Re: [RFC cip-dev][isar-cip-core][PATCH 00/14] Add recipes for image hardening
Jan Kiszka <[email protected]> Mon, 27 Jul 2026 16:18:07 +0200
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <[email protected]> |
On 24.07.26 14:39, Quirin Gylstorff wrote: > From: Quirin Gylstorff <[email protected]> > > This patch series adds the option to harden the build image according to the guidelines published by CIS. > The patch introduces the following packages: > > cip-cis-rules-config: user-facing configuration, stored in .config.json and configurable interactively via Kconfig. > cip-cis-rules: uses the configuration from cip-cis-rules-config to generate a custom Debian package containing the necessary hardening configuration. > cip-cis-validation: an optional package to validate the hardening rules. > > Additionally, the kernel configuration is checked against the hardening rules. > This patch set is currently developed and tested for hardening level 2. > Meta question: There are a lot of "cip" prefixes used across the code. Is everything that is really prefixed like that CIP-specific or CIP-augmented? Where not, I would suggest to stick with plain "cis"/"CIS" as prefix. Jan -- Siemens AG, Foundational Technologies Linux Expert Center