mirror of
https://git.proxmox.com/git/mirror_lxc
synced 2025-07-27 09:48:32 +00:00
Update gentoo.moresecure.conf.
Closes https://github.com/lxc/lxc/issues/1928 Signed-off-by: i.Dark_Templar <darktemplar@dark-templar-archives.net>
This commit is contained in:
parent
33349a049f
commit
23002e923e
@ -30,7 +30,8 @@ lxc.mount.entry=run run tmpfs rw,nosuid,nodev,relatime,mode=755 0 0
|
|||||||
# lxc.cap.drop = audit_write
|
# lxc.cap.drop = audit_write
|
||||||
# lxc.cap.drop = setpcap # breaks journald
|
# lxc.cap.drop = setpcap # breaks journald
|
||||||
# lxc.cap.drop = sys_resource # breaks systemd
|
# lxc.cap.drop = sys_resource # breaks systemd
|
||||||
lxc.cap.drop = audit_control audit_write dac_read_search fsetid ipc_owner linux_immutable mknod setfcap setpcap sys_admin sys_boot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_tty_config syslog
|
# lxc.cap.drop = sys_boot # breaks sysvinit
|
||||||
|
lxc.cap.drop = audit_control audit_write dac_read_search fsetid ipc_owner linux_immutable mknod setfcap setpcap sys_admin sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_tty_config syslog
|
||||||
|
|
||||||
# WARNING: the security vulnerability reported for 'cap_net_admin' at
|
# WARNING: the security vulnerability reported for 'cap_net_admin' at
|
||||||
# http://mainisusuallyafunction.blogspot.com/2012/11/attacking-hardened-linux-systems-with.html
|
# http://mainisusuallyafunction.blogspot.com/2012/11/attacking-hardened-linux-systems-with.html
|
||||||
|
Loading…
Reference in New Issue
Block a user