summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorChristian Hesse <mail@eworm.de>2019-09-04 13:32:19 +0200
committerChristian Hesse <mail@eworm.de>2019-09-04 16:04:40 +0200
commit0fad7226c33c5fd1f94321986f0a96bd9fd5da04 (patch)
tree2b0de4377c9c94b8343519889bf4b1ebfc369f1b
parentdo not run in container (diff)
downloadhaveged-0fad7226c33c5fd1f94321986f0a96bd9fd5da04.tar.xz
haveged-0fad7226c33c5fd1f94321986f0a96bd9fd5da04.zip
use systemd security features
-rw-r--r--init.d/service.fedora5
1 files changed, 5 insertions, 0 deletions
diff --git a/init.d/service.fedora b/init.d/service.fedora
index 0fe6ef6..fdc7bae 100644
--- a/init.d/service.fedora
+++ b/init.d/service.fedora
@@ -9,6 +9,11 @@ Before=sysinit.target shutdown.target systemd-journald.service
ExecStart=/usr/sbin/haveged -w 1024 -v 1 --Foreground
Restart=always
SuccessExitStatus=137 143
+CapabilityBoundingSet=CAP_SYS_ADMIN
+NoNewPrivileges=on
+PrivateDevices=on
+PrivateNetwork=on
+ProtectSystem=full
[Install]
WantedBy=sysinit.target