diff options
| author | Tom Fitzhenry <tom@tom-fitzhenry.me.uk> | 2023-09-15 15:06:20 +1000 |
|---|---|---|
| committer | Tom Fitzhenry <tom@tom-fitzhenry.me.uk> | 2023-09-16 06:37:00 +1000 |
| commit | dd1b3b077af7250742b710d53f983e271bff0b5b (patch) | |
| tree | 2d6d920937fbcb2e9d3ff090d511d07588e1b2d0 /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch | |
| parent | 4b790413b4cb67615f2efcdde5066d9c57138369 (diff) | |
nixos/postfix: add systemd hardening directives
Inspired by
https://github.com/gentoo/gentoo/blob/a9ccc48242da316f37b8e6ddf99bae660fadef48/mail-mta/postfix/files/postfix.service
This decreases the systemd-analyze exposure level from UNSAFE to MEDIUM:
```
$ systemd-analyze security --offline=true postfix-hardened.service | grep Overall
→ Overall exposure level for postfix-hardened.service: 6.2 MEDIUM 😐
$ systemd-analyze security --offline=true postfix-original.service | grep Overall
→ Overall exposure level for postfix-original.service: 9.6 UNSAFE 😨
```
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions
