mirror of
https://git.hardenedbsd.org/hardenedbsd/HardenedBSD.git
synced 2025-01-11 17:04:19 +01:00
Remove stack guard option from hardening menu.
Since kib's change the stack guard is now ON by default, this option in hardening menu of bsdinstall is no longer needed. Submitted by: Bartlomiej Rutkowski <robak@FreeBSD.org> Reviewed by: bapt Approved by: bapt MFC after: 1 day Sponsored by: Pixeware LTD Differential Revision: https://reviews.freebsd.org/D11686
This commit is contained in:
parent
27d8bea898
commit
391aafd7ab
Notes:
svn2git
2020-12-20 02:59:44 +00:00
svn path=/head/; revision=321326
@ -42,11 +42,10 @@ FEATURES=$( dialog --backtitle "FreeBSD Installer" \
|
|||||||
"3 read_msgbuf" "Disable reading kernel message buffer for unprivileged users" ${read_msgbuf:-off} \
|
"3 read_msgbuf" "Disable reading kernel message buffer for unprivileged users" ${read_msgbuf:-off} \
|
||||||
"4 proc_debug" "Disable process debugging facilities for unprivileged users" ${proc_debug:-off} \
|
"4 proc_debug" "Disable process debugging facilities for unprivileged users" ${proc_debug:-off} \
|
||||||
"5 random_pid" "Randomize the PID of newly created processes" ${random_pid:-off} \
|
"5 random_pid" "Randomize the PID of newly created processes" ${random_pid:-off} \
|
||||||
"6 stack_guard" "Set stack guard buffer size to 2MB" ${stack_guard:-off} \
|
"6 clear_tmp" "Clean the /tmp filesystem on system startup" ${clear_tmp:-off} \
|
||||||
"7 clear_tmp" "Clean the /tmp filesystem on system startup" ${clear_tmp:-off} \
|
"7 disable_syslogd" "Disable opening Syslogd network socket (disables remote logging)" ${disable_syslogd:-off} \
|
||||||
"8 disable_syslogd" "Disable opening Syslogd network socket (disables remote logging)" ${disable_syslogd:-off} \
|
"8 disable_sendmail" "Disable Sendmail service" ${disable_sendmail:-off} \
|
||||||
"9 disable_sendmail" "Disable Sendmail service" ${disable_sendmail:-off} \
|
"9 secure_console" "Enable console password prompt" ${secure_console:-off} \
|
||||||
"10 secure_console" "Enable console password prompt" ${secure_console:-off} \
|
|
||||||
2>&1 1>&3 )
|
2>&1 1>&3 )
|
||||||
exec 3>&-
|
exec 3>&-
|
||||||
|
|
||||||
@ -69,9 +68,6 @@ for feature in $FEATURES; do
|
|||||||
if [ "$feature" = "random_pid" ]; then
|
if [ "$feature" = "random_pid" ]; then
|
||||||
echo kern.randompid=$(jot -r 1 9999) >> $BSDINSTALL_TMPETC/sysctl.conf.hardening
|
echo kern.randompid=$(jot -r 1 9999) >> $BSDINSTALL_TMPETC/sysctl.conf.hardening
|
||||||
fi
|
fi
|
||||||
if [ "$feature" = "stack_guard" ]; then
|
|
||||||
echo security.bsd.stack_guard_page=512 >> $BSDINSTALL_TMPETC/sysctl.conf.hardening
|
|
||||||
fi
|
|
||||||
if [ "$feature" = "clear_tmp" ]; then
|
if [ "$feature" = "clear_tmp" ]; then
|
||||||
echo 'clear_tmp_enable="YES"' >> $BSDINSTALL_TMPETC/rc.conf.hardening
|
echo 'clear_tmp_enable="YES"' >> $BSDINSTALL_TMPETC/rc.conf.hardening
|
||||||
fi
|
fi
|
||||||
|
Loading…
Reference in New Issue
Block a user