saikyo-packages-src/saikyo-security-profile/profiles/standard.json

22 lines
409 B
JSON

{
"enable_services": [
"apparmor.service",
"auditd.service"
],
"sysctl": {
"kernel.dmesg_restrict": "1",
"kernel.kptr_restrict": "2",
"kernel.yama.ptrace_scope": "1",
"net.ipv4.conf.all.rp_filter": "1",
"net.ipv4.conf.default.rp_filter": "1"
},
"ufw": {
"allow": [
"OpenSSH"
],
"default_in": "deny",
"default_out": "allow",
"enable": true
}
}