diff --git a/prelude-lml.changes b/prelude-lml.changes index 7fc5f47..ce4ed1d 100644 --- a/prelude-lml.changes +++ b/prelude-lml.changes @@ -1,3 +1,9 @@ +------------------------------------------------------------------- +Wed Oct 20 08:59:50 UTC 2021 - Johannes Segitz + +- Added hardening to systemd service(s) (bsc#1181400). Modified: + * prelude-lml.service + ------------------------------------------------------------------- Sun Oct 25 18:29:49 UTC 2020 - Andreas Stieger diff --git a/prelude-lml.service b/prelude-lml.service index 6f3e447..59bd5c1 100644 --- a/prelude-lml.service +++ b/prelude-lml.service @@ -3,6 +3,19 @@ Description=Log analyzer sensor with IDMEF output After=remode_fs.target prelude-manager.service [Service] +# added automatically, for details please see +# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort +ProtectSystem=full +ProtectHome=true +PrivateDevices=true +ProtectHostname=true +ProtectClock=true +ProtectKernelTunables=true +ProtectKernelModules=true +ProtectKernelLogs=true +ProtectControlGroups=true +RestrictRealtime=true +# end of automatic additions ExecStart=/usr/bin/prelude-lml [Install]