Your message dated Wed, 14 Oct 2020 02:35:21 +0200
with message-id <[email protected]>
and subject line Re: Bug#972186: systemd-analyze
has caused the Debian Bug report #972186,
regarding systemd-analyze
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
972186: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=972186
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: systemd
Version: 241-7~deb10u4
Tags: security, buster, bullseye
Severity: wishlist
Dear Maintainers,
Among others, /usr/bin/systemd-analyze can be called with "security" parameter
which shows sandboxing settings of the loaded units on the scale from 0 to 10.
On Debian v10.6 vast majority of the services are reported as "unsafe" with
exposure score >9. This includes sshd, unattended-upgrades and others.
Is there a plan to improve situation for Bullseye? I think maintainers of
Whonix project, which is based on Debian, are using it for some services they
ship in addition to base (sdwdate, onion-grater, etc).
References:
[1] https://forums.whonix.org/t/systemd-analyze-security/10395
[2] https://www.ctrl.blog/entry/systemd-opensmtpd-hardening.html
[3]
https://forums.whonix.org/t/system-wide-sandboxing-framework-sandbox-app-launcher/9008
--
With regards,
A
--- End Message ---
--- Begin Message ---
Thanks for your interest here, but this is not an actionable bug in the
systemd package, so closing.
Regards,
Michael
signature.asc
Description: OpenPGP digital signature
--- End Message ---