Skip to content

Commit f3e9562

Browse files
committed
Kernel hardening args and Ipv6 privacy
1 parent 096352b commit f3e9562

2 files changed

Lines changed: 31 additions & 4 deletions

File tree

‎README.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,7 @@ The script uses a standard Whiptail terminal interface. You just check off the f
2222

2323
### Hardening & Privacy
2424
* **Kernel & Network:** Applies Secureblue-inspired sysctl hardening, randomizes MAC addresses, and sets Firewalld to DROP.
25+
* **Hardcore Kernel Hardening Args** Applies "Hardcore" kernel hardening.
2526
* **Physical Security:** Installs and enables `usbguard` and `fail2ban`.
2627
* **Secure Boot:** Creates and enrolls custom Secure Boot keys via `sbctl`.
2728
* **Tor & VPNs:** Easily install the Tor daemon/browser, IVPN, or Mullvad.

‎fqs‎

Lines changed: 30 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -85,19 +85,28 @@ sys_hardening() {
8585
sudo dnf install -y fail2ban
8686
sudo systemctl enable --now fail2ban
8787

88-
local network_file="/etc/NetworkManager/conf.d/00-macrandomize.conf"
89-
if [ ! -f "$network_file" ]; then
90-
sudo tee -a "$network_file" >/dev/null <<'EOF'
88+
local macrandomize_rule="/etc/NetworkManager/conf.d/00-macrandomize.conf"
89+
if [ ! -f "$macrandomize_rule" ]; then
90+
sudo tee -a "$macrandomize_rule" >/dev/null <<'EOF'
9191
[device]
9292
wifi.scan-rand-mac-address=yes
9393
9494
[connection]
9595
wifi.cloned-mac-address=random
9696
ethernet.cloned-mac-address=random
9797
EOF
98-
sudo systemctl restart NetworkManager
9998
fi
10099

100+
local ipv6_privacy_rule="/etc/NetworkManager/conf.d/00-ipv6-privacy.conf"
101+
if [ ! -f "$ipv6_privacy_rule" ]; then
102+
sudo tee -a "$ipv6_privacy_rule" >/dev/null <<'EOF'
103+
[connection]
104+
ipv6.ip6-privacy=2
105+
EOF
106+
fi
107+
108+
sudo systemctl restart NetworkManager
109+
101110
echo "Applying sysctl hardening..."
102111
local sysctl_file="/etc/sysctl.d/55-hardening.conf"
103112
sudo tee "$sysctl_file" >/dev/null <<'EOF'
@@ -155,6 +164,21 @@ EOF
155164
sudo systemctl disable cups avahi-daemon
156165
}
157166

167+
hardcore_kernel_args() {
168+
echo -e "\n=> Applying hardcore kernel hardening arguments..."
169+
sudo grubby --update-kernel=ALL --args="\
170+
module.sig_enforce=1 \
171+
lockdown=confidentiality \
172+
kptr_restrict=2 \
173+
spec_store_bypass_disable=on \
174+
pti=on \
175+
l1tf=full,force \
176+
mds=full,nosmt \
177+
tsx=off \
178+
spectre_v2=on \
179+
ipv6.disable=1"
180+
}
181+
158182
setup_usbguard() {
159183
echo -e "\n=> Setting up USBGuard..."
160184
sudo dnf install -y usbguard usbguard-notifier
@@ -309,6 +333,7 @@ BASE_OPTS=$(whiptail --title "System Base Configuration" --checklist \
309333
"HARDEN" "Apply System Hardening (Fail2Ban, Sysctl, etc)" ON \
310334
"FIREWALL" "Set Firewalld default zone to DROP" ON \
311335
"USBGUARD" "Set up USBGuard to block unauthorized devices" OFF \
336+
"KERNEL" "Apply Hardcore Kernel Hardening" OFF \
312337
"BASH" "Install custom Bash prompt" ON \
313338
"AUTO_UPDATES" "Enable DNF-Automatic" OFF \
314339
"SECUREBOOT" "Enroll Secure Boot Keys (sbctl)" OFF \
@@ -388,6 +413,7 @@ clear
388413
[[ "$BASE_OPTS" == *"HARDEN"* ]] && sys_hardening
389414
[[ "$BASE_OPTS" == *"FIREWALL"* ]] && setup_firewall_drop
390415
[[ "$BASE_OPTS" == *"USBGUARD"* ]] && setup_usbguard
416+
[[ "$BASE_OPTS" == *"KERNEL"* ]] && hardcore_kernel_args
391417
[[ "$BASE_OPTS" == *"NVIDIA"* ]] && install_nvidia
392418
[[ "$BASE_OPTS" == *"APPLE_KBD"* ]] && hid_apple_patch
393419
[[ "$BASE_OPTS" == *"DRACUT"* ]] && add_dracut_flags

0 commit comments

Comments
 (0)