i suggest some optimization for hardened-sources kernel series.
all of these optimizations are just increases of the default kernel parameters
i use these optimizations on my production-systems
Created attachment 94261 [details, diff]
these changes are documenter in the book "securing and optimizing linux" vol.3 by Gerhard Mourani
With 2.4.x these old changes used to be needed (when running an ircd) but with
2.6.x I'm not so sure..
What can you not do via the ulimit command?
ulimit -n 8192 ;
ulimit -OPTS ...
only changes in include/linux/limits.h can be do via ulimit
not changes in include/linux/posix_types.h and include/linux/sem.h
(In reply to comment #4)
> only changes in include/linux/limits.h can be do via ulimit
> not changes in include/linux/posix_types.h and include/linux/sem.h
If you really need to change them, please do it locally. This isn't really a patch that belongs into the hardened patchset.