]>
Commit | Line | Data |
---|---|---|
c9d1c54c AM |
1 | # |
2 | # Grsecurity | |
3 | # | |
4 | CONFIG_GRKERNSEC=y | |
5 | # CONFIG_GRKERNSEC_LOW is not set | |
6 | # CONFIG_GRKERNSEC_MEDIUM is not set | |
7 | # CONFIG_GRKERNSEC_HIGH is not set | |
8 | CONFIG_GRKERNSEC_CUSTOM=y | |
9 | ||
10 | # | |
11 | # Address Space Protection | |
12 | # | |
13 | # CONFIG_GRKERNSEC_KMEM is not set | |
14 | # CONFIG_GRKERNSEC_IO is not set | |
2380c486 | 15 | # CONFIG_GRKERNSEC_PROC_MEMMAP is not set |
c9d1c54c | 16 | CONFIG_GRKERNSEC_BRUTE=y |
2380c486 JR |
17 | CONFIG_GRKERNSEC_MODSTOP=y |
18 | # CONFIG_GRKERNSEC_HIDESYM is not set | |
49cd8c1d | 19 | # CONFIG_GRKERNSEC_KERN_LOCKOUT is not set |
c9d1c54c | 20 | |
87f702c5 | 21 | CONFIG_GRKERNSEC_VM86=y |
22 | ||
c9d1c54c AM |
23 | # |
24 | # Role Based Access Control Options | |
25 | # | |
017d2877 | 26 | # CONFIG_GRKERNSEC_NO_RBAC is not set |
c9d1c54c AM |
27 | CONFIG_GRKERNSEC_ACL_HIDEKERN=y |
28 | CONFIG_GRKERNSEC_ACL_MAXTRIES=3 | |
29 | CONFIG_GRKERNSEC_ACL_TIMEOUT=30 | |
30 | ||
31 | # | |
32 | # Filesystem Protections | |
33 | # | |
34 | CONFIG_GRKERNSEC_PROC=y | |
35 | # CONFIG_GRKERNSEC_PROC_USER is not set | |
36 | CONFIG_GRKERNSEC_PROC_USERGROUP=y | |
37 | CONFIG_GRKERNSEC_PROC_GID=17 | |
38 | CONFIG_GRKERNSEC_PROC_ADD=y | |
39 | CONFIG_GRKERNSEC_LINK=y | |
40 | CONFIG_GRKERNSEC_FIFO=y | |
49cd8c1d | 41 | CONFIG_GRKERNSEC_SYSFS_RESTRICT=y |
db2ff2a6 | 42 | CONFIG_GRKERNSEC_ROFS=y |
c9d1c54c AM |
43 | CONFIG_GRKERNSEC_CHROOT=y |
44 | CONFIG_GRKERNSEC_CHROOT_MOUNT=y | |
45 | CONFIG_GRKERNSEC_CHROOT_DOUBLE=y | |
46 | CONFIG_GRKERNSEC_CHROOT_PIVOT=y | |
47 | CONFIG_GRKERNSEC_CHROOT_CHDIR=y | |
48 | CONFIG_GRKERNSEC_CHROOT_CHMOD=y | |
49 | CONFIG_GRKERNSEC_CHROOT_FCHDIR=y | |
50 | CONFIG_GRKERNSEC_CHROOT_MKNOD=y | |
51 | CONFIG_GRKERNSEC_CHROOT_SHMAT=y | |
52 | CONFIG_GRKERNSEC_CHROOT_UNIX=y | |
53 | CONFIG_GRKERNSEC_CHROOT_FINDTASK=y | |
54 | CONFIG_GRKERNSEC_CHROOT_NICE=y | |
55 | CONFIG_GRKERNSEC_CHROOT_SYSCTL=y | |
56 | CONFIG_GRKERNSEC_CHROOT_CAPS=y | |
57 | ||
58 | # | |
59 | # Kernel Auditing | |
60 | # | |
2380c486 JR |
61 | CONFIG_GRKERNSEC_AUDIT_GROUP=y |
62 | CONFIG_GRKERNSEC_AUDIT_GID=1007 | |
63 | CONFIG_GRKERNSEC_EXECLOG=y | |
c9d1c54c | 64 | CONFIG_GRKERNSEC_RESLOG=y |
2380c486 | 65 | CONFIG_GRKERNSEC_CHROOT_EXECLOG=y |
530d557d | 66 | CONFIG_GRKERNSEC_AUDIT_PTRACE=y |
2380c486 JR |
67 | CONFIG_GRKERNSEC_AUDIT_CHDIR=y |
68 | CONFIG_GRKERNSEC_AUDIT_MOUNT=y | |
69 | CONFIG_GRKERNSEC_AUDIT_IPC=y | |
c9d1c54c AM |
70 | CONFIG_GRKERNSEC_SIGNAL=y |
71 | CONFIG_GRKERNSEC_FORKFAIL=y | |
72 | CONFIG_GRKERNSEC_TIME=y | |
73 | CONFIG_GRKERNSEC_PROC_IPADDR=y | |
2380c486 | 74 | CONFIG_GRKERNSEC_AUDIT_TEXTREL=y |
c9d1c54c AM |
75 | |
76 | # | |
77 | # Executable Protections | |
78 | # | |
79 | CONFIG_GRKERNSEC_EXECVE=y | |
80 | CONFIG_GRKERNSEC_DMESG=y | |
49cd8c1d | 81 | CONFIG_GRKERNSEC_HARDEN_PTRACE=y |
82 | CONFIG_GRKERNSEC_PTRACE_READEXEC=y | |
83 | CONFIG_GRKERNSEC_SETXID=y | |
2380c486 JR |
84 | CONFIG_GRKERNSEC_TPE=y |
85 | CONFIG_GRKERNSEC_TPE_ALL=y | |
86 | # CONFIG_GRKERNSEC_TPE_INVERT is not set | |
87 | CONFIG_GRKERNSEC_TPE_GID=65500 | |
c9d1c54c AM |
88 | |
89 | # | |
90 | # Network Protections | |
91 | # | |
92 | CONFIG_GRKERNSEC_RANDNET=y | |
c9d1c54c AM |
93 | CONFIG_GRKERNSEC_SOCKET=y |
94 | CONFIG_GRKERNSEC_SOCKET_ALL=y | |
95 | CONFIG_GRKERNSEC_SOCKET_ALL_GID=65501 | |
96 | CONFIG_GRKERNSEC_SOCKET_CLIENT=y | |
97 | CONFIG_GRKERNSEC_SOCKET_CLIENT_GID=65502 | |
98 | CONFIG_GRKERNSEC_SOCKET_SERVER=y | |
99 | CONFIG_GRKERNSEC_SOCKET_SERVER_GID=65503 | |
1519b3d4 | 100 | # CONFIG_GRKERNSEC_BLACKHOLE is not set |
c9d1c54c AM |
101 | |
102 | # | |
103 | # Sysctl support | |
104 | # | |
105 | CONFIG_GRKERNSEC_SYSCTL=y | |
2380c486 | 106 | # CONFIG_GRKERNSEC_SYSCTL_ON is not set |
c9d1c54c AM |
107 | |
108 | # | |
109 | # Logging Options | |
110 | # | |
111 | CONFIG_GRKERNSEC_FLOODTIME=10 | |
2380c486 | 112 | CONFIG_GRKERNSEC_FLOODBURST=10 |
c9d1c54c | 113 | |
2380c486 | 114 | CONFIG_IP_NF_MATCH_STEALTH=m |
98c4004c | 115 | |
6613b898 | 116 | # CONFIG_GRKERNSEC_MODHARDEN is not set |
49cd8c1d | 117 | # CONFIG_PAX_MEMORY_STACKLEAK is not set |