Skip to content

Harden nsncd.service #156

@KenMacD

Description

@KenMacD

Where the authors are probably most familiar with what access is required, it would be nice if the nsncd.service file was updated with a good and secure default hardening setup.

When the service is running on NixOS there is some hardening applied, but the service still gets a rating of 8.2 EXPOSED 🙁 in systemd-analyze security nscd.service. The existing hardening is available here (here's another users config), and is obviously not very strict.

There is an issue in the Nix repo focused on hardening system services. While hopefully someone will pick up nsncd it would probably be better if the info was available here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions