-
Notifications
You must be signed in to change notification settings - Fork 17
Open
Description
Where the authors are probably most familiar with what access is required, it would be nice if the nsncd.service file was updated with a good and secure default hardening setup.
When the service is running on NixOS there is some hardening applied, but the service still gets a rating of 8.2 EXPOSED 🙁 in systemd-analyze security nscd.service. The existing hardening is available here (here's another users config), and is obviously not very strict.
There is an issue in the Nix repo focused on hardening system services. While hopefully someone will pick up nsncd it would probably be better if the info was available here.
Metadata
Metadata
Assignees
Labels
No labels