On Nov 29, Jarl Gullberg <jarl.gullberg@visar-systems.com> wrote:
The short summary is that we're looking at improving the usage of systemd's hardening options for services, sockets, timers, and the like within the Debian ecosystem. Right now, usage levels are pretty varied and there aren't any hardening guidelines in place for Debian packages as it relates to systemd service hardening.This looks like a great idea, but I think it would be hard to execute without real-world testing of each package. E.g. as it has been noted in this thread, daemons which send emails cannot use NoNewPrivileges.
A related topic is to systematically enable StateDirectory, LogsDirectory, etc... everywhere they can be used.
-- ciao, Marco
Attachment:
signature.asc
Description: PGP signature