]> git.pld-linux.org Git - packages/kernel.git/blame - kernel-grsec.config
- remove from HEAD
[packages/kernel.git] / kernel-grsec.config
CommitLineData
c9d1c54c
AM
1#
2# Grsecurity
3#
4CONFIG_GRKERNSEC=y
5# CONFIG_GRKERNSEC_LOW is not set
6# CONFIG_GRKERNSEC_MEDIUM is not set
7# CONFIG_GRKERNSEC_HIGH is not set
8CONFIG_GRKERNSEC_CUSTOM=y
9
10#
11# Address Space Protection
12#
13# CONFIG_GRKERNSEC_KMEM is not set
14# CONFIG_GRKERNSEC_IO is not set
2380c486 15# CONFIG_GRKERNSEC_PROC_MEMMAP is not set
c9d1c54c 16CONFIG_GRKERNSEC_BRUTE=y
2380c486
JR
17CONFIG_GRKERNSEC_MODSTOP=y
18# CONFIG_GRKERNSEC_HIDESYM is not set
c9d1c54c
AM
19
20#
21# Role Based Access Control Options
22#
017d2877 23# CONFIG_GRKERNSEC_NO_RBAC is not set
c9d1c54c
AM
24CONFIG_GRKERNSEC_ACL_HIDEKERN=y
25CONFIG_GRKERNSEC_ACL_MAXTRIES=3
26CONFIG_GRKERNSEC_ACL_TIMEOUT=30
27
28#
29# Filesystem Protections
30#
31CONFIG_GRKERNSEC_PROC=y
32# CONFIG_GRKERNSEC_PROC_USER is not set
33CONFIG_GRKERNSEC_PROC_USERGROUP=y
34CONFIG_GRKERNSEC_PROC_GID=17
35CONFIG_GRKERNSEC_PROC_ADD=y
36CONFIG_GRKERNSEC_LINK=y
37CONFIG_GRKERNSEC_FIFO=y
38CONFIG_GRKERNSEC_CHROOT=y
39CONFIG_GRKERNSEC_CHROOT_MOUNT=y
40CONFIG_GRKERNSEC_CHROOT_DOUBLE=y
41CONFIG_GRKERNSEC_CHROOT_PIVOT=y
42CONFIG_GRKERNSEC_CHROOT_CHDIR=y
43CONFIG_GRKERNSEC_CHROOT_CHMOD=y
44CONFIG_GRKERNSEC_CHROOT_FCHDIR=y
45CONFIG_GRKERNSEC_CHROOT_MKNOD=y
46CONFIG_GRKERNSEC_CHROOT_SHMAT=y
47CONFIG_GRKERNSEC_CHROOT_UNIX=y
48CONFIG_GRKERNSEC_CHROOT_FINDTASK=y
49CONFIG_GRKERNSEC_CHROOT_NICE=y
50CONFIG_GRKERNSEC_CHROOT_SYSCTL=y
51CONFIG_GRKERNSEC_CHROOT_CAPS=y
52
53#
54# Kernel Auditing
55#
2380c486
JR
56CONFIG_GRKERNSEC_AUDIT_GROUP=y
57CONFIG_GRKERNSEC_AUDIT_GID=1007
58CONFIG_GRKERNSEC_EXECLOG=y
c9d1c54c 59CONFIG_GRKERNSEC_RESLOG=y
2380c486
JR
60CONFIG_GRKERNSEC_CHROOT_EXECLOG=y
61CONFIG_GRKERNSEC_AUDIT_CHDIR=y
62CONFIG_GRKERNSEC_AUDIT_MOUNT=y
63CONFIG_GRKERNSEC_AUDIT_IPC=y
c9d1c54c
AM
64CONFIG_GRKERNSEC_SIGNAL=y
65CONFIG_GRKERNSEC_FORKFAIL=y
66CONFIG_GRKERNSEC_TIME=y
67CONFIG_GRKERNSEC_PROC_IPADDR=y
2380c486 68CONFIG_GRKERNSEC_AUDIT_TEXTREL=y
c9d1c54c
AM
69
70#
71# Executable Protections
72#
73CONFIG_GRKERNSEC_EXECVE=y
74CONFIG_GRKERNSEC_DMESG=y
2380c486
JR
75CONFIG_GRKERNSEC_TPE=y
76CONFIG_GRKERNSEC_TPE_ALL=y
77# CONFIG_GRKERNSEC_TPE_INVERT is not set
78CONFIG_GRKERNSEC_TPE_GID=65500
c9d1c54c
AM
79
80#
81# Network Protections
82#
83CONFIG_GRKERNSEC_RANDNET=y
c9d1c54c
AM
84CONFIG_GRKERNSEC_SOCKET=y
85CONFIG_GRKERNSEC_SOCKET_ALL=y
86CONFIG_GRKERNSEC_SOCKET_ALL_GID=65501
87CONFIG_GRKERNSEC_SOCKET_CLIENT=y
88CONFIG_GRKERNSEC_SOCKET_CLIENT_GID=65502
89CONFIG_GRKERNSEC_SOCKET_SERVER=y
90CONFIG_GRKERNSEC_SOCKET_SERVER_GID=65503
1519b3d4 91# CONFIG_GRKERNSEC_BLACKHOLE is not set
c9d1c54c
AM
92
93#
94# Sysctl support
95#
96CONFIG_GRKERNSEC_SYSCTL=y
2380c486 97# CONFIG_GRKERNSEC_SYSCTL_ON is not set
c9d1c54c
AM
98
99#
100# Logging Options
101#
102CONFIG_GRKERNSEC_FLOODTIME=10
2380c486 103CONFIG_GRKERNSEC_FLOODBURST=10
c9d1c54c 104
2380c486 105CONFIG_IP_NF_MATCH_STEALTH=m
This page took 0.637283 seconds and 4 git commands to generate.