Skip to content

Commit

Permalink
Harden wtmpdbd.service
Browse files Browse the repository at this point in the history
  • Loading branch information
thkukuk committed Jan 10, 2025
1 parent 793021a commit cbabeb7
Showing 1 changed file with 19 additions and 0 deletions.
19 changes: 19 additions & 0 deletions units/wtmpdbd.service
Original file line number Diff line number Diff line change
Expand Up @@ -7,3 +7,22 @@ Type=notify
Environment="WTMPDBD_OPTS="
EnvironmentFile=-/etc/default/wtmpdbd
ExecStart=/usr/libexec/wtmpdbd -s $WTMPDBD_OPTS
#DeviceAllow=/dev/vsock r
IPAddressDeny=any
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
PrivateNetwork=yes
PrivateTmp=yes
ProtectControlGroups=yes
ProtectHome=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
ProtectProc=invisible
ProtectSystem=strict
ReadWritePaths=/etc /run/wtmpdb /var/lib/wtmpdb
RestrictAddressFamilies=AF_UNIX
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes

0 comments on commit cbabeb7

Please sign in to comment.