Setting old Kernel versions to restricted with script

Posted on

Hello,

I was tasked to lock down all but the current kernel version. I am trying to figure out how to do this via a script. It looks like these changes are within /etc/grub2-efi.cfg however we would rather mass deploy versus manually making changes. So if anyone can give me any insight on how to script where the current kernel is unrestricted and all kernels get restricted. To dive deeper.. I am also thinking future proofing when updating the kernel to the next version I would need to update while also restricting the past kernel.... Any insight or help I can get would be highly appreciated.

Thank you,
Joseph

Responses