33# |----------------------------------------------------------|
44# | Copyright (c) 2024-2026 Vili <https://vili.dev>. GPL-3.0 |
55# |----------------------------------------------------------|
6- # Made in Finland.
6+ # Made in Finland.
77
88set -euo pipefail
99
8080 sudo systemctl enable --now dnf-automatic.timer
8181}
8282
83- sys_hardening () {
84- echo -e " \n=> Applying System Hardening ..."
83+ install_fail2ban () {
84+ echo -e " \n=> Installing and enabling Fail2Ban ..."
8585 sudo dnf install -y fail2ban
8686 sudo systemctl enable --now fail2ban
87+ }
8788
89+ mac_randomization () {
90+ echo -e " \n=> Enabling MAC Randomization..."
8891 local macrandomize_rule=" /etc/NetworkManager/conf.d/00-macrandomize.conf"
8992 if [ ! -f " $macrandomize_rule " ]; then
9093 sudo tee -a " $macrandomize_rule " > /dev/null << 'EOF '
@@ -96,18 +99,23 @@ wifi.cloned-mac-address=random
9699ethernet.cloned-mac-address=random
97100EOF
98101 fi
102+ sudo systemctl restart NetworkManager
103+ }
99104
105+ ipv6_privacy () {
106+ echo -e " \n=> Enabling IPv6 Privacy Extensions..."
100107 local ipv6_privacy_rule=" /etc/NetworkManager/conf.d/00-ipv6-privacy.conf"
101108 if [ ! -f " $ipv6_privacy_rule " ]; then
102109 sudo tee -a " $ipv6_privacy_rule " > /dev/null << 'EOF '
103110[connection]
104111ipv6.ip6-privacy=2
105112EOF
106113 fi
107-
108114 sudo systemctl restart NetworkManager
115+ }
109116
110- echo " Applying sysctl hardening..."
117+ sysctl_hardening () {
118+ echo -e " \n=> Applying sysctl hardening..."
111119 local sysctl_file=" /etc/sysctl.d/55-hardening.conf"
112120 sudo tee " $sysctl_file " > /dev/null << 'EOF '
113121net.ipv4.tcp_syncookies = 1
@@ -117,17 +125,24 @@ net.ipv4.icmp_ignore_bogus_error_responses = 1
117125net.ipv4.tcp_timestamps = 0
118126net.ipv4.conf.all.rp_filter = 1
119127net.ipv4.conf.default.rp_filter = 1
120- net.ipv4.conf.*.send_redirects = 0
121- net.ipv4.conf.*.accept_redirects = 0
122- net.ipv6.conf.*.accept_redirects = 0
123- net.ipv4.conf.*.shared_media = 0
124- net.ipv4.conf.*.arp_filter = 1
125- net.ipv4.conf.*.arp_ignore = 2
128+ net.ipv4.conf.all.accept_redirects = 0
129+ net.ipv4.conf.default.accept_redirects = 0
130+ net.ipv4.conf.all.secure_redirects = 0
131+ net.ipv4.conf.default.secure_redirects = 0
132+ net.ipv6.conf.all.accept_redirects = 0
133+ net.ipv6.conf.default.accept_redirects = 0
134+ net.ipv4.conf.all.send_redirects = 0
135+ net.ipv4.conf.default.send_redirects = 0
136+ net.ipv4.conf.all.shared_media = 0
137+ net.ipv4.conf.all.arp_filter = 1
138+ net.ipv4.conf.all.arp_ignore = 2
126139net.ipv4.conf.all.drop_gratuitous_arp = 1
127- net.ipv4.conf.*.accept_source_route = 0
128- net.ipv6.conf.*.accept_source_route = 0
129- net.ipv4.tcp_sack=0
130- net.ipv4.tcp_dsack=0
140+ net.ipv4.conf.all.accept_source_route = 0
141+ net.ipv4.conf.default.accept_source_route = 0
142+ net.ipv6.conf.all.accept_source_route = 0
143+ net.ipv6.conf.default.accept_source_route = 0
144+ net.ipv4.tcp_sack = 0
145+ net.ipv4.tcp_dsack = 0
131146net.ipv6.conf.all.use_tempaddr = 2
132147net.ipv6.conf.default.use_tempaddr = 2
133148net.ipv4.conf.all.log_martians = 1
@@ -138,9 +153,9 @@ kernel.sysrq = 0
138153kernel.perf_event_paranoid = 3
139154kernel.kptr_restrict = 2
140155kernel.dmesg_restrict = 1
141- kernel.oops_limit= 100
142- kernel.warn_limit= 100
143- kernel.panic= -1
156+ kernel.oops_limit = 100
157+ kernel.warn_limit = 100
158+ kernel.panic = -1
144159fs.binfmt_misc.status = 0
145160fs.suid_dumpable = 0
146161fs.protected_regular = 2
@@ -160,8 +175,64 @@ vm.mmap_min_addr = 65536
160175vm.max_map_count = 1048576
161176EOF
162177 sudo sysctl --system
163- echo " Disabling cups and avahi-daemon..."
164- sudo systemctl disable cups avahi-daemon
178+ }
179+
180+ disable_cups_avahi () {
181+ echo -e " \n=> Disabling CUPS and Avahi-daemon..."
182+ sudo systemctl disable --now cups avahi-daemon
183+ }
184+
185+ disable_wifi () {
186+ echo -e " \n=> Completely disabling Wi-Fi capability..."
187+ sudo nmcli radio wifi off || true
188+ sudo rfkill block wifi || true
189+ sudo systemctl disable --now wpa_supplicant
190+ echo " install iwlwifi /bin/true" | sudo tee /etc/modprobe.d/disable-wifi.conf > /dev/null
191+ echo " install iwlmvm /bin/true" | sudo tee -a /etc/modprobe.d/disable-wifi.conf > /dev/null
192+ echo " install rt2800pci /bin/true" | sudo tee -a /etc/modprobe.d/disable-wifi.conf > /dev/null
193+ echo " install ath9k /bin/true" | sudo tee -a /etc/modprobe.d/disable-wifi.conf > /dev/null
194+ }
195+
196+ disable_bluetooth () {
197+ echo -e " \n=> Completely disabling Bluetooth capability..."
198+ sudo systemctl disable --now bluetooth
199+ sudo rfkill block bluetooth || true
200+ echo " install btusb /bin/true" | sudo tee /etc/modprobe.d/disable-bluetooth.conf > /dev/null
201+ echo " install bluetooth /bin/true" | sudo tee -a /etc/modprobe.d/disable-bluetooth.conf > /dev/null
202+ }
203+
204+ disable_webcam () {
205+ echo -e " \n=> Completely disabling Webcam capability..."
206+ echo " install uvcvideo /bin/true" | sudo tee /etc/modprobe.d/disable-webcam.conf > /dev/null
207+ }
208+
209+ disable_obscure_fs () {
210+ echo -e " \n=> Disabling obscure filesystems..."
211+ local fs_list=" cramfs freevxfs jffs2 hfs hfsplus squashfs udf"
212+ for fs in $fs_list ; do
213+ echo " install $fs /bin/true" | sudo tee -a /etc/modprobe.d/disable-fs.conf > /dev/null
214+ done
215+ }
216+
217+ enable_secure_dns () {
218+ local dns_ips=" $1 "
219+ echo -e " \n=> Enabling System-wide DNS-over-TLS (DoT) with IPs: $dns_ips "
220+ sudo mkdir -p /etc/systemd/resolved.conf.d
221+ sudo tee /etc/systemd/resolved.conf.d/dns_over_tls.conf > /dev/null << EOF
222+ [Resolve]
223+ DNS=$dns_ips
224+ DNSOverTLS=yes
225+ EOF
226+ sudo systemctl restart systemd-resolved
227+ }
228+
229+ strict_flatpak_overrides () {
230+ echo -e " \n=> Applying Strict Flatpak Overrides & Installing Flatseal..."
231+ sudo flatpak override --nofilesystem=host
232+ sudo flatpak override --nofilesystem=home
233+ sudo flatpak override --nodevice=all
234+ sudo dnf install flatpak -y > /dev/null
235+ flatpak install -y flathub com.github.tchx84.Flatseal || echo " Warning: Flatseal failed to install."
165236}
166237
167238hardcore_kernel_args () {
@@ -326,11 +397,18 @@ whiptail --title "FQS (Fedora Quick Start)" --msgbox "Welcome to the Fedora Quic
326397
327398# 1. Base Configuration Checklist
328399BASE_OPTS=$( whiptail --title " System Base Configuration" --checklist \
329- " Select system tweaks to apply (Space to select, Enter to confirm):" 22 75 12 \
400+ " Select system tweaks to apply (Space to select, Enter to confirm):" 29 80 20 \
330401" UPDATE" " Perform Full System Upgrade" ON \
331402" REPOS" " Enable RPM Fusion & Flathub" ON \
332403" DNF" " Optimize DNF Configuration" ON \
333- " HARDEN" " Apply System Hardening (Fail2Ban, Sysctl, etc)" ON \
404+ " FAIL2BAN" " Install and enable Fail2Ban" ON \
405+ " MAC_RAND" " Enable MAC Address Randomization" ON \
406+ " IPV6_PRIV" " Enable IPv6 Privacy Extensions" ON \
407+ " SYSCTL" " Apply Sysctl Kernel Hardening" ON \
408+ " FLATPAK_STRICT" " Strict Flatpak Overrides & Install Flatseal" OFF \
409+ " SECURE_DNS" " Enable System-wide DNS-over-TLS (DoT)" OFF \
410+ " DIS_FS" " Disable obscure filesystems (cramfs, hfs, udf, etc.)" OFF \
411+ " DIS_PRINTERS" " Disable CUPS & Avahi (Printers/Discovery)" ON \
334412" FIREWALL" " Set Firewalld default zone to DROP" ON \
335413" USBGUARD" " Set up USBGuard to block unauthorized devices" OFF \
336414" KERNEL" " Apply Hardcore Kernel Hardening" OFF \
@@ -341,9 +419,33 @@ BASE_OPTS=$(whiptail --title "System Base Configuration" --checklist \
341419" NVIDIA" " Install Nvidia Drivers (akmod-nvidia)" OFF \
342420" APPLE_KBD" " Patch Apple Keyboard FN key (hid_apple)" OFF \
343421" DRACUT" " Allow BT keyboard during LUKS decryption" OFF \
422+ " DIS_WIFI" " Completely Disable Wi-Fi (Modprobe & NM)" OFF \
423+ " DIS_BT" " Completely Disable Bluetooth (Modprobe & RFKill)" OFF \
424+ " DIS_WEBCAM" " Completely Disable Webcam (uvcvideo)" OFF \
3444253>&1 1>&2 2>&3 ) || exit 0
345426BASE_OPTS=$( echo " $BASE_OPTS " | tr -d ' "' )
346427
428+ # 1.5 Secure DNS Provider (If selected)
429+ DNS_IPS=" "
430+ if [[ " $BASE_OPTS " == * " SECURE_DNS" * ]]; then
431+ DNS_CHOICE=$( whiptail --title " Secure DNS Provider" --radiolist \
432+ " Choose a DNS-over-TLS provider:" 15 70 4 \
433+ " Cloudflare" " 1.1.1.1 (Fast, Privacy-focused)" ON \
434+ " Quad9" " 9.9.9.9 (Malware blocking)" OFF \
435+ " AdGuard" " 94.140.14.14 (Ad & Tracker blocking)" OFF \
436+ " Custom" " Enter your own IPs (Space separated)" OFF \
437+ 3>&1 1>&2 2>&3 ) || exit 0
438+
439+ case " $DNS_CHOICE " in
440+ " Cloudflare" ) DNS_IPS=" 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001" ;;
441+ " Quad9" ) DNS_IPS=" 9.9.9.9 149.112.112.112 2620:fe::fe 2620:fe::9" ;;
442+ " AdGuard" ) DNS_IPS=" 94.140.14.14 94.140.15.15 2a10:50c0::ad1:ff 2a10:50c0::ad2:ff" ;;
443+ " Custom" )
444+ DNS_IPS=$( whiptail --title " Custom DNS" --inputbox " Enter DNS IPs (IPv4 and/or IPv6, space-separated):" 10 70 3>&1 1>&2 2>&3 ) || exit 0
445+ ;;
446+ esac
447+ fi
448+
347449# 2. Browser Selection
348450BROWSER=$( whiptail --title " Web Browser" --radiolist \
349451" Choose your preferred browser:" 15 60 6 \
@@ -410,7 +512,17 @@ clear
410512[[ " $BASE_OPTS " == * " UPDATE" * ]] && sys_update
411513[[ " $BASE_OPTS " == * " REPOS" * ]] && add_rpm_repos
412514[[ " $BASE_OPTS " == * " AUTO_UPDATES" * ]] && setup_auto_updates
413- [[ " $BASE_OPTS " == * " HARDEN" * ]] && sys_hardening
515+ [[ " $BASE_OPTS " == * " FAIL2BAN" * ]] && install_fail2ban
516+ [[ " $BASE_OPTS " == * " MAC_RAND" * ]] && mac_randomization
517+ [[ " $BASE_OPTS " == * " IPV6_PRIV" * ]] && ipv6_privacy
518+ [[ " $BASE_OPTS " == * " SYSCTL" * ]] && sysctl_hardening
519+ [[ " $BASE_OPTS " == * " FLATPAK_STRICT" * ]] && strict_flatpak_overrides
520+ [[ " $BASE_OPTS " == * " SECURE_DNS" * ]] && enable_secure_dns " $DNS_IPS "
521+ [[ " $BASE_OPTS " == * " DIS_FS" * ]] && disable_obscure_fs
522+ [[ " $BASE_OPTS " == * " DIS_PRINTERS" * ]] && disable_cups_avahi
523+ [[ " $BASE_OPTS " == * " DIS_WIFI" * ]] && disable_wifi
524+ [[ " $BASE_OPTS " == * " DIS_BT" * ]] && disable_bluetooth
525+ [[ " $BASE_OPTS " == * " DIS_WEBCAM" * ]] && disable_webcam
414526[[ " $BASE_OPTS " == * " FIREWALL" * ]] && setup_firewall_drop
415527[[ " $BASE_OPTS " == * " USBGUARD" * ]] && setup_usbguard
416528[[ " $BASE_OPTS " == * " KERNEL" * ]] && hardcore_kernel_args
0 commit comments