]> git.pld-linux.org Git - packages/kernel.git/blame - kernel-grsec.config
- 3.4.85
[packages/kernel.git] / kernel-grsec.config
CommitLineData
c9d1c54c
AM
1#
2# Grsecurity
3#
4CONFIG_GRKERNSEC=y
5# CONFIG_GRKERNSEC_LOW is not set
6# CONFIG_GRKERNSEC_MEDIUM is not set
7# CONFIG_GRKERNSEC_HIGH is not set
8CONFIG_GRKERNSEC_CUSTOM=y
9
10#
11# Address Space Protection
12#
13# CONFIG_GRKERNSEC_KMEM is not set
14# CONFIG_GRKERNSEC_IO is not set
2380c486 15# CONFIG_GRKERNSEC_PROC_MEMMAP is not set
3afa173a 16# CONFIG_GRKERNSEC_BRUTE is not set
2380c486
JR
17CONFIG_GRKERNSEC_MODSTOP=y
18# CONFIG_GRKERNSEC_HIDESYM is not set
6a36902e 19# CONFIG_GRKERNSEC_KERN_LOCKOUT is not set
c9d1c54c 20
87f702c5 21CONFIG_GRKERNSEC_VM86=y
22
c9d1c54c
AM
23#
24# Role Based Access Control Options
25#
017d2877 26# CONFIG_GRKERNSEC_NO_RBAC is not set
c9d1c54c
AM
27CONFIG_GRKERNSEC_ACL_HIDEKERN=y
28CONFIG_GRKERNSEC_ACL_MAXTRIES=3
29CONFIG_GRKERNSEC_ACL_TIMEOUT=30
30
31#
32# Filesystem Protections
33#
34CONFIG_GRKERNSEC_PROC=y
35# CONFIG_GRKERNSEC_PROC_USER is not set
36CONFIG_GRKERNSEC_PROC_USERGROUP=y
37CONFIG_GRKERNSEC_PROC_GID=17
38CONFIG_GRKERNSEC_PROC_ADD=y
39CONFIG_GRKERNSEC_LINK=y
40CONFIG_GRKERNSEC_FIFO=y
db2ff2a6 41CONFIG_GRKERNSEC_ROFS=y
c9d1c54c
AM
42CONFIG_GRKERNSEC_CHROOT=y
43CONFIG_GRKERNSEC_CHROOT_MOUNT=y
44CONFIG_GRKERNSEC_CHROOT_DOUBLE=y
45CONFIG_GRKERNSEC_CHROOT_PIVOT=y
46CONFIG_GRKERNSEC_CHROOT_CHDIR=y
47CONFIG_GRKERNSEC_CHROOT_CHMOD=y
48CONFIG_GRKERNSEC_CHROOT_FCHDIR=y
49CONFIG_GRKERNSEC_CHROOT_MKNOD=y
50CONFIG_GRKERNSEC_CHROOT_SHMAT=y
51CONFIG_GRKERNSEC_CHROOT_UNIX=y
52CONFIG_GRKERNSEC_CHROOT_FINDTASK=y
53CONFIG_GRKERNSEC_CHROOT_NICE=y
54CONFIG_GRKERNSEC_CHROOT_SYSCTL=y
55CONFIG_GRKERNSEC_CHROOT_CAPS=y
56
57#
58# Kernel Auditing
59#
2380c486
JR
60CONFIG_GRKERNSEC_AUDIT_GROUP=y
61CONFIG_GRKERNSEC_AUDIT_GID=1007
62CONFIG_GRKERNSEC_EXECLOG=y
c9d1c54c 63CONFIG_GRKERNSEC_RESLOG=y
2380c486
JR
64CONFIG_GRKERNSEC_CHROOT_EXECLOG=y
65CONFIG_GRKERNSEC_AUDIT_CHDIR=y
66CONFIG_GRKERNSEC_AUDIT_MOUNT=y
67CONFIG_GRKERNSEC_AUDIT_IPC=y
62cca95f 68CONFIG_GRKERNSEC_AUDIT_PTRACE=y
c9d1c54c
AM
69CONFIG_GRKERNSEC_SIGNAL=y
70CONFIG_GRKERNSEC_FORKFAIL=y
71CONFIG_GRKERNSEC_TIME=y
72CONFIG_GRKERNSEC_PROC_IPADDR=y
2380c486 73CONFIG_GRKERNSEC_AUDIT_TEXTREL=y
c9d1c54c
AM
74
75#
76# Executable Protections
77#
78CONFIG_GRKERNSEC_EXECVE=y
79CONFIG_GRKERNSEC_DMESG=y
2380c486
JR
80CONFIG_GRKERNSEC_TPE=y
81CONFIG_GRKERNSEC_TPE_ALL=y
82# CONFIG_GRKERNSEC_TPE_INVERT is not set
83CONFIG_GRKERNSEC_TPE_GID=65500
c9d1c54c
AM
84
85#
86# Network Protections
87#
88CONFIG_GRKERNSEC_RANDNET=y
c9d1c54c
AM
89CONFIG_GRKERNSEC_SOCKET=y
90CONFIG_GRKERNSEC_SOCKET_ALL=y
91CONFIG_GRKERNSEC_SOCKET_ALL_GID=65501
92CONFIG_GRKERNSEC_SOCKET_CLIENT=y
93CONFIG_GRKERNSEC_SOCKET_CLIENT_GID=65502
94CONFIG_GRKERNSEC_SOCKET_SERVER=y
95CONFIG_GRKERNSEC_SOCKET_SERVER_GID=65503
1519b3d4 96# CONFIG_GRKERNSEC_BLACKHOLE is not set
c9d1c54c
AM
97
98#
99# Sysctl support
100#
101CONFIG_GRKERNSEC_SYSCTL=y
2380c486 102# CONFIG_GRKERNSEC_SYSCTL_ON is not set
c9d1c54c
AM
103
104#
105# Logging Options
106#
107CONFIG_GRKERNSEC_FLOODTIME=10
2380c486 108CONFIG_GRKERNSEC_FLOODBURST=10
c9d1c54c 109
2380c486 110CONFIG_IP_NF_MATCH_STEALTH=m
98c4004c 111
6613b898 112# CONFIG_GRKERNSEC_MODHARDEN is not set
98c4004c 113CONFIG_GRKERNSEC_HARDEN_PTRACE=y
53fda8d6
AM
114
115# Networking
116CONFIG_NETFILTER_XT_MATCH_GRADM=m
410dbfd4 117CONFIG_GRKERNSEC_SYSFS_RESTRICT=n
This page took 0.142183 seconds and 4 git commands to generate.