From: Silvio Rhatto Date: Thu, 29 Dec 2016 13:04:38 +0000 (-0200) Subject: Adds nodo::subsystem::grsec X-Git-Url: https://gitweb.fluxo.info/?a=commitdiff_plain;h=53ad32e8f08124f9ac837df091f61adf685775a8;p=puppet-nodo.git Adds nodo::subsystem::grsec --- diff --git a/manifests/subsystem/grsec.pp b/manifests/subsystem/grsec.pp new file mode 100644 index 0000000..185454f --- /dev/null +++ b/manifests/subsystem/grsec.pp @@ -0,0 +1,11 @@ +class nodo::subsystem::grsec { + include nodo::utils::security::grsec + + nodo::subsystem::sysctl::entry { 'kernel.grsecurity.rwxmap_logging': + value => 0, + } + + nodo::subsystem::sysctl::entry { 'kernel.grsecurity.grsec_lock': + value => 1, + } +} diff --git a/manifests/utils/security/grsec.pp b/manifests/utils/security/grsec.pp new file mode 100644 index 0000000..c978088 --- /dev/null +++ b/manifests/utils/security/grsec.pp @@ -0,0 +1,13 @@ +class nodo::utils::security::grsec { + package { [ + # The package with the specific image version might not be used + # but right now apt is complaining of unmet dependencies when + # trying to install only the metapackage maybe because both are + # on jessie-backports. This might chance in the near future. + 'linux-image-4.7.0-1-grsec-amd64', + 'linux-image-grsec-amd64', + 'paxtest', + ]: + ensure => present, + } +}