Skip to content

leverage systemd hardening options for omid #698

@juju4

Description

@juju4

This change (juju4@8621f1f) adds security hardening capabilities from systemd per https://www.freedesktop.org/software/systemd/man/systemd.exec.html

It brings down exposure level from 9.6 to 2.8 (systemd-analyze security omid) and would likely limit impact of vulnerability like recent one (https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure)

It requires more extensive testing as I only ensured that service is started and no error in /var/opt/omi/log/omiserver.log.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions