]> git.pld-linux.org Git - packages/kernel.git/blame - kernel-grsec.config
- rel 2; fix for local root hole CVE-2007-4573
[packages/kernel.git] / kernel-grsec.config
CommitLineData
c6410bf7 1#
2# Grsecurity
3#
4CONFIG_GRKERNSEC=y
5# CONFIG_GRKERNSEC_LOW is not set
6# CONFIG_GRKERNSEC_MEDIUM is not set
7# CONFIG_GRKERNSEC_HIGH is not set
8CONFIG_GRKERNSEC_CUSTOM=y
9
10#
11# Address Space Protection
12#
13# CONFIG_GRKERNSEC_KMEM is not set
14# CONFIG_GRKERNSEC_IO is not set
15CONFIG_GRKERNSEC_BRUTE=y
16CONFIG_GRKERNSEC_MODSTOP=y
17# CONFIG_GRKERNSEC_HIDESYM is not set
18
19#
20# Role Based Access Control Options
21#
22CONFIG_GRKERNSEC_ACL_HIDEKERN=y
23CONFIG_GRKERNSEC_ACL_MAXTRIES=3
24CONFIG_GRKERNSEC_ACL_TIMEOUT=30
25
26#
27# Filesystem Protections
28#
29CONFIG_GRKERNSEC_PROC=y
30# CONFIG_GRKERNSEC_PROC_USER is not set
31CONFIG_GRKERNSEC_PROC_USERGROUP=y
32CONFIG_GRKERNSEC_PROC_GID=17
33CONFIG_GRKERNSEC_PROC_ADD=y
34CONFIG_GRKERNSEC_LINK=y
35CONFIG_GRKERNSEC_FIFO=y
36CONFIG_GRKERNSEC_CHROOT=y
37CONFIG_GRKERNSEC_CHROOT_MOUNT=y
38CONFIG_GRKERNSEC_CHROOT_DOUBLE=y
39CONFIG_GRKERNSEC_CHROOT_PIVOT=y
40CONFIG_GRKERNSEC_CHROOT_CHDIR=y
41CONFIG_GRKERNSEC_CHROOT_CHMOD=y
42CONFIG_GRKERNSEC_CHROOT_FCHDIR=y
43CONFIG_GRKERNSEC_CHROOT_MKNOD=y
44CONFIG_GRKERNSEC_CHROOT_SHMAT=y
45CONFIG_GRKERNSEC_CHROOT_UNIX=y
46CONFIG_GRKERNSEC_CHROOT_FINDTASK=y
47CONFIG_GRKERNSEC_CHROOT_NICE=y
48CONFIG_GRKERNSEC_CHROOT_SYSCTL=y
49CONFIG_GRKERNSEC_CHROOT_CAPS=y
50
51#
52# Kernel Auditing
53#
54CONFIG_GRKERNSEC_AUDIT_GROUP=y
55CONFIG_GRKERNSEC_AUDIT_GID=1007
56CONFIG_GRKERNSEC_EXECLOG=y
57CONFIG_GRKERNSEC_RESLOG=y
58CONFIG_GRKERNSEC_CHROOT_EXECLOG=y
59CONFIG_GRKERNSEC_AUDIT_CHDIR=y
60CONFIG_GRKERNSEC_AUDIT_MOUNT=y
61CONFIG_GRKERNSEC_AUDIT_IPC=y
62CONFIG_GRKERNSEC_SIGNAL=y
63CONFIG_GRKERNSEC_FORKFAIL=y
64CONFIG_GRKERNSEC_TIME=y
65CONFIG_GRKERNSEC_PROC_IPADDR=y
66# CONFIG_GRKERNSEC_AUDIT_TEXTREL is not set
67
68#
69# Executable Protections
70#
71CONFIG_GRKERNSEC_EXECVE=y
72CONFIG_GRKERNSEC_SHM=y
73CONFIG_GRKERNSEC_DMESG=y
74CONFIG_GRKERNSEC_RANDPID=y
75CONFIG_GRKERNSEC_TPE=y
76CONFIG_GRKERNSEC_TPE_ALL=y
77# CONFIG_GRKERNSEC_TPE_INVERT is not set
78CONFIG_GRKERNSEC_TPE_GID=65500
79
80#
81# Network Protections
82#
83CONFIG_GRKERNSEC_RANDNET=y
84CONFIG_GRKERNSEC_SOCKET=y
85CONFIG_GRKERNSEC_SOCKET_ALL=y
86CONFIG_GRKERNSEC_SOCKET_ALL_GID=65501
87CONFIG_GRKERNSEC_SOCKET_CLIENT=y
88CONFIG_GRKERNSEC_SOCKET_CLIENT_GID=65502
89CONFIG_GRKERNSEC_SOCKET_SERVER=y
90CONFIG_GRKERNSEC_SOCKET_SERVER_GID=65503
91
92#
93# Sysctl support
94#
95CONFIG_GRKERNSEC_SYSCTL=y
96# CONFIG_GRKERNSEC_SYSCTL_ON is not set
97
98#
99# Logging Options
100#
101CONFIG_GRKERNSEC_FLOODTIME=10
102CONFIG_GRKERNSEC_FLOODBURST=10
103
104#
105# PaX
106#
107# CONFIG_PAX is not set
108
109CONFIG_IP_NF_MATCH_STEALTH=m
This page took 0.083772 seconds and 4 git commands to generate.