sftpgo/init
Marc 9b6b9cca3d systemd-security: add some easy wins
We can tighten security by adding the following to
the systemd service file:

* NoNewPrivileges: should never be needed
* DevicePolicy: only basics required
* PrivateDevices: only needs mounted stuff, never devs
* ProtectSystem: no need to change boot
* RestrictAddressFamilies: INET, UNIX only

Signed-off-by: Marc <mail@lpcvoid.com>
2022-01-15 13:31:59 +01:00
..
com.github.drakkan.sftpgo.plist improve some docs 2021-12-26 14:54:29 +01:00
sftpgo.service systemd-security: add some easy wins 2022-01-15 13:31:59 +01:00