summary refs log tree commit diff
path: root/nixos/modules/security
AgeCommit message (Expand)AuthorFilesLines
2019-05-13FIx some malformed XML in option descriptionsEelco Dolstra1-16/+2
2019-05-12Merge pull request #61306 from joachifm/feat/fix-apparmor-boot-linux_5_1Joachim F1-0/+2
2019-05-11nixos/apparmor: ensure that apparmor is selected at bootJoachim Fasting1-0/+2
2019-05-07rngd: harden service config, from archWill Dietz1-0/+5
2019-05-06rngd: add option to run w/debug flagWill Dietz1-10/+23
2019-04-28nixos/apparmor: allow reloading profiles without losing confinementJoachim Fasting1-0/+3
2019-04-28nixos/apparmor: order before sysinit.targetJoachim Fasting1-1/+6
2019-04-21nixos/hardened: split description of allowUserNamespaces into parasJoachim Fasting1-7/+17
2019-04-14nixos/pam: Add GNOME keyring use_authtok directive to password groupAlexander Kahl1-0/+2
2019-03-31yubico-pam: add nixos integrationWill Dietz1-0/+60
2019-03-29Merge pull request #57519 (systemd-confinement)aszlig1-0/+199
2019-03-27nixos/confinement: Use PrivateMounts optionaszlig1-1/+1
2019-03-27nixos/confinement: Remove handling for StartOnlyaszlig1-7/+2
2019-03-17nixos/security: make duo support secure failure correctlyAlex Guzman1-1/+1
2019-03-15nixos/confinement: Explicitly set serviceConfigaszlig1-8/+20
2019-03-14nixos/confinement: Allow to include the full unitaszlig1-3/+24
2019-03-14nixos/confinement: Allow to configure /bin/shaszlig1-12/+23
2019-03-14nixos/systemd-chroot: Rename chroot to confinementaszlig1-13/+13
2019-03-14nixos: Add 'chroot' options to systemd.servicesaszlig1-0/+160
2019-02-25Merge pull request #55792 from sdier/fix/pam-updateSilvan Mosberger2-14/+26
2019-02-24nixos/security: Fix pam configuration file generation.Scott Dier1-5/+8
2019-02-24nixos/security: Allow configuration of pam for duosec.Scott Dier1-6/+0
2019-02-24nixos/security: Add duo-unix support to pam.Scott Dier1-3/+18
2019-02-22nixos: add preferLocalBuild=true; on derivations for config filesSymphorien Gibol2-1/+5
2019-01-30Merge pull request #53762 from ju1m/nslcdFlorian Klink1-1/+1
2019-01-29nixos/pam: refactor U2F, docs about u2f_keys path (#54756)Wael Nasreddine1-11/+98
2019-01-18nixos/tests: test LDAP password changing through nslcdJulien Moutinho1-1/+1
2018-12-27nixos/security/misc: expose SMT control optionJoachim Fasting1-0/+30
2018-12-27nixos/security/misc: expose l1tf mitigation optionJoachim Fasting1-0/+39
2018-12-27nixos/security/misc: factor out protectKernelImageJoachim Fasting1-0/+15
2018-12-27nixos/security/misc: use mkMerge for easier extensionJoachim Fasting1-11/+13
2018-12-21config.security.googleOsLogin: add moduleFlorian Klink1-0/+68
2018-12-21security.pam.services.<name?>.: add googleOsLogin(AccountVerification|Authent...Florian Klink1-0/+30
2018-12-21security.pam: make pam_unix.so required, not sufficientFlorian Klink1-1/+1
2018-11-05nixos/rngd: do not pass --version flagGabriel Ebner1-1/+1
2018-10-30apparmor-suid: don't force glibcWill Dietz1-1/+1
2018-10-31dhparams module: add self as maintainerLéo Gaspard1-0/+2
2018-10-28nixos/rngd: fix exec flags and udev rulesRenaud1-3/+1
2018-10-24nixos/rngd: use new name pkgs.rng-toolsRenaud1-1/+1
2018-10-21nixos/wrappers: remove outdated upgrade codeLinus Heckemann1-29/+0
2018-10-15Merge pull request #48439 from joachifm/hardened-miscJoachim F1-0/+39
2018-10-15nixos/security/misc: initJoachim Fasting1-0/+39
2018-10-15nixos/lock-kernel-modules: add myself to maintainersJoachim Fasting1-0/+4
2018-10-02Merge pull request #47563 from jameysharp/unscriptedJörg Thalheim2-5/+12
2018-09-30nixos/pam: create wtmp/lastlog iff using pam_lastlogJamey Sharp1-0/+7
2018-09-30nixos/polkit: use tmpfiles to clean old dirsJamey Sharp1-5/+5
2018-09-29docs: formatGraham Christensen2-70/+71
2018-09-12acme module: fix self-signed cert with openssl 1.1Robin Gloster1-4/+4
2018-09-01nixos docs: give IDs to thingsGraham Christensen1-3/+3
2018-07-23Merge pull request #42834 from Synthetica9/patch-1Matthew Bauer1-1/+1