mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-13 12:32:59 +02:00
suricata: Enable landlock security feature
This will limit the suricata process to only read and write to a certain files/directories. Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org> Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
This commit is contained in:
committed by
Michael Tremer
parent
4d24d99461
commit
64e057aaa5
@@ -768,16 +768,16 @@ security:
|
||||
limit-noproc: true
|
||||
# Use landlock security module under Linux
|
||||
landlock:
|
||||
enabled: no
|
||||
enabled: yes
|
||||
directories:
|
||||
#write:
|
||||
# - @e_rundir@
|
||||
write:
|
||||
- /run
|
||||
# /usr and /etc folders are added to read list to allow
|
||||
# file magic to be used.
|
||||
read:
|
||||
- /usr/
|
||||
- /etc/
|
||||
- @e_sysconfdir@
|
||||
- /usr/share/misc/magic.mgc
|
||||
- /var/ipfire/suricata/
|
||||
- /var/lib/suricata/rules/
|
||||
|
||||
lua:
|
||||
# Allow Lua rules. Disabled by default.
|
||||
|
||||
Reference in New Issue
Block a user