|
80bb7c00d8
|
Add ARM support for hardened_malloc on Red Hat systems
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-03-05 14:20:13 -07:00 |
|
|
8889adca80
|
Use default hardened_malloc variant on Red Hat systems
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-02-27 00:08:28 -07:00 |
|
|
8c362a9999
|
Fix amd_iommu and remove extra_latent_entropy
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-02-26 21:37:40 -07:00 |
|
|
7672345a89
|
Consistency fixes
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-02-13 17:16:33 -07:00 |
|
|
81f79f2616
|
Remove nullok on Red Hat systems
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-02-13 16:55:36 -07:00 |
|
|
6cdbe919f9
|
Split SSH hardening config
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-02-07 09:52:52 -07:00 |
|
|
0d7dc2817f
|
Split /etc/sysconfig/chronyd
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-02-07 08:46:06 -07:00 |
|
|
d0819bbcb1
|
Cleanup kernel args
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-02-07 06:39:00 -07:00 |
|
|
0ce4a7b30e
|
RHEL script update
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-22 09:26:55 -07:00 |
|
|
79a0297a7b
|
Account for RHEL GUI installation
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-22 09:11:47 -07:00 |
|
|
1e0d6d3a3c
|
Update grub hardening
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-21 01:23:50 -07:00 |
|
|
b19562c65d
|
Update copyright year
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-20 01:09:48 -07:00 |
|
|
fb62de7ddc
|
Disable bluetooth on servers
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-15 05:49:11 -07:00 |
|
|
423c3fff72
|
Setup hardened_malloc
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-11 03:25:11 -07:00 |
|
|
90019fbb1c
|
Consistency Fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-11 02:43:40 -07:00 |
|
|
44430c889a
|
Add ia32_emulation=0
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-11 00:28:23 -07:00 |
|
|
3a48c54ead
|
Remove theatre
|
2024-01-02 01:38:34 -07:00 |
|
|
34ca17f672
|
Fix chmod 700 /home/*
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-31 14:40:36 -07:00 |
|
|
159f947132
|
Consistency between RHEL and Fedora
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-25 02:18:48 -07:00 |
|
|
0c8ae2fa24
|
Lockdown firewalld on RHEL
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-12 01:21:56 -07:00 |
|
|
9c942cf89e
|
CtrlAltDelBurstAction=none
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-12 01:20:52 -07:00 |
|
|
7fd8e73563
|
Make sure home dirs are private
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-07 17:26:53 -07:00 |
|
|
5aca397a76
|
Compliance update
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-07 17:15:05 -07:00 |
|
|
6a6b775631
|
Disable ctrl-alt-del
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-07 16:44:55 -07:00 |
|
|
e8aec0c4e8
|
Update styling
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-06 13:47:53 -07:00 |
|
|
63b63e8129
|
Shellcheck fixes
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-04 16:17:55 -07:00 |
|
|
5b73cf5caa
|
Consistency fixes
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-02 05:05:02 -07:00 |
|
|
8538648088
|
(Mostly) unprivileged curl
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-02 04:56:58 -07:00 |
|
|
0a43002047
|
curl | sudo tee
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 23:04:02 -07:00 |
|
|
05e24fd2db
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 20:00:10 -07:00 |
|
|
e68ef1bccc
|
Split out fwupd on Red Hat systems
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:59:11 -07:00 |
|
|
0f7021b528
|
Fancy blue output highlighting
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:54:20 -07:00 |
|
|
e11e7587df
|
Fix indentation
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:43:42 -07:00 |
|
|
0287cf74a6
|
Add real-ucode for Red Hat systems
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:42:32 -07:00 |
|
Guru
|
fd7ea92744
|
rename 990_security-misc.conf -> 990-security-misc.conf (#9)
|
2023-11-15 14:12:25 -07:00 |
|
|
9dbb4a3dd4
|
Split out dnf config
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-11-10 16:43:49 -07:00 |
|
|
77d7837854
|
Remove fastest mirror
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-11-10 16:07:30 -07:00 |
|
|
6c92727673
|
Update sysctl security-misc.conf path
|
2023-10-31 09:16:46 -07:00 |
|
|
ace0829999
|
Update Kicksecure sysctl config location
|
2023-10-31 09:02:33 -07:00 |
|
|
53340db0ea
|
Update SSH hardening
|
2023-10-10 12:23:50 -07:00 |
|
|
ab72f9eba9
|
fwupd hardening on Red Hat systems
|
2023-10-03 15:02:30 -07:00 |
|
|
08f4d5ed11
|
Add Apache license header
|
2023-09-27 00:56:28 -07:00 |
|
|
1de21fa18b
|
Harden boot params on Red Hat systems
|
2023-09-27 00:35:31 -07:00 |
|
|
d8a7235a8a
|
Rebuild initramfs
|
2023-09-26 23:03:35 -07:00 |
|
|
b93eba253a
|
Update dnf config
|
2023-09-26 15:43:53 -07:00 |
|
|
e0d02f1c72
|
Update SSH Hardening
|
2023-09-22 15:09:36 -07:00 |
|
|
92b639fe9e
|
Change sshd override
|
2023-09-07 14:44:00 -07:00 |
|
|
85ada77f4c
|
Consistency fix
|
2023-08-22 17:46:56 -07:00 |
|
|
8ae830a175
|
Improved consistency across distros
|
2023-08-16 03:22:28 -07:00 |
|
|
a331025f3f
|
Enable seccomp filter for Chrony
Signed-off-by: Thien Tran <contact@tommytran.io>
|
2023-08-08 21:33:38 -07:00 |
|