]> code.ossystems Code Review - openembedded-core.git/commit
rng-tools: Restrict rngd.service
authorAlex Kiernan <alex.kiernan@gmail.com>
Thu, 23 Apr 2020 14:12:06 +0000 (15:12 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sun, 26 Apr 2020 12:58:45 +0000 (13:58 +0100)
commit3ed70b755d0b60e61e0871f8b0cca2e2ab5e13f9
treefa9997a58ec14007c03144629da8e1787be7acf2
parenteeb1e236dab087b7565dbbf6979e2b4c03e56e91
rng-tools: Restrict rngd.service

Whilst rngd has to run as root, we can significantly constrain its
permissions (network is only required if nistbeacon is enabled).

Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-support/rng-tools/rng-tools/rngd.service
meta/recipes-support/rng-tools/rng-tools_6.9.bb