]> git.pld-linux.org Git - packages/kernel.git/blame - kernel-grsec.config
- typo
[packages/kernel.git] / kernel-grsec.config
CommitLineData
7f651772 1#
2# Grsecurity
3#
4CONFIG_GRKERNSEC=y
5# CONFIG_GRKERNSEC_LOW is not set
6# CONFIG_GRKERNSEC_MEDIUM is not set
7# CONFIG_GRKERNSEC_HIGH is not set
8CONFIG_GRKERNSEC_CUSTOM=y
9
10#
11# Address Space Protection
12#
13# CONFIG_GRKERNSEC_KMEM is not set
14# CONFIG_GRKERNSEC_IO is not set
15# CONFIG_GRKERNSEC_PROC_MEMMAP is not set
16CONFIG_GRKERNSEC_BRUTE=y
17CONFIG_GRKERNSEC_MODSTOP=y
18# CONFIG_GRKERNSEC_HIDESYM is not set
19
20#
21# Role Based Access Control Options
22#
23CONFIG_GRKERNSEC_ACL_HIDEKERN=y
24CONFIG_GRKERNSEC_ACL_MAXTRIES=3
25CONFIG_GRKERNSEC_ACL_TIMEOUT=30
26
27#
28# Filesystem Protections
29#
30CONFIG_GRKERNSEC_PROC=y
31# CONFIG_GRKERNSEC_PROC_USER is not set
32CONFIG_GRKERNSEC_PROC_USERGROUP=y
33CONFIG_GRKERNSEC_PROC_GID=17
34CONFIG_GRKERNSEC_PROC_ADD=y
35CONFIG_GRKERNSEC_LINK=y
36CONFIG_GRKERNSEC_FIFO=y
37CONFIG_GRKERNSEC_CHROOT=y
38CONFIG_GRKERNSEC_CHROOT_MOUNT=y
39CONFIG_GRKERNSEC_CHROOT_DOUBLE=y
40CONFIG_GRKERNSEC_CHROOT_PIVOT=y
41CONFIG_GRKERNSEC_CHROOT_CHDIR=y
42CONFIG_GRKERNSEC_CHROOT_CHMOD=y
43CONFIG_GRKERNSEC_CHROOT_FCHDIR=y
44CONFIG_GRKERNSEC_CHROOT_MKNOD=y
45CONFIG_GRKERNSEC_CHROOT_SHMAT=y
46CONFIG_GRKERNSEC_CHROOT_UNIX=y
47CONFIG_GRKERNSEC_CHROOT_FINDTASK=y
48CONFIG_GRKERNSEC_CHROOT_NICE=y
49CONFIG_GRKERNSEC_CHROOT_SYSCTL=y
50CONFIG_GRKERNSEC_CHROOT_CAPS=y
51
52#
53# Kernel Auditing
54#
55CONFIG_GRKERNSEC_AUDIT_GROUP=y
56CONFIG_GRKERNSEC_AUDIT_GID=1007
57CONFIG_GRKERNSEC_EXECLOG=y
58CONFIG_GRKERNSEC_RESLOG=y
59CONFIG_GRKERNSEC_CHROOT_EXECLOG=y
60CONFIG_GRKERNSEC_AUDIT_CHDIR=y
61CONFIG_GRKERNSEC_AUDIT_MOUNT=y
62CONFIG_GRKERNSEC_AUDIT_IPC=y
63CONFIG_GRKERNSEC_SIGNAL=y
64CONFIG_GRKERNSEC_FORKFAIL=y
65CONFIG_GRKERNSEC_TIME=y
66CONFIG_GRKERNSEC_PROC_IPADDR=y
67# CONFIG_GRKERNSEC_AUDIT_TEXTREL is not set
68
69#
70# Executable Protections
71#
72CONFIG_GRKERNSEC_EXECVE=y
73CONFIG_GRKERNSEC_SHM=y
74CONFIG_GRKERNSEC_DMESG=y
75CONFIG_GRKERNSEC_TPE=y
76CONFIG_GRKERNSEC_TPE_ALL=y
77# CONFIG_GRKERNSEC_TPE_INVERT is not set
78CONFIG_GRKERNSEC_TPE_GID=65500
79
80#
81# Network Protections
82#
83CONFIG_GRKERNSEC_RANDNET=y
84CONFIG_GRKERNSEC_SOCKET=y
85CONFIG_GRKERNSEC_SOCKET_ALL=y
86CONFIG_GRKERNSEC_SOCKET_ALL_GID=65501
87CONFIG_GRKERNSEC_SOCKET_CLIENT=y
88CONFIG_GRKERNSEC_SOCKET_CLIENT_GID=65502
89CONFIG_GRKERNSEC_SOCKET_SERVER=y
90CONFIG_GRKERNSEC_SOCKET_SERVER_GID=65503
91
92#
93# Sysctl support
94#
95CONFIG_GRKERNSEC_SYSCTL=y
96# CONFIG_GRKERNSEC_SYSCTL_ON is not set
97
98#
99# Logging Options
100#
101CONFIG_GRKERNSEC_FLOODTIME=10
102CONFIG_GRKERNSEC_FLOODBURST=10
103
104CONFIG_IP_NF_MATCH_STEALTH=m
This page took 0.114533 seconds and 4 git commands to generate.