Harden profiles

- Added 'disable-devel.conf' to many profiles
- Added 'disable-mnt' to many profiles
- Added 'noexec' to many profiles
- Removed 'netfilter' and 'net none' from profiles with 'protocol unix'
- Cleaned up profiles using defaults
This commit is contained in:
Tad 2017-07-05 09:40:54 -04:00
parent 8ef01b3863
commit 0dba38435e
105 changed files with 535 additions and 484 deletions

View file

@ -30,6 +30,7 @@ protocol unix,inet,inet6
seccomp
shell none
private
private-bin gnome-calculator
private-dev
#private-etc fonts