]> git.pld-linux.org Git - packages/kernel.git/blame - kernel-grsec+pax.config
This commit was manufactured by cvs2git to create branch 'LINUX_2_6_16'.
[packages/kernel.git] / kernel-grsec+pax.config
CommitLineData
7383e370 1#
2# PaX
3#
4CONFIG_PAX=y
5
6#
7# PaX Control
8#
9CONFIG_PAX_SOFTMODE=y
10# CONFIG_PAX_EI_PAX is not set
11CONFIG_PAX_PT_PAX_FLAGS=y
12# CONFIG_PAX_NO_ACL_FLAGS is not set
13CONFIG_PAX_HAVE_ACL_FLAGS=y
14# CONFIG_PAX_HOOK_ACL_FLAGS is not set
15
16#
17# Non-executable pages
18#
19CONFIG_PAX_NOEXEC=y
20CONFIG_PAX_PAGEEXEC=y
21CONFIG_PAX_SEGMEXEC=y
22# CONFIG_PAX_DEFAULT_PAGEEXEC is not set
23CONFIG_PAX_DEFAULT_SEGMEXEC=y
24CONFIG_PAX_EMUTRAMP=y
25CONFIG_PAX_MPROTECT=y
26# CONFIG_PAX_NOELFRELOCS is not set
27
28#
29# Address Space Layout Randomization
30#
31CONFIG_PAX_ASLR=y
32# CONFIG_PAX_RANDKSTACK is not set
33CONFIG_PAX_RANDUSTACK=y
34CONFIG_PAX_RANDMMAP=y
35CONFIG_PAX_NOVSYSCALL=y
36
37#
38# Grsecurity
39#
40CONFIG_GRKERNSEC=y
41# CONFIG_GRKERNSEC_LOW is not set
42# CONFIG_GRKERNSEC_MEDIUM is not set
43# CONFIG_GRKERNSEC_HIGH is not set
44CONFIG_GRKERNSEC_CUSTOM=y
45
46#
47# Address Space Protection
48#
49CONFIG_GRKERNSEC_KMEM=y
50# CONFIG_GRKERNSEC_IO is not set
51CONFIG_GRKERNSEC_PROC_MEMMAP=y
52CONFIG_GRKERNSEC_BRUTE=y
53CONFIG_GRKERNSEC_MODSTOP=y
54# CONFIG_GRKERNSEC_HIDESYM is not set
55
56#
57# Role Based Access Control Options
58#
59CONFIG_GRKERNSEC_ACL_HIDEKERN=y
60CONFIG_GRKERNSEC_ACL_MAXTRIES=3
61CONFIG_GRKERNSEC_ACL_TIMEOUT=30
62
63#
64# Filesystem Protections
65#
66CONFIG_GRKERNSEC_PROC=y
67# CONFIG_GRKERNSEC_PROC_USER is not set
68CONFIG_GRKERNSEC_PROC_USERGROUP=y
69CONFIG_GRKERNSEC_PROC_GID=17
70CONFIG_GRKERNSEC_PROC_ADD=y
71CONFIG_GRKERNSEC_LINK=y
72CONFIG_GRKERNSEC_FIFO=y
73CONFIG_GRKERNSEC_CHROOT=y
74CONFIG_GRKERNSEC_CHROOT_MOUNT=y
75CONFIG_GRKERNSEC_CHROOT_DOUBLE=y
76CONFIG_GRKERNSEC_CHROOT_PIVOT=y
77CONFIG_GRKERNSEC_CHROOT_CHDIR=y
78CONFIG_GRKERNSEC_CHROOT_CHMOD=y
79CONFIG_GRKERNSEC_CHROOT_FCHDIR=y
80CONFIG_GRKERNSEC_CHROOT_MKNOD=y
81CONFIG_GRKERNSEC_CHROOT_SHMAT=y
82CONFIG_GRKERNSEC_CHROOT_UNIX=y
83CONFIG_GRKERNSEC_CHROOT_FINDTASK=y
84CONFIG_GRKERNSEC_CHROOT_NICE=y
85CONFIG_GRKERNSEC_CHROOT_SYSCTL=y
86CONFIG_GRKERNSEC_CHROOT_CAPS=y
87
88#
89# Kernel Auditing
90#
91CONFIG_GRKERNSEC_AUDIT_GROUP=y
92CONFIG_GRKERNSEC_AUDIT_GID=1007
93CONFIG_GRKERNSEC_EXECLOG=y
94CONFIG_GRKERNSEC_RESLOG=y
95CONFIG_GRKERNSEC_CHROOT_EXECLOG=y
96CONFIG_GRKERNSEC_AUDIT_CHDIR=y
97CONFIG_GRKERNSEC_AUDIT_MOUNT=y
98CONFIG_GRKERNSEC_AUDIT_IPC=y
99CONFIG_GRKERNSEC_SIGNAL=y
100CONFIG_GRKERNSEC_FORKFAIL=y
101CONFIG_GRKERNSEC_TIME=y
102CONFIG_GRKERNSEC_PROC_IPADDR=y
103# CONFIG_GRKERNSEC_AUDIT_TEXTREL is not set
104
105#
106# Executable Protections
107#
108CONFIG_GRKERNSEC_EXECVE=y
109CONFIG_GRKERNSEC_SHM=y
110CONFIG_GRKERNSEC_DMESG=y
111CONFIG_GRKERNSEC_RANDPID=y
112CONFIG_GRKERNSEC_TPE=y
113CONFIG_GRKERNSEC_TPE_ALL=y
114# CONFIG_GRKERNSEC_TPE_INVERT is not set
115CONFIG_GRKERNSEC_TPE_GID=65500
116
117#
118# Network Protections
119#
120CONFIG_GRKERNSEC_RANDNET=y
121CONFIG_GRKERNSEC_SOCKET=y
122CONFIG_GRKERNSEC_SOCKET_ALL=y
123CONFIG_GRKERNSEC_SOCKET_ALL_GID=65501
124CONFIG_GRKERNSEC_SOCKET_CLIENT=y
125CONFIG_GRKERNSEC_SOCKET_CLIENT_GID=65502
126CONFIG_GRKERNSEC_SOCKET_SERVER=y
127CONFIG_GRKERNSEC_SOCKET_SERVER_GID=65503
128
129#
130# Sysctl support
131#
132CONFIG_GRKERNSEC_SYSCTL=y
133# CONFIG_GRKERNSEC_SYSCTL_ON is not set
134
135#
136# Logging Options
137#
138CONFIG_GRKERNSEC_FLOODTIME=10
139CONFIG_GRKERNSEC_FLOODBURST=10
140
141#
142# Some Netfilter stuff
143#
144CONFIG_IP_NF_MATCH_STEALTH=m
145
This page took 0.046646 seconds and 4 git commands to generate.