This commit is contained in:
Patrick Schleizer
2019-11-23 14:06:28 +00:00
parent fe1f1b73a7
commit 6a6a638ef0

View File

@ -81,6 +81,11 @@ that shouldn't be accessible to unprivileged users. As this will break many
things, it is disabled by default and can optionally be enabled by running things, it is disabled by default and can optionally be enabled by running
`systemctl enable hide-hardware-info.service` as root. `systemctl enable hide-hardware-info.service` as root.
Improve Entropy Collection
* Load jitterentropy_rng kernel module.
/usr/lib/modules-load.d/30_security-misc.conf
Uncommon network protocols are blacklisted: Uncommon network protocols are blacklisted:
These are rarely used and may have unknown vulnerabilities. These are rarely used and may have unknown vulnerabilities.
/etc/modprobe.d/uncommon-network-protocols.conf /etc/modprobe.d/uncommon-network-protocols.conf