Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
home:bmwiedemann:reproducible:distribution:ring0
audit
fix-hardened-service.patch
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File fix-hardened-service.patch of Package audit
From: Enzo Matsumiya <ematsumiya@suse.de> Subject: init.d/auditd.service: make /etc/audit writable References: bsc#1181400 systemd hardening effort (bsc#1181400) broke auditd.service when starting/ restarting it. This was because auditd couldn't save/create audit.rules from /etc/audit/rules.d/* files. Make /etc/audit writable for the service. Also remove PrivateDevices=true so /dev/* are exposed to auditd. Signed-off-by: Enzo Matsumiya <ematsumiya@suse.de> Index: audit-3.1.1/init.d/auditd.service =================================================================== --- audit-3.1.1.orig/init.d/auditd.service +++ audit-3.1.1/init.d/auditd.service @@ -42,12 +42,12 @@ RestrictRealtime=true # added automatically, for details please see # https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort ProtectSystem=full -PrivateDevices=true ProtectHostname=true ProtectClock=true ProtectKernelTunables=true ProtectKernelLogs=true # end of automatic additions +ReadWritePaths=/etc/audit [Install] WantedBy=multi-user.target
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor