]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/commitdiff
Kernel: Enable LSM support and set security level to "integrity"
authorPeter Müller <peter.mueller@ipfire.org>
Sun, 19 Dec 2021 17:42:08 +0000 (18:42 +0100)
committerPeter Müller <peter.mueller@ipfire.org>
Tue, 1 Mar 2022 15:29:06 +0000 (15:29 +0000)
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
config/kernel/kernel.config.x86_64-ipfire

index b325feb1d83686c0d4196311161a561fdd8d1497..222b2dc539b1cf18a2d50b4434ebaa9bd4bf1eaf 100644 (file)
@@ -6972,7 +6972,11 @@ CONFIG_SECURITY_LOADPIN=y
 CONFIG_SECURITY_LOADPIN_ENFORCE=y
 # CONFIG_SECURITY_YAMA is not set
 CONFIG_SECURITY_SAFESETID=y
-# CONFIG_SECURITY_LOCKDOWN_LSM is not set
+CONFIG_SECURITY_LOCKDOWN_LSM=y
+CONFIG_SECURITY_LOCKDOWN_LSM_EARLY=y
+# CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE is not set
+CONFIG_LOCK_DOWN_KERNEL_FORCE_INTEGRITY=y
+# CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY is not set
 # CONFIG_SECURITY_LANDLOCK is not set
 CONFIG_INTEGRITY=y
 # CONFIG_INTEGRITY_SIGNATURE is not set