aboutsummaryrefslogtreecommitdiff
path: root/ansible/roles
diff options
context:
space:
mode:
authorMilo Casagrande <milo.casagrande@linaro.org>2014-12-23 15:07:32 +0100
committerMilo Casagrande <milo.casagrande@linaro.org>2014-12-23 15:07:32 +0100
commit365266db9afaba7add6d847016f2d7929ab16de1 (patch)
tree01956a4414f384224e886f9fce1451761bc0c546 /ansible/roles
parentebff68fcdb2b235bf2e11be660053cef5624fd5f (diff)
ansible: Add more sysctl config options.
Change-Id: Iedbd8e81c4dff911e90dee12a6b897358337958a
Diffstat (limited to 'ansible/roles')
-rw-r--r--ansible/roles/common/files/sysctl.conf6
1 files changed, 6 insertions, 0 deletions
diff --git a/ansible/roles/common/files/sysctl.conf b/ansible/roles/common/files/sysctl.conf
index cb3d35a..eb04524 100644
--- a/ansible/roles/common/files/sysctl.conf
+++ b/ansible/roles/common/files/sysctl.conf
@@ -75,3 +75,9 @@ kernel.randomize_va_space = 1
# Allow more PIDs
kernel.pid_max = 65536
+
+# Treat dmesg as sensitive information
+kernel.dmesg_restrict = 1
+
+# Treat kernel address as sensitive information
+kernel.kptr_restrict = 1