aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMilo Casagrande <milo.casagrande@linaro.org>2014-12-23 15:08:14 +0100
committerMilo Casagrande <milo.casagrande@linaro.org>2014-12-23 15:08:14 +0100
commitcd74248bf1fbf34926a319ff39784b7459575138 (patch)
tree50358e563910e472b2962efaaff96f7779d92f7c
parent8c46ea5f6e66c53bacc4e5966f23b4e1279edd42 (diff)
ansible: Add more sysctl options.
Change-Id: Ic65f195cee6c164495c9ca46160d4e971a1f7666
-rw-r--r--ansible/roles/common/files/sysctl.conf6
1 files changed, 6 insertions, 0 deletions
diff --git a/ansible/roles/common/files/sysctl.conf b/ansible/roles/common/files/sysctl.conf
index cb3d35a..eb04524 100644
--- a/ansible/roles/common/files/sysctl.conf
+++ b/ansible/roles/common/files/sysctl.conf
@@ -75,3 +75,9 @@ kernel.randomize_va_space = 1
# Allow more PIDs
kernel.pid_max = 65536
+
+# Treat dmesg as sensitive information
+kernel.dmesg_restrict = 1
+
+# Treat kernel address as sensitive information
+kernel.kptr_restrict = 1