From cb176565030d229b8905a8873b0bf28b98d78914 Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Sun, 24 Feb 2019 20:40:30 +0000 Subject: Harden arch-audit.profile (#2450) --- etc/arch-audit.profile | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/etc/arch-audit.profile b/etc/arch-audit.profile index 7321f4e90..e28733c63 100644 --- a/etc/arch-audit.profile +++ b/etc/arch-audit.profile @@ -17,10 +17,13 @@ include disable-passwdmgr.inc include disable-programs.inc include disable-xdg.inc +apparmor caps.drop all ipc-namespace +machine-id netfilter no3d +nodbus nodvd nogroups nonewprivs @@ -29,14 +32,14 @@ nosound notv nou2f novideo -protocol unix,inet,inet6 +protocol inet,inet6 seccomp shell none disable-mnt private -private-cache private-bin arch-audit +private-cache private-dev private-tmp -- cgit v1.2.3-70-g09d2