From fbfdb0fa99087e4160979b612db04e63a1d3e3b1 Mon Sep 17 00:00:00 2001 From: Raja Grewal Date: Mon, 15 Jul 2024 14:40:03 +1000 Subject: [PATCH] Update `security-misc.maintscript` relating to grub --- debian/security-misc.maintscript | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/debian/security-misc.maintscript b/debian/security-misc.maintscript index 5d115c3..78a36fd 100644 --- a/debian/security-misc.maintscript +++ b/debian/security-misc.maintscript @@ -66,3 +66,17 @@ rm_conffile /etc/permission-hardening.d/25_default_whitelist_sudo.conf rm_conffile /etc/permission-hardening.d/25_default_whitelist_unix_chkpwd.conf rm_conffile /etc/permission-hardening.d/25_default_whitelist_virtualbox.conf rm_conffile /etc/permission-hardening.d/30_default.conf + +## merged into 1 file /etc/default/grub.d/40_kernel_hardening.cfg +rm /etc/default/grub.d/40_distrust_bootloader.cfg +rm /etc/default/grub.d/40_distrust_cpu.cfg +rm /etc/default/grub.d/40_enable_iommu.cfg + +## renamed to /etc/default/grub.d/40_remount_secure.cfg +rm /etc/default/grub.d/40_remmount-secure.cfg + +## renamed to /etc/default/grub.d/40_signed_modules.cfg +rm /etc/default/grub.d/40_only_allow_signed_modules.cfg + +## renamed to /etc/default/grub.d/41_quiet_boot.cfg +rm /etc/default/grub.d/41_quiet.cfg