Req #72510 [Opn->Csd]: systemd service should be hardened

From: Date: Wed, 12 Dec 2018 16:14:23 +0000
Subject: Req #72510 [Opn->Csd]: systemd service should be hardened
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218424@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72510&edit=1 ID: 72510 Updated by: cmb@php.net Reported by: candrews at integralblue dot com Summary: systemd service should be hardened -Status: Open +Status: Closed Type: Feature/Change Request Package: FPM related Operating System: Linux PHP Version: Irrelevant -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: This feature request has been implemented as commit 40c4d7f[1]. [1] <http://git.php.net/?p=php-src.git;a=commit;h=40c4d7f1820df1872a71ab07fd26da45a203e37f> Previous Comments: ------------------------------------------------------------------------ [2016-06-28 20:05:12] candrews at integralblue dot com Description: ------------ The php-fpm systemd service, php-fpm.service, should use be hardened as much as possible against potential attacks. Besides reducing the likelihood of an attack, if php does get compromised, there will be less damage possible. I suggest these features be added to the systemd units: --------------- ProtectHome=true PrivateTmp=true ProtectSystem=full NoNewPrivileges=true PrivateDevices=true # Required for dropping privileges and running as a different user CapabilityBoundingSet=CAP_SETGID CAP_SETUID --------------- I tested these settings and didn't experience any problems in my (admitted limited) setup. I think they should be fine for anyone except for exceptional and odd situations (ex, php-fpm is setup to read files from /tmp that another services writes to /tmp). For the (very rare) impacted user, they can always override the systemd service - but a secure configuration should be the default. Test script: --------------- n/a Expected result: ---------------- n/a Actual result: -------------- n/a ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72510&edit=1

« previous php.bugs (#218424) next »