Skip to content

review secureblue sysctl #283

Activity

  1. raja-grewal commented on Dec 17, 2024

    @raja-grewal
    Contributor

    They do not include any settings that are not already included in our settings, however, they do enable certain settings that we for a variety of reasons keep disabled.

    The discrepancies are:

    1. net.ipv6.conf.*.use_tempaddr=2: We keep the IPv6 privacy extensions disabled due to breakages.
    2. net.ipv4.conf.*.log_martians=1: We keep the logging of these packets optional.
    3. fs.binfmt_misc.status=0: We keep this enabled due to current file/folder permissions issue.

    Furthermore, we can also review their kernel arguments:

    Across all these there are only minor explainable discrepancies:

    1. lockdown=confidentiality and module.sig_enforce=1: We do not enable these due to compatibility issues.
    2. ia32_emulation=0: We can not currently enable this as it is only applicable when using Linux kernel >= 6.7.
    3. kvm-intel.vmentry_l1d_flush=always: We do not include this, however according kernel docs, this parameter is redundant if using l1tf=full,force (which we enable by default).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions