|
fb62de7ddc
|
Disable bluetooth on servers
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-15 05:49:11 -07:00 |
|
|
423c3fff72
|
Setup hardened_malloc
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-11 03:25:11 -07:00 |
|
|
90019fbb1c
|
Consistency Fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-11 02:43:40 -07:00 |
|
|
44430c889a
|
Add ia32_emulation=0
Signed-off-by: Tommy <contact@tommytran.io>
|
2024-01-11 00:28:23 -07:00 |
|
|
3a48c54ead
|
Remove theatre
|
2024-01-02 01:38:34 -07:00 |
|
|
34ca17f672
|
Fix chmod 700 /home/*
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-31 14:40:36 -07:00 |
|
|
159f947132
|
Consistency between RHEL and Fedora
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-25 02:18:48 -07:00 |
|
|
0c8ae2fa24
|
Lockdown firewalld on RHEL
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-12 01:21:56 -07:00 |
|
|
9c942cf89e
|
CtrlAltDelBurstAction=none
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-12 01:20:52 -07:00 |
|
|
7fd8e73563
|
Make sure home dirs are private
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-07 17:26:53 -07:00 |
|
|
5aca397a76
|
Compliance update
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-07 17:15:05 -07:00 |
|
|
6a6b775631
|
Disable ctrl-alt-del
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-07 16:44:55 -07:00 |
|
|
e8aec0c4e8
|
Update styling
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-06 13:47:53 -07:00 |
|
|
63b63e8129
|
Shellcheck fixes
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-04 16:17:55 -07:00 |
|
|
5b73cf5caa
|
Consistency fixes
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-02 05:05:02 -07:00 |
|
|
8538648088
|
(Mostly) unprivileged curl
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-02 04:56:58 -07:00 |
|
|
0a43002047
|
curl | sudo tee
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 23:04:02 -07:00 |
|
|
05e24fd2db
|
Consistency fix
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 20:00:10 -07:00 |
|
|
e68ef1bccc
|
Split out fwupd on Red Hat systems
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:59:11 -07:00 |
|
|
0f7021b528
|
Fancy blue output highlighting
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:54:20 -07:00 |
|
|
e11e7587df
|
Fix indentation
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:43:42 -07:00 |
|
|
0287cf74a6
|
Add real-ucode for Red Hat systems
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-12-01 19:42:32 -07:00 |
|
Guru
|
fd7ea92744
|
rename 990_security-misc.conf -> 990-security-misc.conf (#9)
|
2023-11-15 14:12:25 -07:00 |
|
|
9dbb4a3dd4
|
Split out dnf config
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-11-10 16:43:49 -07:00 |
|
|
77d7837854
|
Remove fastest mirror
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-11-10 16:07:30 -07:00 |
|
|
6c92727673
|
Update sysctl security-misc.conf path
|
2023-10-31 09:16:46 -07:00 |
|
|
ace0829999
|
Update Kicksecure sysctl config location
|
2023-10-31 09:02:33 -07:00 |
|
|
53340db0ea
|
Update SSH hardening
|
2023-10-10 12:23:50 -07:00 |
|
|
ab72f9eba9
|
fwupd hardening on Red Hat systems
|
2023-10-03 15:02:30 -07:00 |
|
|
08f4d5ed11
|
Add Apache license header
|
2023-09-27 00:56:28 -07:00 |
|
|
1de21fa18b
|
Harden boot params on Red Hat systems
|
2023-09-27 00:35:31 -07:00 |
|
|
d8a7235a8a
|
Rebuild initramfs
|
2023-09-26 23:03:35 -07:00 |
|
|
b93eba253a
|
Update dnf config
|
2023-09-26 15:43:53 -07:00 |
|
|
e0d02f1c72
|
Update SSH Hardening
|
2023-09-22 15:09:36 -07:00 |
|
|
92b639fe9e
|
Change sshd override
|
2023-09-07 14:44:00 -07:00 |
|
|
85ada77f4c
|
Consistency fix
|
2023-08-22 17:46:56 -07:00 |
|
|
8ae830a175
|
Improved consistency across distros
|
2023-08-16 03:22:28 -07:00 |
|
|
a331025f3f
|
Enable seccomp filter for Chrony
Signed-off-by: Thien Tran <contact@tommytran.io>
|
2023-08-08 21:33:38 -07:00 |
|
|
88bcc610a9
|
Use 1.1.1.2 for badness enumeration
|
2023-07-27 18:33:18 -07:00 |
|
|
d43598710f
|
Enable fstrim.timer
|
2023-07-07 02:41:36 -07:00 |
|
|
1d15c26865
|
Change to Cloudflare DNS
Signed-off-by: Thien Tran <contact@tommytran.io>
|
2023-06-25 17:14:10 -07:00 |
|
|
40fcdc01c5
|
Fix /etc/ssh/ssh_config.d/10-custom.conf permission
|
2023-06-25 03:11:43 -07:00 |
|
|
907a7006f0
|
Enable automatic reboot
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-04-16 15:33:37 -04:00 |
|
|
f7d95c86a7
|
Enable dnf-automatic.timer
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-04-16 15:29:43 -04:00 |
|
|
8d9a741e07
|
Enable automatic update
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-04-16 15:28:03 -04:00 |
|
|
42dc68b17a
|
Disable cockpit port
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-04-16 02:49:34 -04:00 |
|
|
e2415d7a21
|
Add missing daemon-reload
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-04-16 02:26:44 -04:00 |
|
|
aa22bd45a7
|
Allow ICMP on servers
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-03-20 14:39:50 -04:00 |
|
|
98cd78a8b9
|
Remove do-not-query-localhost
|
2023-03-11 00:52:20 -05:00 |
|
|
037022c6d2
|
Update kicksecure sysctl
Signed-off-by: Tommy <contact@tommytran.io>
|
2023-02-04 05:21:33 -05:00 |
|