Skip to content

Commit

Permalink
init.d/service.fedora: Set SecureBits=noroot-locked
Browse files Browse the repository at this point in the history
No capabilities(7) are granted through execve(2); this setting cannot be undone.
  • Loading branch information
nbraud committed Jan 31, 2020
1 parent 2fa7c23 commit aead88a
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions init.d/service.fedora
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@ Before=sysinit.target shutdown.target systemd-journald.service
ExecStart=/usr/sbin/haveged -w 1024 -v 1 --Foreground
Restart=always
SuccessExitStatus=137 143

SecureBits=noroot-locked
CapabilityBoundingSet=CAP_SYS_ADMIN
PrivateDevices=true
PrivateNetwork=true
Expand Down

0 comments on commit aead88a

Please sign in to comment.