|
acf3e6ae11
|
Move generate-kmod-blacklist to TommyTran732/Security-Misc
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-06-02 15:06:04 -07:00 |
|
|
a781fd5a5d
|
Use AF's link
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 20:45:08 -07:00 |
|
|
db4a82be7e
|
Better regex for kernel module blacklist
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:46:59 -07:00 |
|
|
8087457cb0
|
Add escape for regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:34:48 -07:00 |
|
|
90bebe1665
|
Better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 13:19:20 -07:00 |
|
|
0f0b98feb6
|
Add badge & expand ignore list
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 10:32:55 -07:00 |
|
|
f8819622ec
|
Add shellcheck
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 10:29:25 -07:00 |
|
|
023cc46676
|
Typo fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 05:11:03 -07:00 |
|
|
4b9ae05218
|
Even better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 02:33:02 -07:00 |
|
|
5bc20644e6
|
Better regex
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-31 02:27:28 -07:00 |
|
|
f1508a7f01
|
Stop hardcoding compression level
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-30 21:57:03 -07:00 |
|
|
3e97fd298c
|
Add notes on DNS handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 18:16:17 -07:00 |
|
|
520bb847e6
|
Disable systemd-resolved
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 18:06:18 -07:00 |
|
|
f99929f796
|
Fix unbound config URL
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 18:00:53 -07:00 |
|
|
236e1ae23a
|
Add irqbalance hardening for Fedora Server
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 17:49:12 -07:00 |
|
|
0c892f019b
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 17:48:45 -07:00 |
|
|
b32330c79d
|
Re-add irqbalance hardening on RHEL 9
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 17:23:29 -07:00 |
|
|
3cd2cf7215
|
Add notes for unbound on RHEL
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 17:11:34 -07:00 |
|
|
09cd7639ad
|
Add unbound to Fedora server
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 16:45:12 -07:00 |
|
|
5956eb9095
|
Install dnf-automatic
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 16:05:07 -07:00 |
|
|
b0cb3d2788
|
Keep RHEL 9 and F40 scripts in sync
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 16:00:50 -07:00 |
|
|
441c4e068a
|
Remove abrt
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 15:33:25 -07:00 |
|
|
e3a44ffbd4
|
Fix indentation
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 15:21:11 -07:00 |
|
|
9610e72d95
|
Fix tuned handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 14:59:14 -07:00 |
|
|
1aecfcd3a5
|
Add missing -y
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 14:53:50 -07:00 |
|
|
7c8394ea12
|
Better virtualization handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 14:52:09 -07:00 |
|
|
24e7e6bd88
|
Minor reorganization
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 12:43:53 -07:00 |
|
|
1cca00f237
|
Better umask handling
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-29 12:27:45 -07:00 |
|
|
2d8eb5f31d
|
Combine ls commands
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 19:08:23 -07:00 |
|
|
5475551abf
|
Add kernel module blacklist generator
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 18:04:46 -07:00 |
|
|
6e80f936bb
|
Fix kargs
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 10:40:07 -07:00 |
|
|
0a6419874a
|
Fix grub
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 10:26:12 -07:00 |
|
|
c2c57e5393
|
Update kernel hardening params
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-27 10:22:47 -07:00 |
|
|
312d968efd
|
Minor reorganization
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-21 23:16:23 -07:00 |
|
|
07d62d45f5
|
Remove more useless packages
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-21 19:26:42 -07:00 |
|
|
7b9a916694
|
Remove unnecessary command
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-20 19:02:18 -07:00 |
|
|
ad4b8ac8df
|
Better systemd-boot detection
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-20 07:07:44 -07:00 |
|
|
40e9c49fcd
|
Check for /usr/lib/systemd/boot/efi
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-19 18:26:54 -07:00 |
|
|
7177cdf774
|
Typo fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 15:39:05 -07:00 |
|
|
29a3993155
|
Add ssh hardening
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 15:34:33 -07:00 |
|
|
2e1b763290
|
tuned not installed by default
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 15:22:28 -07:00 |
|
|
dfe149a763
|
Add serial port for server installs
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 14:29:16 -07:00 |
|
|
92412279e2
|
Remove cockpit
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 13:23:25 -07:00 |
|
|
a3ddb68e26
|
Add SSHD hardening
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 06:11:37 -07:00 |
|
|
98ec119430
|
Fix firewalld
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 04:12:35 -07:00 |
|
|
3d1ece9861
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-17 02:49:31 -07:00 |
|
|
7b6d7a4911
|
Setup /etc/issue
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 23:28:26 -07:00 |
|
|
5538cdf7fb
|
Add /etc/issue
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 23:15:07 -07:00 |
|
|
c5d3b81475
|
Update zram config
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 22:32:28 -07:00 |
|
|
d712fea4f7
|
Add public zram generator config
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-05-16 22:24:30 -07:00 |
|