Skip to content
This repository has been archived by the owner on Jun 21, 2018. It is now read-only.

Commit

Permalink
system.conf: Default security settings for services
Browse files Browse the repository at this point in the history
  • Loading branch information
KellerFuchs committed Sep 21, 2015
1 parent 62d8e78 commit 39a713b
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions systemd/system.conf.d/service-isolation.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
[Service]
PrivateTmp=true # Poly-instantiates {/var,}/tmp per service
PrivateDevices=true # Only exposes API pseudo-devices (/dev/null, zero, random)
ProtectSystem=full # Makes /usr, /boot and /etc read-only
ProtectHome=true # Prevents access to /home, /root and /run/user

CapabilityBoundingSet=~CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SYS_PTRACE
NoNewPrivileges=true

0 comments on commit 39a713b

Please sign in to comment.