From 64035201b56ee78dc937dfa675e610c03850dcad Mon Sep 17 00:00:00 2001 From: shibayashi Date: Fri, 28 Dec 2018 21:09:48 +0100 Subject: [PATCH] Security/Drops the sysadmin privilege from the daemon --- installation/pleroma.service | 2 ++ 1 file changed, 2 insertions(+) diff --git a/installation/pleroma.service b/installation/pleroma.service index 6955e5cc6..f1ed56cb3 100644 --- a/installation/pleroma.service +++ b/installation/pleroma.service @@ -21,6 +21,8 @@ ProtectSystem=full PrivateDevices=false ; Ensures that the service process and all its children can never gain new privileges through execve(). NoNewPrivileges=true +; Drops the sysadmin capability from the daemon. +CapabilityBoundingSet=~CAP_SYS_ADMIN [Install] WantedBy=multi-user.target