Skip to content

Create a "high security" profile #20161

@spacekitteh

Description

@spacekitteh

This is an easy way to reduce the barrier to creating a secure NixOS system.

It could include such things as:

  • haveged
  • containers
  • fail2ban
  • clamav
  • grsec
  • dnscrypt
  • tcpcryptd

also, optionally networking layers in separate contains such as:

  • tor
  • cjdns
  • i2p

and then use iptables to route all traffic through those containers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    0.kind: enhancementAdd something new or improve an existing system.1.severity: securityIssues which raise a security issue, or PRs that fix one
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions