|
d96f5a70da
|
Update modprobe url and bug fixes
|
2024-07-26 04:59:01 -07:00 |
|
|
e04febb0fe
|
Add set -u
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-20 18:23:38 -07:00 |
|
|
d434af04b4
|
Not overwrite USERGROUP_ENAB on anything but Ubuntu
The nonsense with umask is introduced by Canonical's infinite wisdom: https://git.launchpad.net/ubuntu/+source/pam/tree/debian/patches/pam_umask_usergroups_from_login.defs.patch?h=ubuntu/noble
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583958
We don't need to break sensible distributions because of Ubuntu nonsenses
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-09 15:07:40 -07:00 |
|
mce0
|
4809dcb4ce
|
Fix typo and notices (#15)
* Fix typo in Fedora-Server-40.sh
Signed-off-by: mce0 <contact@mce0.dev>
* Fix notices in Fedora-Server-40.sh
Signed-off-by: mce0 <contact@mce0.dev>
---------
Signed-off-by: mce0 <contact@mce0.dev>
|
2024-07-08 11:10:27 -07:00 |
|
|
fe4205fe45
|
Suppress curl output
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-03 02:23:28 -07:00 |
|
|
0b25901b86
|
Add set -e
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-07-02 16:48:15 -07:00 |
|
|
4c9c1150be
|
Consistency fix
|
2024-07-02 15:14:43 -07:00 |
|
|
e3104f037f
|
POSIX Compliance
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-25 22:24:45 -07:00 |
|
|
9fafe1704b
|
Comment out docker only unbound config
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-24 18:22:42 -07:00 |
|
|
46ea5f81bf
|
Remove real-ucode
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-09 05:34:13 -07:00 |
|
|
517c1ed2dc
|
Fix real-ucode condition
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-07 21:20:30 -07:00 |
|
|
e258f693dc
|
Use SecureBlue for HardenedMalloc
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-07 14:11:45 -07:00 |
|
|
afb3f0e98a
|
Typo fix
|
2024-06-06 21:59:38 -07:00 |
|
|
4514fe279a
|
Add preload file for hmalloc
|
2024-06-06 21:58:28 -07:00 |
|
|
3790c4df70
|
Fix file permission on Fedora
|
2024-06-05 21:42:12 -07:00 |
|
|
2ff48df2d1
|
Typo fixes
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-04 14:29:50 -07:00 |
|
|
236f650566
|
Use custom config & SecureBlue whenever possible on Fedora
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-04 04:23:30 -07:00 |
|
|
db4a82be7e
|
Better regex for kernel module blacklist
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:46:59 -07:00 |
|
|
8087457cb0
|
Add escape for regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:34:48 -07:00 |
|
|
90bebe1665
|
Better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:19:20 -07:00 |
|
|
4b9ae05218
|
Even better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 02:33:02 -07:00 |
|
|
5bc20644e6
|
Better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 02:27:28 -07:00 |
|
|
f1508a7f01
|
Stop hardcoding compression level
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-30 21:57:03 -07:00 |
|
|
3e97fd298c
|
Add notes on DNS handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 18:16:17 -07:00 |
|
|
520bb847e6
|
Disable systemd-resolved
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 18:06:18 -07:00 |
|
|
f99929f796
|
Fix unbound config URL
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 18:00:53 -07:00 |
|
|
236e1ae23a
|
Add irqbalance hardening for Fedora Server
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 17:49:12 -07:00 |
|
|
0c892f019b
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 17:48:45 -07:00 |
|
|
09cd7639ad
|
Add unbound to Fedora server
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 16:45:12 -07:00 |
|
|
5956eb9095
|
Install dnf-automatic
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 16:05:07 -07:00 |
|
|
b0cb3d2788
|
Keep RHEL 9 and F40 scripts in sync
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 16:00:50 -07:00 |
|
|
e3a44ffbd4
|
Fix indentation
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 15:21:11 -07:00 |
|
|
9610e72d95
|
Fix tuned handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 14:59:14 -07:00 |
|
|
7c8394ea12
|
Better virtualization handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 14:52:09 -07:00 |
|
|
1cca00f237
|
Better umask handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 12:27:45 -07:00 |
|
|
6e80f936bb
|
Fix kargs
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 10:40:07 -07:00 |
|
|
c2c57e5393
|
Update kernel hardening params
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 10:22:47 -07:00 |
|
|
7b9a916694
|
Remove unnecessary command
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-20 19:02:18 -07:00 |
|
|
40e9c49fcd
|
Check for /usr/lib/systemd/boot/efi
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-19 18:26:54 -07:00 |
|
|
7177cdf774
|
Typo fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 15:39:05 -07:00 |
|
|
29a3993155
|
Add ssh hardening
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 15:34:33 -07:00 |
|
|
2e1b763290
|
tuned not installed by default
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 15:22:28 -07:00 |
|
|
dfe149a763
|
Add serial port for server installs
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 14:29:16 -07:00 |
|
|
92412279e2
|
Remove cockpit
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 13:23:25 -07:00 |
|
|
a3ddb68e26
|
Add SSHD hardening
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 06:11:37 -07:00 |
|
|
98ec119430
|
Fix firewalld
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 04:12:35 -07:00 |
|
|
3d1ece9861
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 02:49:31 -07:00 |
|
|
7b6d7a4911
|
Setup /etc/issue
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 23:28:26 -07:00 |
|
|
c5d3b81475
|
Update zram config
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 22:32:28 -07:00 |
|
|
3c5cc65c74
|
Adjust sysctl on Fedora Server
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 22:18:42 -07:00 |
|