/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

  • Committer: Teddy Hogeborn
  • Date: 2016-03-04 22:07:35 UTC
  • Revision ID: teddy@recompile.se-20160304220735-4xeeqt5p4nhw5cuh
Restrict the Mandos server daemon in the systemd service file.

* mandos.service ([Service]/ProtectSystem): Set to "full".
 ([Service]/PrivateTmp, [Service]/PrivateDevices,
  [Service]/ProtectHome): Set to "yes".
 ([Service]/CapabilityBoundingSet): Set to "CAP_SETUID
                                    CAP_DAC_OVERRIDE CAP_NET_RAW".
Filename Latest Rev Last Changed Committer Comment Size
..
File bridge 594.1.4 12 years ago Teddy Hogeborn * plugins.d/mandos-client.c (get_flags): Don't clo 2 KB Diff Download File
bridge.conf 535.1.8 13 years ago teddy at recompile * network-hooks.s/bridge: Don't use interface name 189 bytes Diff Download File
File openvpn 594.1.4 12 years ago Teddy Hogeborn * plugins.d/mandos-client.c (get_flags): Don't clo 1.4 KB Diff Download File
openvpn.conf 505.3.26 13 years ago teddy at bsnet * network-hooks.d/openvpn: Tolerate relative MANDO 291 bytes Diff Download File
File wireless 594.1.4 12 years ago Teddy Hogeborn * plugins.d/mandos-client.c (get_flags): Don't clo 4 KB Diff Download File
wireless.conf 535.1.8 13 years ago teddy at recompile * network-hooks.s/bridge: Don't use interface name 611 bytes Diff Download File