Commit Graph

491 Commits

Author SHA1 Message Date
64f8b2eb58 Revert "no longer disable Intel ME related kernel modules"
This reverts commit 6157e328f4.

https://www.kicksecure.com/wiki/Out-of-band_Management_Technology#Intel_ME_Kernel_Modules

https://github.com/Kicksecure/security-misc/issues/239
2024-07-21 06:36:22 -04:00
f0a478c7c9 permission hardener: allow postfix
postqueue matchwhitelist
postdrop matchwhitelist
2024-07-20 12:57:56 -04:00
8791aecb38 Merge remote-tracking branch 'raja/fixes' 2024-07-19 07:19:09 -04:00
06894d1c98 Typo 2024-07-19 18:30:42 +10:00
cac5bbad99 comment 2024-07-18 14:04:00 -04:00
a5eed00eba cleanup comments 2024-07-18 14:02:38 -04:00
21efacf1b1 cleanup duplicate comments which are already in /etc/dkms/framework.conf 2024-07-18 14:00:28 -04:00
9e6facda70 Update module disabling presentation 2024-07-18 12:21:37 +10:00
faa9181a6c Typos 2024-07-18 12:19:27 +10:00
d454f36c63 spelling 2024-07-17 11:52:29 -04:00
f4da582aa3 spelling 2024-07-17 11:44:17 -04:00
9e976474d5 spelling 2024-07-17 11:40:51 -04:00
b569fc02a4 spelling 2024-07-17 11:38:53 -04:00
4afe257a42 minor 2024-07-18 00:14:13 +10:00
d0a59617f6 Add missing Copyright (C) statements 2024-07-18 00:13:30 +10:00
8f3896c3da Upgrade hyperlinks to HTTPS 2024-07-17 23:44:37 +10:00
df80385289 Merge pull request #237 from raja-grewal/intel_pmt
Disable some Intel PMT kernel modules
2024-07-17 09:04:18 -04:00
6157e328f4 no longer disable Intel ME related kernel modules
https://github.com/Kicksecure/security-misc/issues/239
2024-07-17 08:52:11 -04:00
a4ba6e485d Merge pull request #236 from raja-grewal/intel_me
Disable more Intel ME kernel modules
2024-07-17 08:46:27 -04:00
9a75135633 Merge pull request #238 from raja-grewal/uvcvideo_2
Minor additions to `30_security-misc_disable.conf`
2024-07-17 08:41:43 -04:00
d29a616142 minor 2024-07-17 08:39:20 -04:00
a2802f352f Merge remote-tracking branch 'raja/kargs' 2024-07-17 08:38:23 -04:00
a3408990ab Uncomment disabling of already disabled ATM modules 2024-07-17 15:03:39 +10:00
81a3715c7c Add info regarding the downsides of disabling SMT 2024-07-17 13:32:08 +10:00
abafb1945c Add Intel ME references 2024-07-17 13:26:03 +10:00
f317aaebab Disable two network modules
These were previously blacklisted for two years in 61ef9bd59f.
2024-07-17 01:09:02 +10:00
d69fe88091 Provide option to disable uvcvideo driver 2024-07-17 01:08:01 +10:00
49594ccb22 Partially revert f4d652fa7b 2024-07-17 00:49:25 +10:00
94df2e3d24 further discussion required
https://github.com/Kicksecure/security-misc/pull/234#issuecomment-2228909249
2024-07-15 12:29:52 -04:00
73f6d4b26f Fix transcription error 2024-07-16 01:03:41 +10:00
724435e56e Disable some Intel Platform Monitoring Technology Telemetry (PMT) modules 2024-07-15 22:38:43 +10:00
22ba7a7c39 Disable more Intel Management Engine (ME) modules 2024-07-15 22:21:20 +10:00
9300c208e2 Fix script 2024-07-15 21:36:25 +10:00
f2db11269e Fix script 2024-07-15 21:18:32 +10:00
fda3832eaf Replace bash file presented for disabling of miscellaneous modules 2024-07-15 21:08:45 +10:00
cb2fb95b81 Disable more miscellaneous drivers 2024-07-15 21:01:36 +10:00
96aa63267a Disable more Thunderbolt modules 2024-07-15 20:57:14 +10:00
51f7776bc8 Disable more network protocols/drivers 2024-07-15 20:56:12 +10:00
9e40ff0551 Disable more network file systems 2024-07-15 20:54:18 +10:00
82c5a93f7c Disable another GPS module 2024-07-15 20:53:07 +10:00
99b0ce7948 Disable more file systems 2024-07-15 20:47:56 +10:00
4476a477a7 Provide option to disable more Bluetooth modules 2024-07-15 20:47:07 +10:00
b2657bc61f Improve docs 2024-07-15 15:05:00 +10:00
c8385d82fb Clarify instructions for increasing log verbosity 2024-07-15 14:57:40 +10:00
d229e8b04d Fix link 2024-07-15 14:50:29 +10:00
f4d652fa7b Update presentation of quiet loglevel=0 2024-07-15 14:39:12 +10:00
48e1ac4163 Remove the optional slub_debug parameter since it is no longer recommended 2024-07-15 02:04:25 +10:00
99038c7a06 Add option to disable support for x86 processes and syscalls in the future 2024-07-15 02:02:01 +10:00
f550fbe07c Add option to disable the entire IPv6 stack functionality 2024-07-15 01:59:04 +10:00
a33d4cd099 Refactor existing kernel parameters for clarity 2024-07-15 01:56:25 +10:00