I am currently running the following hardening settings:
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
PrivateDevices=yes
PrivateTmp=yes
ProtectClock=yes
ProtectControlGroups=yes
ProtectHome=yes
ProtectHostname=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectKernelT
Package: quassel-core
Severity: wishlist
X-Debbugs-Cc: jvalle...@mailbox.org
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512
Dear Maintainer,
Please consider adding systemd service hardening options to the service file.
These are the options we have been using in FreedomBox [1]:
[Service]
Loc
2 matches
Mail list logo