1
1
mirror of https://gitlab.archlinux.org/archlinux/infrastructure.git synced 2024-09-20 07:12:19 +02:00
infrastructure/roles/hardening/files/50-lockdown.conf
Giancarlo Razzolini eb64ecaf1b
roles/hardening: Change the lockdown file creation to run only at boot
Since after enabling lockdown you cannot change the file anymore until reboot,
change the tmpfile setting to use ! and run only at boot time. This makes
systemd-tmpfiles --create command to not fail, since it cannot write to the lockdown
file.
2020-02-13 13:40:28 -03:00

2 lines
51 B
Plaintext

w! /sys/kernel/security/lockdown - - - - integrity