Index: audit-3.0.9/init.d/auditd.service =================================================================== --- audit-3.0.9.orig/init.d/auditd.service +++ audit-3.0.9/init.d/auditd.service @@ -38,6 +38,15 @@ LockPersonality=true ProtectControlGroups=true ProtectKernelModules=true RestrictRealtime=true +# added automatically, for details please see +# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort +ProtectSystem=full +PrivateDevices=true +ProtectHostname=true +ProtectClock=true +ProtectKernelTunables=true +ProtectKernelLogs=true +# end of automatic additions [Install] WantedBy=multi-user.target