Re: Systemd service hardening project
I had not seen that thread, no! Lots of useful information in there that
I think we can easily carry forward.
I have tried shh with some success, but I found it was easier to do
services by hand once I got a feel for it. Could be useful for more
in-depth hardening, though, like syscalls.
I'm glad to see there's already a release goal wiki for this, and as far
as I can tell this might "just" be a matter of reviving that with a bit
more structure to it.
Putting the horse slightly before the cart here, but developing a
lintian inspection for it like mentioned in the thread definitely sounds
worthwhile.
--
Jarl Gullberg
CEO & CTO
Visar Systems AB
+46 73 644 96 64
jarl.gullberg@visar-systems.com
https://visar-systems.com
Reply to: