]> git.pld-linux.org Git - packages/kernel.git/blame - kernel-grsec.config
- obsolete
[packages/kernel.git] / kernel-grsec.config
CommitLineData
c9d1c54c
AM
1#
2# Grsecurity
3#
4CONFIG_GRKERNSEC=y
5# CONFIG_GRKERNSEC_LOW is not set
6# CONFIG_GRKERNSEC_MEDIUM is not set
7# CONFIG_GRKERNSEC_HIGH is not set
8CONFIG_GRKERNSEC_CUSTOM=y
9
10#
11# Address Space Protection
12#
13# CONFIG_GRKERNSEC_KMEM is not set
14# CONFIG_GRKERNSEC_IO is not set
15CONFIG_GRKERNSEC_PROC_MEMMAP=y
16CONFIG_GRKERNSEC_BRUTE=y
17CONFIG_GRKERNSEC_HIDESYM=y
18
19#
20# Role Based Access Control Options
21#
22CONFIG_GRKERNSEC_ACL_HIDEKERN=y
23CONFIG_GRKERNSEC_ACL_MAXTRIES=3
24CONFIG_GRKERNSEC_ACL_TIMEOUT=30
25
26#
27# Filesystem Protections
28#
29CONFIG_GRKERNSEC_PROC=y
30# CONFIG_GRKERNSEC_PROC_USER is not set
31CONFIG_GRKERNSEC_PROC_USERGROUP=y
32CONFIG_GRKERNSEC_PROC_GID=17
33CONFIG_GRKERNSEC_PROC_ADD=y
34CONFIG_GRKERNSEC_LINK=y
35CONFIG_GRKERNSEC_FIFO=y
36CONFIG_GRKERNSEC_CHROOT=y
37CONFIG_GRKERNSEC_CHROOT_MOUNT=y
38CONFIG_GRKERNSEC_CHROOT_DOUBLE=y
39CONFIG_GRKERNSEC_CHROOT_PIVOT=y
40CONFIG_GRKERNSEC_CHROOT_CHDIR=y
41CONFIG_GRKERNSEC_CHROOT_CHMOD=y
42CONFIG_GRKERNSEC_CHROOT_FCHDIR=y
43CONFIG_GRKERNSEC_CHROOT_MKNOD=y
44CONFIG_GRKERNSEC_CHROOT_SHMAT=y
45CONFIG_GRKERNSEC_CHROOT_UNIX=y
46CONFIG_GRKERNSEC_CHROOT_FINDTASK=y
47CONFIG_GRKERNSEC_CHROOT_NICE=y
48CONFIG_GRKERNSEC_CHROOT_SYSCTL=y
49CONFIG_GRKERNSEC_CHROOT_CAPS=y
50
51#
52# Kernel Auditing
53#
54# CONFIG_GRKERNSEC_AUDIT_GROUP is not set
55# CONFIG_GRKERNSEC_EXECLOG is not set
56CONFIG_GRKERNSEC_RESLOG=y
57# CONFIG_GRKERNSEC_CHROOT_EXECLOG is not set
58# CONFIG_GRKERNSEC_AUDIT_CHDIR is not set
59# CONFIG_GRKERNSEC_AUDIT_MOUNT is not set
60# CONFIG_GRKERNSEC_AUDIT_IPC is not set
61CONFIG_GRKERNSEC_SIGNAL=y
62CONFIG_GRKERNSEC_FORKFAIL=y
63CONFIG_GRKERNSEC_TIME=y
64CONFIG_GRKERNSEC_PROC_IPADDR=y
65# CONFIG_GRKERNSEC_AUDIT_TEXTREL is not set
66
67#
68# Executable Protections
69#
70CONFIG_GRKERNSEC_EXECVE=y
71CONFIG_GRKERNSEC_DMESG=y
72CONFIG_GRKERNSEC_RANDPID=y
73# CONFIG_GRKERNSEC_TPE is not set
74
75#
76# Network Protections
77#
78CONFIG_GRKERNSEC_RANDNET=y
79CONFIG_GRKERNSEC_RANDISN=y
80CONFIG_GRKERNSEC_RANDID=y
81CONFIG_GRKERNSEC_RANDSRC=y
82CONFIG_GRKERNSEC_RANDRPC=y
83CONFIG_GRKERNSEC_SOCKET=y
84CONFIG_GRKERNSEC_SOCKET_ALL=y
85CONFIG_GRKERNSEC_SOCKET_ALL_GID=65501
86CONFIG_GRKERNSEC_SOCKET_CLIENT=y
87CONFIG_GRKERNSEC_SOCKET_CLIENT_GID=65502
88CONFIG_GRKERNSEC_SOCKET_SERVER=y
89CONFIG_GRKERNSEC_SOCKET_SERVER_GID=65503
90
91#
92# Sysctl support
93#
94CONFIG_GRKERNSEC_SYSCTL=y
95
96#
97# Logging Options
98#
99CONFIG_GRKERNSEC_FLOODTIME=10
100CONFIG_GRKERNSEC_FLOODBURST=4
101
102#
103# PaX
104#
105# CONFIG_PAX is not set
This page took 0.192984 seconds and 4 git commands to generate.