Add SystemCallFilter=@system-service

This commit is contained in:
Carl Tashian 2021-01-28 09:45:20 -08:00
parent 2af73881d7
commit 9fd0964e1c

View file

@ -30,6 +30,7 @@ SecureBits=keep-caps
NoNewPrivileges=yes
; Sandboxing
; This works with YubiKey PIV (via pcscd), and presumably with YubiHSM2 via http connector
ProtectSystem=full
ProtectHome=true
RestrictNamespaces=true
@ -44,8 +45,8 @@ LockPersonality=true
RestrictSUIDSGID=true
RemoveIPC=true
RestrictRealtime=true
; confirmed this works, even with YubiKey PIV, and presumably with YubiHSM2:
PrivateDevices=true
SystemCallFilter=@system-service
MemoryDenyWriteExecute=true
ReadWriteDirectories=/etc/step-ca/db