@@ -85,19 +85,28 @@ sys_hardening() {
8585 sudo dnf install -y fail2ban
8686 sudo systemctl enable --now fail2ban
8787
88- local network_file =" /etc/NetworkManager/conf.d/00-macrandomize.conf"
89- if [ ! -f " $network_file " ]; then
90- sudo tee -a " $network_file " > /dev/null << 'EOF '
88+ local macrandomize_rule =" /etc/NetworkManager/conf.d/00-macrandomize.conf"
89+ if [ ! -f " $macrandomize_rule " ]; then
90+ sudo tee -a " $macrandomize_rule " > /dev/null << 'EOF '
9191[device]
9292wifi.scan-rand-mac-address=yes
9393
9494[connection]
9595wifi.cloned-mac-address=random
9696ethernet.cloned-mac-address=random
9797EOF
98- sudo systemctl restart NetworkManager
9998 fi
10099
100+ local ipv6_privacy_rule=" /etc/NetworkManager/conf.d/00-ipv6-privacy.conf"
101+ if [ ! -f " $ipv6_privacy_rule " ]; then
102+ sudo tee -a " $ipv6_privacy_rule " > /dev/null << 'EOF '
103+ [connection]
104+ ipv6.ip6-privacy=2
105+ EOF
106+ fi
107+
108+ sudo systemctl restart NetworkManager
109+
101110 echo " Applying sysctl hardening..."
102111 local sysctl_file=" /etc/sysctl.d/55-hardening.conf"
103112 sudo tee " $sysctl_file " > /dev/null << 'EOF '
155164 sudo systemctl disable cups avahi-daemon
156165}
157166
167+ hardcore_kernel_args () {
168+ echo -e " \n=> Applying hardcore kernel hardening arguments..."
169+ sudo grubby --update-kernel=ALL --args=" \
170+ module.sig_enforce=1 \
171+ lockdown=confidentiality \
172+ kptr_restrict=2 \
173+ spec_store_bypass_disable=on \
174+ pti=on \
175+ l1tf=full,force \
176+ mds=full,nosmt \
177+ tsx=off \
178+ spectre_v2=on \
179+ ipv6.disable=1"
180+ }
181+
158182setup_usbguard () {
159183 echo -e " \n=> Setting up USBGuard..."
160184 sudo dnf install -y usbguard usbguard-notifier
@@ -309,6 +333,7 @@ BASE_OPTS=$(whiptail --title "System Base Configuration" --checklist \
309333" HARDEN" " Apply System Hardening (Fail2Ban, Sysctl, etc)" ON \
310334" FIREWALL" " Set Firewalld default zone to DROP" ON \
311335" USBGUARD" " Set up USBGuard to block unauthorized devices" OFF \
336+ " KERNEL" " Apply Hardcore Kernel Hardening" OFF \
312337" BASH" " Install custom Bash prompt" ON \
313338" AUTO_UPDATES" " Enable DNF-Automatic" OFF \
314339" SECUREBOOT" " Enroll Secure Boot Keys (sbctl)" OFF \
@@ -388,6 +413,7 @@ clear
388413[[ " $BASE_OPTS " == * " HARDEN" * ]] && sys_hardening
389414[[ " $BASE_OPTS " == * " FIREWALL" * ]] && setup_firewall_drop
390415[[ " $BASE_OPTS " == * " USBGUARD" * ]] && setup_usbguard
416+ [[ " $BASE_OPTS " == * " KERNEL" * ]] && hardcore_kernel_args
391417[[ " $BASE_OPTS " == * " NVIDIA" * ]] && install_nvidia
392418[[ " $BASE_OPTS " == * " APPLE_KBD" * ]] && hid_apple_patch
393419[[ " $BASE_OPTS " == * " DRACUT" * ]] && add_dracut_flags
0 commit comments