Req #72510 [Opn->Csd]: systemd service should be hardened
| From: | cmb@php.net | Date: | Wed, 12 Dec 2018 16:14:23 +0000 |
| Subject: | Req #72510 [Opn->Csd]: systemd service should be hardened | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218424@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72510&edit=1
ID: 72510
Updated by: cmb@php.net
Reported by: candrews at integralblue dot com
Summary: systemd service should be hardened
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: FPM related
Operating System: Linux
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This feature request has been implemented as commit 40c4d7f[1].
[1] <http://git.php.net/?p=php-src.git;a=commit;h=40c4d7f1820df1872a71ab07fd26da45a203e37f>
Previous Comments:
------------------------------------------------------------------------
[2016-06-28 20:05:12] candrews at integralblue dot com
Description:
------------
The php-fpm systemd service, php-fpm.service, should use be hardened as much as possible against
potential attacks. Besides reducing the likelihood of an attack, if php does get compromised, there
will be less damage possible.
I suggest these features be added to the systemd units:
---------------
ProtectHome=true
PrivateTmp=true
ProtectSystem=full
NoNewPrivileges=true
PrivateDevices=true
# Required for dropping privileges and running as a different user
CapabilityBoundingSet=CAP_SETGID CAP_SETUID
---------------
I tested these settings and didn't experience any problems in my (admitted limited) setup. I
think they should be fine for anyone except for exceptional and odd situations (ex, php-fpm is setup
to read files from /tmp that another services writes to /tmp). For the (very rare) impacted user,
they can always override the systemd service - but a secure configuration should be the default.
Test script:
---------------
n/a
Expected result:
----------------
n/a
Actual result:
--------------
n/a
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72510&edit=1