Fedora 40 plans to include isolation for system services.

The Fedora 40 release proposes to include isolation settings for systemd services that are enabled by default, as well as for services with important applications such as PostgreSQL, Apache httpd, Nginx, and MariaDB. It is expected that this change will significantly enhance the security of the distribution in its default configuration and allow for the blocking of unknown vulnerabilities in system services. The proposal has not yet been reviewed by the FESCo (Fedora Engineering Steering Committee), which is responsible for the technical development of the Fedora distribution. The proposal may also be rejected during the community review process.

Recommended settings for inclusion:

  • PrivateTmp=yes β€” provides separate directories for temporary files.
  • ProtectSystem=yes/full/strict β€” mounts the filesystem in read-only mode (in 'full' mode β€” /etc/, in strict mode β€” all filesystems except /dev/, /proc/, and /sys/).
  • ProtectHome=yes β€” denies access to users' home directories.
  • PrivateDevices=yes β€” leaves access only to /dev/null, /dev/zero, and /dev/random.
  • ProtectKernelTunables=yes β€” read-only access to /proc/sys/, /sys/, /proc/acpi, /proc/fs, /proc/irq, etc.
  • ProtectKernelModules=yes β€” prohibits loading kernel modules.
  • ProtectKernelLogs=yes β€” denies access to the kernel log buffer.
  • ProtectControlGroups=yes β€” read-only access to /sys/fs/cgroup/
  • NoNewPrivileges=yes β€” prohibits privilege escalation via setuid, setgid, and capabilities flags.
  • PrivateNetwork=yes β€” places in a separate network stack namespace.
  • ProtectClock=yes β€” prohibits changing the time.
  • ProtectHostname=yes β€” prohibits changing the hostname.
  • ProtectProc=invisible β€” hides other users' processes in /proc.
  • User= β€” changes the user.

Additionally, the inclusion of the following settings may be considered:

  • CapabilityBoundingSet=
  • DevicePolicy=closed
  • KeyringMode=private
  • LockPersonality=yes
  • MemoryDenyWriteExecute=yes
  • PrivateUsers=yes
  • RemoveIPC=yes
  • RestrictAddressFamilies=
  • RestrictNamespaces=yes
  • RestrictRealtime=yes
  • RestrictSUIDSGID=yes
  • SystemCallFilter=
  • SystemCallArchitectures=native

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers πŸ”₯ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster