data: Add additional fprintd lockdown

This commit is contained in:
Bastien Nocera
2020-10-02 14:17:38 +02:00
committed by Benjamin Berg
parent 6dc699ae6f
commit 2fd86624e5

View File

@ -15,6 +15,8 @@ ProtectControlGroups=true
StateDirectory=fprint
ProtectHome=true
PrivateTmp=true
ProtectKernelLogs=yes
SystemCallFilter=@system-service
# Network
PrivateNetwork=true
@ -31,3 +33,8 @@ RestrictRealtime=true
# Privilege escalation
NoNewPrivileges=true
TasksMax=1
# Capabilities
CapabilityBoundingSet=
ProtectClock=yes