summary refs log tree commit diff
path: root/nixos/modules/security
Commit message (Expand)AuthorAge
* apparmor: support for lxc profilesJörg Thalheim2017-01-10
* nixos docs: update for Nginx + ACME (#21320)teh2017-01-09
* sssd: init at 1.14.2Alexander Kahl2017-01-04
* grsecurity doc: describe work-around for gitlabJoachim Fasting2016-12-08
* hidepid: polkit and systemd-logind compatibilityJoachim Fasting2016-12-07
* grsecurity: enable module hardeningJoachim Fasting2016-12-06
* grsecurity docs: note that pax_sanitize_slab defaults to fastJoachim Fasting2016-12-06
* grsecurity: enable optional sysfs restrictionsJoachim Fasting2016-12-06
* grsecurity: delay toggling of sysctls until system is upJoachim Fasting2016-12-06
* acme: ensure nginx challenges directory is writeableDomen Kožar2016-11-29
* grsecurity module: force a known good kernel package setJoachim Fasting2016-11-28
* grsecurity module: remove code pertaining to zfsJoachim Fasting2016-11-20
* grsecurity module: remove requiredKernelConfigJoachim Fasting2016-11-20
* grsecurity module: remove use of mkEnableOptionJoachim Fasting2016-11-20
* duosec module: use enumEric Sagnes2016-11-16
* grsecurity: fix 'isYes' and 'isNo'Timofei Kushnir2016-10-29
* acme: we do want to support ipv4 afterallDomen Kožar2016-10-21
* acme: provide full nginx exampleDomen Kožar2016-10-21
* audit module: only enable service if kernel has audit (#19569)Alexander Ried2016-10-15
* cacerts: refactor, add blacklist optionFranz Pletz2016-10-09
* nixos.acme: make timer persistentRicardo M. Correia2016-10-03
* grsecurity doc: note that module autoload hardening is disabledJoachim Fasting2016-10-02
* grsecurity: make GRKERNSEC y and PAX y implicitJoachim Fasting2016-10-02
* Merge pull request #18511 from ericsagnes/feat/remove-optionSetJoachim F2016-10-01
|\
| * pam module: optionSet -> submoduleEric Sagnes2016-09-13
| * acme module: optionSet -> submoduleEric Sagnes2016-09-13
* | Merge branch 'rngd-wantedBy' of git://github.com/srp/nixpkgs-1Shea Levy2016-09-19
|\ \
| * | rngd: update modalias to match cpu typeScott R. Parish2016-09-17
* | | Revert "nixos/pam: clean up generated files (no functional change) (#18580)"Thomas Tuegel2016-09-17
|/ /
* | nixos/pam: Fix wrong string concatenationaszlig2016-09-16
* | hidepid module: detailed description to external docJoachim Fasting2016-09-15
* | nixos/pam: clean up generated files (no functional change) (#18580)Bjørn Forsman2016-09-14
* | sudo: Allow root to use sudo to switch groupsRoger Qiu2016-09-13
|/
* Merge pull request #18366 from groxxda/acme-loopFranz Pletz2016-09-06
|\
| * security.acme: the client really needs networkingAlexander Ried2016-09-06
* | Enable the runuser command from util-linuxEelco Dolstra2016-09-06
|/
* grsecurity module: set nixpkgs.config.grsecurity = trueJoachim Fasting2016-09-05
* setuid-wrappers: correctly umount the tmpfsDomen Kožar2016-09-04
* setuid-wrappers : Prepare permissions for running wrappersKarn Kallio2016-09-04
* Fixes #18124: atomically replace /var/setuid-wrappers/ (#18186)Domen Kožar2016-09-01
* Merge staging into masterTuomas Tynkkynen2016-09-01
|\
| * audit: Disable by defaultTuomas Tynkkynen2016-08-31
| * audit service: Explicitly call auditctl to disable everythingTuomas Tynkkynen2016-08-31
* | Revert "setuid-wrappers: Update wrapper dir atomically."Domen Kožar2016-08-31
* | hidepid service: use new boot.specialFileSystemsNikolay Amiantov2016-08-31
* | setuid-wrappers: Update wrapper dir atomically.Shea Levy2016-08-31
* | Merge pull request #17822 from abbradar/systemd-mountsNikolay Amiantov2016-08-30
|\ \
| * | nixos filesystems: unify early filesystems handlingNikolay Amiantov2016-08-27
* | | nixos manual: move chapter on grsecurity to auto-generated module docsJoachim Fasting2016-08-29
| |/ |/|
* | Merge pull request #15025 from ericsagnes/modules/manualDomen Kožar2016-08-28
|\ \ | |/ |/|