HomeFreeBSD

sysctls which should be restricted when securelevel is raised should also

Description

sysctls which should be restricted when securelevel is raised should also
be restricted when veriexec is enforced.

Add mpo_system_check_sysctl method to mac_veriexec which does this.

Obtained from: Juniper Networks, Inc.
MFC after: 1 week

Details

Provenance
stevekAuthored on May 17 2019, 6:09 PM
Parents
rG3d53cd0fbbbe: Fix format strings for some debug messages that could have arguments that
Branches
Unknown
Tags
Unknown