2021-04-04 01:09:26 -04:00
#!/bin/bash
#Please note that this is how I PERSONALLY setup my computer - I do some stuff such as not using anything to download GNOME extensions from extensions.gnome.org and installing the extensions as a package instead
#Customize it to your liking
#Run this script as your user, NOT root
2021-04-04 05:19:59 -04:00
#Note: BTRFS Setup is not included in this script. I highly recommend using encrypted ZFS instead: https://linsomniac.gitlab.io/post/2020-04-09-ubuntu-2004-encrypted-zfs/
2021-04-04 01:09:26 -04:00
#Written by yours truly, Tomster
#Variables
USER = $( whoami)
output( ) {
echo -e '\e[36m' $1 '\e[0m' ;
}
2021-04-04 06:35:46 -04:00
promptPassphrase( ) {
PASS = ""
PASSCONF = ""
while [ -z " $PASS " ] ; do
read -s -p "Passphrase: " PASS
echo ""
done
while [ -z " $PASSCONF " ] ; do
read -s -p "Confirm passphrase: " PASSCONF
echo ""
done
echo ""
}
getPassphrase( ) {
promptPassphrase
while [ " $PASS " != " $PASSCONF " ] ; do
output "Passphrases did not match, try again..."
promptPassphrase
done
}
2021-04-04 01:09:26 -04:00
#Moving to the home directory
#Note that I always use /home/${USER} because gnome-terminal is wacky and sometimes doesn't load the environment variables in correctly (Right click somewhere in nautilus, click on open in terminal, then hit create new tab and you will see.)
cd /home/${ USER } || exit
#Setting umask to 077
umask 077
2021-04-04 06:43:36 -04:00
sudo sed -ie '/^DIR_MODE=/ s/=[0-9]*\+/=0700/' /etc/adduser.conf
sudo sed -ie '/^UMASK\s\+/ s/022/077/' /etc/login.defs
2021-04-04 04:52:51 -04:00
echo "umask 077" | sudo tee --append /etc/profile
2021-04-04 01:09:26 -04:00
2021-04-04 06:10:27 -04:00
#Disabling shell access for new users
2021-04-04 06:43:36 -04:00
sudo sed -ie '/^SHELL=/ s/=.*\+/=\/usr\/sbin\/nologin/' /etc/default/useradd
sudo sed -ie '/^DSHELL=/ s/=.*\+/=\/usr\/sbin\/nologin/' /etc/adduser.conf
#Disabling su for normal users
sudo dpkg-statoverride --update --add root adm 4750 /bin/su
2021-04-04 06:10:27 -04:00
2021-04-04 05:12:54 -04:00
#Make home directory private
chmod -R o-rwx /home/${ USER }
2021-04-04 06:43:36 -04:00
chmod -R g-rwx /home/${ USER }
2021-04-04 05:12:54 -04:00
2021-04-04 05:46:40 -04:00
#Remove unnecessary permissions
2021-04-04 05:46:57 -04:00
sudo chmod o-w /var/crash
sudo chmod o-w /var/metrics
sudo chmod o-w /var/tmp
2021-04-04 05:46:40 -04:00
2021-04-04 05:50:35 -04:00
#Disable crash reports
gsettings set com.ubuntu.update-notifier show-apport-crashes false
ubuntu-report -f send no
2021-04-04 06:04:37 -04:00
sudo systemctl stop apport.service
sudo systemctl disable apport.service
sudo systemctl mask apport.service
sudo systemctl stop whoopsie.service
sudo systemctl disable whoopsie.service
sudo systemctl mask whoopsie.service
2021-04-04 05:50:35 -04:00
2021-04-04 01:09:26 -04:00
#Disable ptrace
2021-04-04 05:05:59 -04:00
echo "kernel.yama.ptrace_scope = 3" | sudo tee /etc/sysctl.d/10-default-yama-scope.conf
2021-04-04 01:09:26 -04:00
sudo sysctl --load= /etc/sysctl.d/10-default-yama-scope.conf
2021-04-04 05:58:20 -04:00
#Blacklist Firewire SBP2
echo "blacklist firewire-sbp2" | sudo tee /etc/modprobe.d/blacklist.conf
2021-04-04 06:32:41 -04:00
#GRUB hardening (Thanks to https://www.ncsc.gov.uk/collection/end-user-device-security/platform-specific-guidance/ubuntu-18-04-lts)
echo -e " ${ HIGHLIGHT } Configuring grub... ${ NC } "
2021-04-04 06:35:46 -04:00
output "Please enter a grub sysadmin passphrase..."
2021-04-04 06:32:41 -04:00
getPassphrase
echo "set superusers=\"sysadmin\"" >> /etc/grub.d/40_custom
echo -e " $PASS \n $PASS " | grub-mkpasswd-pbkdf2 | tail -n1 | awk -F" " '{print "password_pbkdf2 sysadmin " $7}' >> /etc/grub.d/40_custom
sed -ie '/echo "menuentry / s/echo "menuentry /echo "menuentry --unrestricted /' /etc/grub.d/10_linux
sed -ie '/^GRUB_CMDLINE_LINUX_DEFAULT=/ s/"$/ module.sig_enforce=yes"/' /etc/default/grub
echo "GRUB_SAVEDEFAULT=false" >> /etc/default/grub
update-grub
2021-04-04 01:11:05 -04:00
#Enable UFW
2021-04-04 01:09:26 -04:00
sudo ufw enable
#Update packages and firmware
2021-04-04 01:11:05 -04:00
sudo apt update
sudo apt upgrade -y
sudp apt autoremove -y
2021-04-04 01:09:26 -04:00
sudo fwupdmgr get-devices
sudo fwupdmgr refresh --force
sudo fwupdmgr get-updates
sudo fwupdmgr update -y
#Remove unneeded packages
2021-04-04 05:55:01 -04:00
#Note that I remove unattended upgrades because GNOME Software will be handling auto updates
sudo apt purge gnome-calculator *evince* *seahorse* *gedit* *yelp* gnome-screenshot gnome-power-manager eog gnome-logs gnome-characters gnome-shell-extension-desktop-icons gnome-font-viewer *file-roller* cups* printer-driver* network-manager-pptp* network-manager-openvpn* *nfs* aaport* telnet *spice* tcpdump firefox* gnome-disk* gnome-initial-setup ubuntu-report popularity-contest whoopsie speech-dispatcher modemmanager avahi* gnome-shell-extension-ubuntu-dock mobile-broadband-provider-info ImageMagick* adcli libreoffice* ntfs* xfs* tracker* thermald sane* simple-scan *hangul* unattended-upgrades -y
2021-04-04 01:20:37 -04:00
sudo apt autoremove -y
2021-04-04 01:22:36 -04:00
sudo snap remove snap-store
2021-04-04 01:09:26 -04:00
#Install packages that I use
2021-04-04 01:26:48 -04:00
sudo add-apt-repository ppa:alexlarsson/flatpak -y
sudo apt update
2021-04-04 01:28:15 -04:00
sudo apt upgrade -y
2021-04-04 05:21:52 -04:00
sudo apt -y install neofetch gnome-software flatpak gnome-software-plugin-flatpak firejail apparmor-profiles apparmor-profiles-extra apparmor-utils gnome-tweak-tool git-core sudo apt install gnome-session-wayland
2021-04-04 01:09:26 -04:00
2021-04-04 05:08:24 -04:00
#Put all AppArmor profiles into enforcing mode
sudo aa-enforce /etc/apparmor. d/*
2021-04-04 04:52:51 -04:00
#Install Yubico Stuff
2021-04-04 05:41:14 -04:00
sudo apt -y install libpam-u2f
2021-04-04 01:09:26 -04:00
mkdir -p /home/${ USER } /.config/Yubico
#Install IVPN
2021-04-04 03:26:27 -04:00
curl -fsSL https://repo.ivpn.net/stable/ubuntu/generic.gpg | sudo apt-key add -
curl -fsSL https://repo.ivpn.net/stable/ubuntu/generic.list | sudo tee /etc/apt/sources.list.d/ivpn.list
2021-04-04 04:17:40 -04:00
sudo chmod 644 /etc/apt/sources.list.d/ivpn.list
2021-04-04 03:26:27 -04:00
sudo apt update
sudo apt upgrade -y
sudo apt install ivpn-ui -y
2021-04-04 01:09:26 -04:00
#Install OpenSnitch
2021-04-04 04:52:51 -04:00
sudo apt install -y https://github.com/evilsocket/opensnitch/releases/download/v1.3.6/opensnitch_1.3.6-1_amd64.deb
sudo apt install -y https://github.com/evilsocket/opensnitch/releases/download/v1.3.6/python3-opensnitch-ui_1.3.6-1_all.deb
2021-04-04 01:09:26 -04:00
sudo chmod -R $USER :USER /home/${ USER } /.config/autostart
#Setup VSCodium
2021-04-04 04:17:40 -04:00
wget -qO - https://gitlab.com/paulcarroty/vscodium-deb-rpm-repo/raw/master/pub.gpg | gpg --dearmor | sudo dd of = /etc/apt/trusted.gpg.d/vscodium.gpg
sudo chmod 644 /etc/apt/trusted.gpg.d/vscodium.gpg
echo 'deb https://paulcarroty.gitlab.io/vscodium-deb-rpm-repo/debs/ vscodium main' | sudo tee --append /etc/apt/sources.list.d/vscodium.list
sudo chmod 644 /etc/apt/sources.list.d/vscodium.list
2021-04-04 04:20:37 -04:00
sudo apt update
sudo apt upgrade -y
2021-04-04 04:17:40 -04:00
sudo apt install -y codium
2021-04-04 01:09:26 -04:00
sudo cp /etc/firejail/vscodium.profile /etc/firejail/codium.profile
sudo chmod 644 /etc/firejail/codium.profile
#Setting up Flatpak
flatpak remote-add --user flathub https://flathub.org/repo/flathub.flatpakrepo
2021-04-04 02:08:52 -04:00
flatpak remote-add --user flathub-beta https://flathub.org/beta-repo/flathub-beta.flatpakrepo
2021-04-04 01:09:26 -04:00
flatpak remove --unused
#Install default applications
flatpak install flathub com.github.tchx84.Flatseal org.mozilla.firefox org.videolan.VLC org.gnome.eog org.gnome.Calendar org.gnome.Contacts org.gnome.FileRoller com.yubico.yubioath -y
#Enable auto TRIM
sudo systemctl enable fstrim.timer
#Enable Firejail
sudo firecfg
#Download and set icon theme
git clone https://github.com/NicoHood/arc-icon-theme.git
mkdir /home/${ USER } /.icons
ln -s /home/${ USER } /arc-icon-theme/Arc /home/${ USER } /.icons/
git clone https://github.com/zayronxio/Mojave-CT.git
ln -s /home/${ USER } /Mojave-CT /home/${ USER } /.icons/
sed -i 's/Inherits=Moka,Adwaita,gnome,hicolor/Inherits=Mojave-CT,Moka,Adwaita,gnome,hicolor/g' /home/${ USER } /arc-icon-theme/Arc/index.theme
find /home/${ USER } /arc-icon-theme -name '*[Tt]rash*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Nn]autilus*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Gg]nome.[Ss]ettings*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Gg]nome.[Tt]weak*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Gg]nome.[Ss]oftware*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Gg]nome.[Bb]oxes*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Ss]team*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Tt]hunderbird*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Mm]inecraft*' -exec rm { } \;
find /home/${ USER } /Mojave-CT -name '*[Ee]piphany*' -exec rm { } \;
gsettings set org.gnome.desktop.interface icon-theme "Arc"
#Set GTK theme
2021-04-04 04:52:51 -04:00
gsettings set org.gnome.desktop.interface gtk-theme "Yaru-Dark"
2021-04-04 01:09:26 -04:00
flatpak upgrade -y
2021-04-04 04:00:34 -04:00
#Set Ubuntu 20.04 LTS Wallpaper
gsettings set org.gnome.desktop.background picture-uri 'file:///usr/share/backgrounds/matt-mcnulty-nyc-2nd-ave.jpg'
2021-04-04 01:09:26 -04:00
#Enable Titlebar buttons
gsettings set org.gnome.desktop.wm.preferences button-layout 'appmenu:minimize,maximize,close'
#Enable GNOME shell extensions
gsettings set org.gnome.shell disable-user-extensions false
#Enable tap to click
gsettings set org.gnome.desktop.peripherals.touchpad tap-to-click true
2021-04-04 06:51:01 -04:00
#Setup GetExtensions
git clone https://github.com/ekistece/GetExtensions.git
pip3 install ./GetExtensions --user
2021-04-04 01:09:26 -04:00
#Reenable Wayland... They are working to support it, and if you aren't gaming you shouldn't stay on x11 anyways
sudo sed -i 's^DRIVER=="nvidia", RUN+="/usr/libexec/gdm-disable-wayland"^#DRIVER=="nvidia", RUN+="/usr/libexec/gdm-disable-wayland"^g' /usr/lib/udev/rules.d/61-gdm.rules
#Randomize MAC address
sudo bash -c 'cat > /etc/NetworkManager/conf.d/00-macrandomize.conf' <<-'EOF'
[ device]
wifi.scan-rand-mac-address= yes
[ connection]
wifi.cloned-mac-address= random
ethernet.cloned-mac-address= random
connection.stable-id= ${ CONNECTION } /${ BOOT }
EOF
sudo systemctl restart NetworkManager