Fedora 40์€ ์‹œ์Šคํ…œ ์„œ๋น„์Šค ๊ฒฉ๋ฆฌ๋ฅผ ํ™œ์„ฑํ™”ํ•  ๊ณ„ํš์ž…๋‹ˆ๋‹ค.

Fedora 40 ๋ฆด๋ฆฌ์Šค์—์„œ๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ํ™œ์„ฑํ™”๋œ ์‹œ์Šคํ…œ ์‹œ์Šคํ…œ ์„œ๋น„์Šค๋ฟ๋งŒ ์•„๋‹ˆ๋ผ PostgreSQL, Apache httpd, Nginx ๋ฐ MariaDB์™€ ๊ฐ™์€ ๋ฏธ์…˜ ํฌ๋ฆฌํ‹ฐ์ปฌ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ํฌํ•จ๋œ ์„œ๋น„์Šค์— ๋Œ€ํ•œ ๊ฒฉ๋ฆฌ ์„ค์ • ํ™œ์„ฑํ™”๋ฅผ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฒˆ ๋ณ€๊ฒฝ์œผ๋กœ ๊ธฐ๋ณธ ๊ตฌ์„ฑ์—์„œ ๋ฐฐํฌํŒ์˜ ๋ณด์•ˆ์„ฑ์ด ๋Œ€ํญ ๊ฐ•ํ™”๋˜๊ณ , ์‹œ์Šคํ…œ ์„œ๋น„์Šค์—์„œ ์•Œ๋ ค์ง€์ง€ ์•Š์€ ์ทจ์•ฝ์ ์„ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋  ๊ฒƒ์œผ๋กœ ๊ธฐ๋Œ€๋œ๋‹ค. ์ด ์ œ์•ˆ์€ ์•„์ง Fedora ๋ฐฐํฌํŒ ๊ฐœ๋ฐœ์˜ ๊ธฐ์ˆ ์ ์ธ ๋ถ€๋ถ„์„ ๋‹ด๋‹นํ•˜๋Š” FESCo(Fedora Engineering Steering Committee)์—์„œ ๊ณ ๋ ค๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ์ปค๋ฎค๋‹ˆํ‹ฐ ๊ฒ€ํ†  ๊ณผ์ •์—์„œ ์ œ์•ˆ์ด ๊ฑฐ๋ถ€๋  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ™œ์„ฑํ™”ํ•  ๊ถŒ์žฅ ์„ค์ •:

  • PrivateTmp=yes - ์ž„์‹œ ํŒŒ์ผ์ด ํฌํ•จ๋œ ๋ณ„๋„์˜ ๋””๋ ‰ํ„ฐ๋ฆฌ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
  • ProtectSystem=yes/full/strict โ€” ํŒŒ์ผ ์‹œ์Šคํ…œ์„ ์ฝ๊ธฐ ์ „์šฉ ๋ชจ๋“œ๋กœ ๋งˆ์šดํŠธํ•ฉ๋‹ˆ๋‹ค("์ „์ฒด" ๋ชจ๋“œ - /etc/, ์—„๊ฒฉ ๋ชจ๋“œ - /dev/, /proc/ ๋ฐ /sys/๋ฅผ ์ œ์™ธํ•œ ๋ชจ๋“  ํŒŒ์ผ ์‹œ์Šคํ…œ).
  • ProtectHome=yes - ์‚ฌ์šฉ์ž ํ™ˆ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค๋ฅผ ๊ฑฐ๋ถ€ํ•ฉ๋‹ˆ๋‹ค.
  • PrivateDevices=yes - /dev/null, /dev/zero ๋ฐ /dev/random์—๋งŒ ์•ก์„ธ์Šคํ•˜๋„๋ก ๋‘ก๋‹ˆ๋‹ค.
  • ProtectKernelTunables=yes - /proc/sys/, /sys/, /proc/acpi, /proc/fs, /proc/irq ๋“ฑ์— ๋Œ€ํ•œ ์ฝ๊ธฐ ์ „์šฉ ์•ก์„ธ์Šค์ž…๋‹ˆ๋‹ค.
  • ProtectKernelModules=yes - ์ปค๋„ ๋ชจ๋“ˆ ๋กœ๋“œ๋ฅผ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • ProtectKernelLogs=yes - ์ปค๋„ ๋กœ๊ทธ๊ฐ€ ์žˆ๋Š” ๋ฒ„ํผ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค๋ฅผ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • ProtectControlGroups=yes - /sys/fs/cgroup/์— ๋Œ€ํ•œ ์ฝ๊ธฐ ์ „์šฉ ์•ก์„ธ์Šค
  • NoNewPrivileges=yes - setuid, setgid ๋ฐ ๊ธฐ๋Šฅ ํ”Œ๋ž˜๊ทธ๋ฅผ ํ†ตํ•œ ๊ถŒํ•œ ์ƒ์Šน์„ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • PrivateNetwork=yes - ๋„คํŠธ์›Œํฌ ์Šคํƒ์˜ ๋ณ„๋„ ๋„ค์ž„์ŠคํŽ˜์ด์Šค์— ๋ฐฐ์น˜๋ฉ๋‹ˆ๋‹ค.
  • ProtectClock=yes - ์‹œ๊ฐ„ ๋ณ€๊ฒฝ์„ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • ProtectHostname=yes - ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ๋ณ€๊ฒฝ์„ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • ProtectProc=invisible - /proc์— ๋‹ค๋ฅธ ์‚ฌ๋žŒ์˜ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ˆจ๊น๋‹ˆ๋‹ค.
  • ์‚ฌ์šฉ์ž= - ์‚ฌ์šฉ์ž ๋ณ€๊ฒฝ

๋˜ํ•œ ๋‹ค์Œ ์„ค์ •์„ ํ™œ์„ฑํ™”ํ•˜๋Š” ๊ฒƒ์„ ๊ณ ๋ คํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • CapabilityBoundingSet=
  • DevicePolicy=๋‹ซํž˜
  • ํ‚ค๋ง๋ชจ๋“œ=๋น„๊ณต๊ฐœ
  • LockPersonality=์˜ˆ
  • MemoryDenyWriteExecute=์˜ˆ
  • ๊ฐœ์ธ์‚ฌ์šฉ์ž=์˜ˆ
  • ์ œ๊ฑฐIPC=์˜ˆ
  • RestrictAddressFamilies=
  • RestrictNamespaces=์˜ˆ
  • RestrictRealtime=์˜ˆ
  • RestrictSUIDSGID=์˜ˆ
  • ์‹œ์Šคํ…œ์ฝœํ•„ํ„ฐ=
  • SystemCallArchitectures=๋„ค์ดํ‹ฐ๋ธŒ

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€