{"id":111644,"date":"2023-11-21T03:10:16","date_gmt":"2023-11-21T01:10:16","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-fedora-40-planiruyut-vklyuchit-izolyacziyu-sistemnyh-servisov"},"modified":"2023-11-21T03:10:16","modified_gmt":"2023-11-21T01:10:16","slug":"v-fedora-40-planiruyut-vklyuchit-izolyacziyu-sistemnyh-servisov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/v-fedora-40-planiruyut-vklyuchit-izolyacziyu-sistemnyh-servisov","title":{"rendered":"Fedora 40 plans to include isolation for system services.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The Fedora 40 release proposes to include isolation settings for systemd services that are enabled by default, as well as for services with important applications such as PostgreSQL, Apache httpd, Nginx, and MariaDB. It is expected that this change will significantly enhance the security of the distribution in its default configuration and allow for the blocking of unknown vulnerabilities in system services. The proposal has not yet been reviewed by the FESCo (Fedora Engineering Steering Committee), which is responsible for the technical development of the Fedora distribution. The proposal may also be rejected during the community review process.     <\/p>\n<p>Recommended settings for inclusion:  <\/p>\n<ul>\n<li class=\"l\">  PrivateTmp=yes \u2014 providing separate directories for temporary files.\n<li class=\"l\">  ProtectSystem=yes\/full\/strict \u2014 mounting the filesystem in read-only mode (in 'full' mode \u2014 \/etc\/, in strict mode \u2014 all filesystems except \/dev\/, \/proc\/, and \/sys\/).\n<li class=\"l\">  ProtectHome=yes \u2014 preventing access to users' home directories.\n<li class=\"l\">  PrivateDevices=yes \u2014 allowing access only to \/dev\/null, \/dev\/zero, and \/dev\/random.\n<li class=\"l\">  ProtectKernelTunables=yes \u2014 read-only access to \/proc\/sys\/, \/sys\/, \/proc\/acpi, \/proc\/fs, \/proc\/irq, etc.\n<li class=\"l\">  ProtectKernelModules=yes \u2014 preventing the loading of kernel modules.\n<li class=\"l\">  ProtectKernelLogs=yes \u2014 preventing access to the kernel log buffer.\n<li class=\"l\">  ProtectControlGroups=yes \u2014 read-only access to \/sys\/fs\/cgroup\/\n<li class=\"l\">  NoNewPrivileges=yes \u2014 preventing privilege escalation through setuid, setgid, and capabilities flags.\n<li class=\"l\">  PrivateNetwork=yes \u2014 placing in a separate namespace for the network stack.\n<li class=\"l\"> ProtectClock=yes \u2014 preventing time changes.\n<li class=\"l\"> ProtectHostname=yes \u2014 preventing hostname changes.\n<li class=\"l\"> ProtectProc=invisible \u2014 hiding other users' processes in \/proc.\n<li class=\"l\"> User= \u2014 changing the user      <\/ul>\n<p>Additionally, the inclusion of the following settings may be considered:  <\/p>\n<ul>\n<li class=\"l\">    CapabilityBoundingSet=\n<li class=\"l\">    DevicePolicy=closed\n<li class=\"l\">    KeyringMode=private\n<li class=\"l\">    LockPersonality=yes\n<li class=\"l\">    MemoryDenyWriteExecute=yes\n<li class=\"l\">    PrivateUsers=yes\n<li class=\"l\">    RemoveIPC=yes\n<li class=\"l\">    RestrictAddressFamilies=\n<li class=\"l\">    RestrictNamespaces=yes\n<li class=\"l\">    RestrictRealtime=yes\n<li class=\"l\">    RestrictSUIDSGID=yes\n<li class=\"l\">    SystemCallFilter=\n<li class=\"l\">    SystemCallArchitectures=native  <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60152\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Fedora 40 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043e \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u044b\u0445 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 systemd, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0441 \u0432\u0430\u0436\u043d\u044b\u043c\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c\u0438, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a PostgreSQL, Apache httpd, Nginx \u0438 MariaDB. \u041f\u0440\u0435\u0434\u043f\u043e\u043b\u0430\u0433\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u043e\u0441\u0442\u044c \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0438 \u0434\u0430\u0441\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u0430\u0445. \u041f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043f\u043e\u043a\u0430 \u043d\u0435 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u043e \u043a\u043e\u043c\u0438\u0442\u0435\u0442\u043e\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-111644","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Fedora 40 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043e \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u044b\u0445 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 systemd, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0441 \u0432\u0430\u0436\u043d\u044b\u043c\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c\u0438, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a PostgreSQL, Apache httpd, Nginx \u0438 MariaDB.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/v-fedora-40-planiruyut-vklyuchit-izolyacziyu-sistemnyh-servisov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 Fedora 40 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Fedora 40 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043e \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u044b\u0445 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 systemd, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0441 \u0432\u0430\u0436\u043d\u044b\u043c\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c\u0438, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a PostgreSQL, Apache httpd, Nginx \u0438 MariaDB.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/v-fedora-40-planiruyut-vklyuchit-izolyacziyu-sistemnyh-servisov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-11-21T01:10:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-11-21T01:10:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Fedora 40 plans to include isolation for system services | ProHoster","description":"The Fedora 40 release proposes to include isolation settings for systemd services that are enabled by default, as well as for services with important applications such as PostgreSQL, Apache httpd, Nginx, and MariaDB.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/v-fedora-40-planiruyut-vklyuchit-izolyacziyu-sistemnyh-servisov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 Fedora 40 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e\u0442 \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 | ProHoster","og:description":"\u0412 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Fedora 40 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043e \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u0434\u043b\u044f \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u044b\u0445 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 systemd, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432 \u0441 \u0432\u0430\u0436\u043d\u044b\u043c\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c\u0438, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a PostgreSQL, Apache httpd, Nginx \u0438 MariaDB.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/v-fedora-40-planiruyut-vklyuchit-izolyacziyu-sistemnyh-servisov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-11-21T01:10:16+00:00","article:modified_time":"2023-11-21T01:10:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/111644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=111644"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/111644\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=111644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=111644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=111644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}