29 lines
975 B
YAML
29 lines
975 B
YAML
---
|
|
sysctl_hardening_apply: true
|
|
sysctl_hardening_values:
|
|
fs.protected_hardlinks: 1
|
|
fs.protected_symlinks: 1
|
|
fs.protected_fifos: 2
|
|
fs.protected_regular: 2
|
|
fs.suid_dumpable: 0
|
|
kernel.core_uses_pid: 1
|
|
kernel.ctrl-alt-del: 0
|
|
kernel.dmesg_restrict: 1
|
|
kernel.kptr_restrict: 2
|
|
kernel.perf_event_paranoid: 2
|
|
kernel.randomize_va_space: 2
|
|
net.ipv4.conf.all.accept_redirects: 0
|
|
net.ipv4.conf.default.accept_redirects: 0
|
|
net.ipv6.conf.all.accept_redirects: 0
|
|
net.ipv6.conf.default.accept_redirects: 0
|
|
net.ipv4.conf.all.send_redirects: 0
|
|
net.ipv4.conf.default.send_redirects: 0
|
|
net.ipv4.conf.all.accept_source_route: 0
|
|
net.ipv4.conf.default.accept_source_route: 0
|
|
net.ipv6.conf.all.accept_source_route: 0
|
|
net.ipv6.conf.default.accept_source_route: 0
|
|
net.ipv4.icmp_echo_ignore_broadcasts: 1
|
|
net.ipv4.icmp_ignore_bogus_error_responses: 1
|
|
net.ipv4.tcp_syncookies: 1
|
|
net.ipv4.conf.all.log_martians: 1
|
|
net.ipv4.conf.default.log_martians: 1
|