From b57ec8c0e56015553c468e7282905fa8582632ba Mon Sep 17 00:00:00 2001 From: Denis Chevalier Date: Thu, 6 Aug 2026 13:48:44 +0200 Subject: move sysctl, mkinitcpio and systemctl commands to sysctl.bash --- etc.bash | 18 ------------------ sysctl.bash | 22 ++++++++++++++++++++++ 2 files changed, 22 insertions(+), 18 deletions(-) diff --git a/etc.bash b/etc.bash index 9e5a253..1477d17 100755 --- a/etc.bash +++ b/etc.bash @@ -11,7 +11,6 @@ sudo cp -v ./etc/updatedb.conf /etc/ sudo cp -v ./etc/sudoers.d/00-hardening /etc/sudoers.d/ sudo cp -v ./etc/systemd/coredump.conf /etc/systemd/ sudo cp -v ./etc/sysctl.d/99-security.conf /etc/sysctl.d/ -sudo sysctl --system grep tmpfs /etc/fstab || sudo cat ./etc/fstab >> /etc/fstab @@ -27,14 +26,9 @@ sudo systemctl enable --now ufw # fail2ban sudo cp -v ./etc/fail2ban/jail.d/sshd.conf /etc/fail2ban/jail.d/ -sudo systemctl enable --now fail2ban - -# fs trim -sudo systemctl enable --now fstrim.timer # linux-hardened sudo cp -v ./etc/mkinitcpio.d/linux-hardened.preset /etc/mkinitcpio.d -sudo mkinitcpio -P # harden systemd services echo "==> Creating drop-in override directories..." @@ -50,15 +44,3 @@ sudo cp -v ./etc/systemd/system/fail2ban.service.d/override.conf /etc/systemd/sy echo "==> Applying cups.service hardening..." sudo cp -v ./etc/systemd/system/cups.service.d/override.conf /etc/systemd/system/cups.service.d/ - -sudo systemctl daemon-reload - -echo "==> Restarting services..." -for svc in sshd fail2ban cups; do - if systemctl is-active --quiet "$svc"; then - echo " Restarting active service: $svc" - sudo systemctl restart "$svc" - else - echo " Skipping restart for inactive service: $svc" - fi -done diff --git a/sysctl.bash b/sysctl.bash index b2c9b9c..fcbadb2 100755 --- a/sysctl.bash +++ b/sysctl.bash @@ -1,8 +1,30 @@ #!/bin/bash +sudo sysctl --system + +sudo mkinitcpio -P + +sudo systemctl daemon-reload + systemctl --user enable gnome-keyring-daemon.socket systemctl --user enable ssh-agent.socket sudo systemctl enable keyd.service sudo systemctl enable proton.VPN.service sudo systemctl enable snapper-cleanup.timer sudo systemctl enable snapper-timeline.timer + +# fail2ban +sudo systemctl enable --now fail2ban + +# fs trim +sudo systemctl enable --now fstrim.timer + +echo "==> Restarting services..." +for svc in sshd fail2ban cups; do + if systemctl is-active --quiet "$svc"; then + echo " Restarting active service: $svc" + sudo systemctl restart "$svc" + else + echo " Skipping restart for inactive service: $svc" + fi +done -- cgit