33 lines
1.2 KiB
INI
33 lines
1.2 KiB
INI
..........................................................................
|
|
. WARNING
|
|
.
|
|
. This file is a kernel configuration fragment, and not a full kernel
|
|
. configuration file. The final kernel configuration is made up of
|
|
. an assembly of processed fragments, each of which is designed to
|
|
. capture a specific part of the final configuration (e.g. platform
|
|
. configuration, feature configuration, and board specific hardware
|
|
. configuration). For more information on kernel configuration, please
|
|
. consult the product documentation.
|
|
.
|
|
..........................................................................
|
|
CONFIG_AUDIT=y
|
|
CONFIG_NETWORK_SECMARK=y
|
|
CONFIG_EXT2_FS_SECURITY=y
|
|
CONFIG_EXT3_FS_SECURITY=y
|
|
CONFIG_EXT4_FS_SECURITY=y
|
|
CONFIG_JFS_SECURITY=y
|
|
CONFIG_REISERFS_FS_SECURITY=y
|
|
CONFIG_JFFS2_FS_SECURITY=y
|
|
CONFIG_SECURITY=y
|
|
CONFIG_SECURITYFS=y
|
|
CONFIG_SECURITY_NETWORK=y
|
|
CONFIG_SECURITY_SELINUX=y
|
|
CONFIG_SECURITY_SELINUX_BOOTPARAM=y
|
|
CONFIG_SECURITY_SELINUX_DISABLE=y
|
|
CONFIG_SECURITY_SELINUX_DEVELOP=y
|
|
CONFIG_SECURITY_SELINUX_AVC_STATS=y
|
|
CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE=1
|
|
CONFIG_AUDIT_GENERIC=y
|
|
CONFIG_DEFAULT_SECURITY_DAC=n
|
|
CONFIG_LSM="lockdown,yama,loadpin,safesetid,integrity,selinux,smack,tomoyo,apparmor"
|