Patrick Schleizer
|
cd216095eb
|
set default umask to 027
using package libpam-umask
https://www.debian.org/doc/manuals/securing-debian-manual/ch04s11.en.html#id-1.5.14.19
https://github.com/Kicksecure/security-misc/pull/151
|
2023-11-03 09:12:24 -04:00 |
|
monsieuremre
|
ac224b270a
|
disable sysrq
|
2023-11-02 13:01:55 +00:00 |
|
monsieuremre
|
07882f61a8
|
enable service on install
not sure if this would be the right way to do it
|
2023-11-02 10:44:19 +00:00 |
|
monsieuremre
|
9f063584c1
|
disable-kernel-module-loading
|
2023-11-02 10:28:41 +00:00 |
|
monsieuremre
|
3e604618a8
|
harden-module-loading.service
|
2023-11-02 10:24:35 +00:00 |
|
monsieuremre
|
3ee4be652b
|
depend on libpam-tmpdir
|
2023-11-02 09:36:58 +00:00 |
|
monsieuremre
|
1abac794b5
|
very secure and private defaults
|
2023-11-02 09:15:20 +00:00 |
|
monsieuremre
|
5a583ca48c
|
typo in file name
|
2023-11-02 08:30:26 +00:00 |
|
monsieuremre
|
229032d691
|
Rename etc/systemd/networkd.conf.d/99_ipv6-privacy-extensions.conf to usr/lib/systemd/networkd.conf.d/99_ipv6-privacy-extensions.conf
|
2023-11-01 17:54:05 +00:00 |
|
monsieuremre
|
1049298e7b
|
Update and rename etc/NetworkManager/conf.d/99_randomize-mac.conf to usr/lib/NetworkManager/conf.d/99_randomize-mac.conf
|
2023-11-01 17:52:40 +00:00 |
|
monsieuremre
|
76e684cc0a
|
Update and rename etc/NetworkManager/conf.d/99_ipv6-privacy.conf to usr/lib/NetworkManager/conf.d/99_ipv6-privacy.conf
|
2023-11-01 17:51:27 +00:00 |
|
Patrick Schleizer
|
a768f1f1eb
|
bumped changelog version
|
2023-11-01 12:26:21 -04:00 |
|
Patrick Schleizer
|
bb14a05852
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2023-11-01 11:11:54 -04:00 |
|
Patrick Schleizer
|
44906e8f39
|
Merge pull request #142 from monsieuremre/patch-5
ssh config
|
2023-11-01 11:11:27 -04:00 |
|
Patrick Schleizer
|
5ed2a5ce4a
|
bumped changelog version
|
2023-11-01 11:10:36 -04:00 |
|
Patrick Schleizer
|
bb1161986b
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2023-11-01 10:31:04 -04:00 |
|
Patrick Schleizer
|
b7cddd6e55
|
Merge pull request #143 from monsieuremre/patch-6
new lines 990-security-misc.conf
|
2023-11-01 10:30:26 -04:00 |
|
monsieuremre
|
fc8e201e84
|
rename
|
2023-10-27 14:49:24 +00:00 |
|
monsieuremre
|
90a88225a4
|
security-misc.maintscript
|
2023-10-27 14:38:31 +00:00 |
|
monsieuremre
|
13b4ddbb62
|
30_security-misc.conf
|
2023-10-27 14:34:21 +00:00 |
|
monsieuremre
|
b298d152fc
|
30_security-misc.conf
|
2023-10-27 14:32:08 +00:00 |
|
monsieuremre
|
3d4b04fddc
|
99_ipv6-privacy.conf
|
2023-10-27 12:35:39 +00:00 |
|
monsieuremre
|
e90f62eaab
|
99_randomize_mac.conf
|
2023-10-27 12:34:15 +00:00 |
|
monsieuremre
|
604d839537
|
99_ipv6-privacy-extensions.conf
|
2023-10-27 12:30:26 +00:00 |
|
monsieuremre
|
c975c3c0ff
|
new lines 990-security-misc.conf
added new recommended hardening settings with comments
|
2023-10-27 11:07:53 +00:00 |
|
monsieuremre
|
f2c23a2831
|
ssh config
|
2023-10-27 10:53:45 +00:00 |
|
Patrick Schleizer
|
7d576842fb
|
bumped changelog version
|
2023-10-26 20:08:41 -04:00 |
|
Patrick Schleizer
|
7cff267002
|
remove duplicates
|
2023-10-26 19:31:14 -04:00 |
|
Patrick Schleizer
|
928cdb81d4
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2023-10-26 19:29:55 -04:00 |
|
Patrick Schleizer
|
39fed058f4
|
Merge pull request #140 from monsieuremre/patch-3
New lines in default permission config
|
2023-10-26 19:27:41 -04:00 |
|
Patrick Schleizer
|
a330a9fd75
|
refactor permission-lockdown
|
2023-10-26 19:20:21 -04:00 |
|
Patrick Schleizer
|
8bf5ff82be
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2023-10-26 19:15:04 -04:00 |
|
Patrick Schleizer
|
92a6ecc40a
|
Merge pull request #141 from monsieuremre/patch-4
New permission-lockdown
|
2023-10-26 19:13:34 -04:00 |
|
Patrick Schleizer
|
1123d23114
|
remount-secure: disable debugging to save space in initrd
|
2023-10-26 18:45:07 -04:00 |
|
monsieuremre
|
91c445244c
|
actually we do it once indeed
|
2023-10-26 19:41:07 +00:00 |
|
monsieuremre
|
88f396264c
|
avoiding /etc/passwd
|
2023-10-26 19:35:59 +00:00 |
|
monsieuremre
|
b5ba03247a
|
readability
|
2023-10-26 19:31:25 +00:00 |
|
monsieuremre
|
f487752ba1
|
not limiting ourselves. we do not do this not just once.
|
2023-10-26 19:30:58 +00:00 |
|
monsieuremre
|
88cd5a905d
|
strip unnecessary
|
2023-10-26 19:25:24 +00:00 |
|
monsieuremre
|
d9f10c221a
|
new permission-lockdown
|
2023-10-26 18:17:50 +00:00 |
|
monsieuremre
|
99355c6169
|
new lines 30_default.conf
|
2023-10-26 17:45:28 +00:00 |
|
Patrick Schleizer
|
ca9603af17
|
bumped changelog version
|
2023-10-26 12:23:48 -04:00 |
|
Patrick Schleizer
|
5f4222c1c3
|
enable SUID Disabler and Permission Hardener by default
https://www.kicksecure.com/wiki/SUID_Disabler_and_Permission_Hardener
https://forums.whonix.org/t/suid-disabler-and-permission-hardener/7706
|
2023-10-26 12:20:48 -04:00 |
|
Patrick Schleizer
|
e5d989af5a
|
comment
|
2023-10-26 12:04:13 -04:00 |
|
Patrick Schleizer
|
8557e0963e
|
bumped changelog version
|
2023-10-25 17:55:37 -04:00 |
|
Patrick Schleizer
|
b7e2d49f5f
|
comment
|
2023-10-25 17:41:05 -04:00 |
|
Patrick Schleizer
|
5d71217e59
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2023-10-25 17:40:13 -04:00 |
|
Patrick Schleizer
|
6a22351d29
|
renamed: usr/lib/sysctl.d/30_security-misc.conf -> usr/lib/sysctl.d/990-security-misc.conf
|
2023-10-25 17:30:07 -04:00 |
|
Patrick Schleizer
|
b7c52800f4
|
renamed: etc/sysctl.d/30_security-misc.conf -> usr/lib/sysctl.d/30_security-misc.conf
renamed: etc/sysctl.d/30_security-misc_kexec-disable.conf -> usr/lib/sysctl.d/30_security-misc_kexec-disable.conf
renamed: etc/sysctl.d/30_silent-kernel-printk.conf -> usr/lib/sysctl.d/30_silent-kernel-printk.conf
|
2023-10-25 17:28:43 -04:00 |
|
Patrick Schleizer
|
a2f811aff0
|
Merge pull request #135 from monsieuremre/kernel-fix
Kernel hardening fix
|
2023-10-25 17:26:46 -04:00 |
|