 +00:00
Patrick Schleizer
80159545a5
fix xfce4-power-manager xfpm-power-backlight-helper pkexec lxsudo popup
https://forums.whonix.org/t/xfce4-power-manager-xfpm-power-backlight-helper-pkexec-lxsudo-popup/8764

do show lxqt-sudo password prompt if there is a sudoers exceptoin

improved pkexec wrapper logging
2020-01-15 02:42:10 -05:00
Patrick Schleizer
d90ca4b1ad
refactoring 2020-01-14 15:12:13 -05:00
Patrick Schleizer
082f04f2d4
add logging to pkexec wrapper 2020-01-14 15:04:58 -05:00
Patrick Schleizer
1059ccf225
bumped changelog version 2020-01-14 09:28:28 -05:00
Patrick Schleizer
660837dc38
fix case when user "user" does not exists 2020-01-14 09:25:32 -05:00
Patrick Schleizer
18c726c3ee
comment 2020-01-14 09:23:02 -05:00
Patrick Schleizer
b8652681e7
fix legacy 2020-01-14 09:21:47 -05:00
Patrick Schleizer
cc21f912a3
bumped changelog version 2020-01-14 09:20:36 -05:00
Patrick Schleizer
2078cd237f
readme 2020-01-14 09:18:30 -05:00
Patrick Schleizer
c377c5ff83
Merge remote-tracking branch 'origin/master' 2020-01-14 09:01:38 -05:00
Patrick Schleizer
539f24b65e
Merge pull request #54 from madaidan/panic_on_oops
Document panic_on_oops
2020-01-14 14:01:17 +00:00
madaidan
0953bbe1d7
Update control 2020-01-13 21:05:35 +00:00
madaidan
9dc43eae38
Description 2020-01-12 21:42:07 +00:00
madaidan
8c4e0ff1c4
Set sysctl values in initramfs 2020-01-12 21:37:37 +00:00
Patrick Schleizer
8341242abc
bumped changelog version 2020-01-11 15:19:29 -05:00
Patrick Schleizer
130a4cf6d4
readme 2020-01-11 15:17:06 -05:00
Patrick Schleizer
61a2d390a7
lintian 2020-01-11 15:15:12 -05:00
Patrick Schleizer
3fae8e771f
Merge remote-tracking branch 'origin/master' 2020-01-11 15:14:43 -05:00
Patrick Schleizer
e9f4dbdda5
Merge pull request #52 from madaidan/vivid
Blacklist the vivid kernel module
2020-01-11 20:14:10 +00:00
madaidan
6088444c37
Update control 2020-01-11 18:38:17 +00:00
madaidan
a662a76a52
Blacklist vivid 2020-01-11 18:37:00 +00:00
Patrick Schleizer
13a1e1321e
bumped changelog version 2020-01-01 05:59:59 -05:00
Patrick Schleizer
5031e7cc4b
better output if trying to login with non-existing user 2019-12-31 08:18:38 -05:00
Patrick Schleizer
b2bdeb9095
bumped changelog version 2019-12-31 06:08:32 -05:00
Patrick Schleizer
2a3aae62b1
fix 2019-12-31 06:06:52 -05:00
Patrick Schleizer
427deec3f5
bumped changelog version 2019-12-31 06:03:48 -05:00
Patrick Schleizer
e89552c984
add user "user" to group "console" in Whonix and Kicksecure
enable Console Lockdown in Whonix and Kicksecure
2019-12-31 05:55:44 -05:00
Patrick Schleizer
b5a2d1dc58
bumped changelog version 2019-12-31 02:54:58 -05:00
Patrick Schleizer
20697db3ee
improve console lockdown info output 2019-12-31 02:53:02 -05:00
Patrick Schleizer
788914de95
group ssh check was removed
https://forums.whonix.org/t/etc-security-hardening-console-lockdown-pam-access-access-conf/8592/27
2019-12-31 02:46:32 -05:00
Patrick Schleizer
06ed728d79
bumped changelog version 2019-12-30 06:42:14 -05:00
Patrick Schleizer
f3ff32ddbb
Protect /bin/mount from 'chmod -x'.
/bin/mount exactwhitelist
/usr/bin/mount exactwhitelist

Remove SUID from 'mount' but keep executable.

/bin/mount 745 root root
/usr/bin/mount 745 root root

https://forums.whonix.org/t/disable-suid-binaries/7706/61
2019-12-30 06:39:24 -05:00
Patrick Schleizer
e4e9c4e3b0
bumped changelog version 2019-12-30 05:59:43 -05:00