From: Michael Tremer Date: Sun, 8 Feb 2009 18:10:27 +0000 (+0100) Subject: Again, some modification on grsec config. X-Git-Tag: v3.0-alpha1~18 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=effe09b2ad4c667e7d133301c61dd6d6cc636aa0;p=ipfire-3.x.git Again, some modification on grsec config. --- diff --git a/config/kernel/kernel.config b/config/kernel/kernel.config index 416548228..9675298c7 100644 --- a/config/kernel/kernel.config +++ b/config/kernel/kernel.config @@ -1,7 +1,7 @@ # # Automatically generated make config: don't edit # Linux kernel version: 2.6.27.10 -# Fri Feb 6 14:48:32 2009 +# Sun Feb 8 09:29:42 2009 # # CONFIG_64BIT is not set CONFIG_X86_32=y @@ -2343,7 +2343,7 @@ CONFIG_GRKERNSEC_CUSTOM=y # # Address Space Protection # -CONFIG_GRKERNSEC_KMEM=y +# CONFIG_GRKERNSEC_KMEM is not set # CONFIG_GRKERNSEC_IO is not set CONFIG_GRKERNSEC_PROC_MEMMAP=y CONFIG_GRKERNSEC_BRUTE=y @@ -2382,16 +2382,17 @@ CONFIG_GRKERNSEC_CHROOT_CAPS=y # Kernel Auditing # # CONFIG_GRKERNSEC_AUDIT_GROUP is not set -# CONFIG_GRKERNSEC_EXECLOG is not set +CONFIG_GRKERNSEC_EXECLOG=y CONFIG_GRKERNSEC_RESLOG=y -# CONFIG_GRKERNSEC_CHROOT_EXECLOG is not set -# CONFIG_GRKERNSEC_AUDIT_CHDIR is not set +CONFIG_GRKERNSEC_CHROOT_EXECLOG=y +CONFIG_GRKERNSEC_AUDIT_CHDIR=y CONFIG_GRKERNSEC_AUDIT_MOUNT=y -# CONFIG_GRKERNSEC_AUDIT_IPC is not set +CONFIG_GRKERNSEC_AUDIT_IPC=y CONFIG_GRKERNSEC_SIGNAL=y CONFIG_GRKERNSEC_FORKFAIL=y CONFIG_GRKERNSEC_TIME=y CONFIG_GRKERNSEC_PROC_IPADDR=y +# CONFIG_GRKERNSEC_AUDIT_TEXTREL is not set # # Executable Protections @@ -2437,10 +2438,11 @@ CONFIG_PAX_HAVE_ACL_FLAGS=y # Non-executable pages # CONFIG_PAX_NOEXEC=y -CONFIG_PAX_PAGEEXEC=y +# CONFIG_PAX_PAGEEXEC is not set CONFIG_PAX_SEGMEXEC=y -# CONFIG_PAX_EMUTRAMP is not set -# CONFIG_PAX_MPROTECT is not set +CONFIG_PAX_EMUTRAMP=y +CONFIG_PAX_MPROTECT=y +# CONFIG_PAX_NOELFRELOCS is not set CONFIG_PAX_KERNEXEC=y #