Merge pull request #61032 from dtzWill/feature/rngd-harden
rngd: harden service config, settings from arch
This commit is contained in:
commit
e8d7f17c81
|
@ -42,6 +42,11 @@ in
|
|||
serviceConfig = {
|
||||
ExecStart = "${pkgs.rng-tools}/sbin/rngd -f"
|
||||
+ optionalString cfg.debug " -d";
|
||||
NoNewPrivileges = true;
|
||||
PrivateNetwork = true;
|
||||
PrivateTmp = true;
|
||||
ProtectSystem = "full";
|
||||
ProtectHome = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
|
Loading…
Reference in New Issue