
Untitled
By: a guest on
Apr 28th, 2012 | syntax:
None | size: 0.58 KB | hits: 19 | expires: Never
CONFIG_GRKERNSEC_SYSCTL_DISTRO:
If you say Y here, additional sysctl options will be created
for features that affect processes running as root. Therefore,
it is critical when using this option that the grsec_lock entry be
enabled after boot. Only distros with prebuilt kernel packages
with this option enabled that can ensure grsec_lock is enabled
after boot should use this option.
*Failure to set grsec_lock after boot makes all grsec features
this option covers useless*
Currently this option creates the following sysctl entries:
"Disable Privileged I/O": "disable_priv_io"