This commit is contained in:
Patrick Schleizer 2024-01-16 09:26:21 -05:00
parent 3ba8fe586e
commit 0d78ecaee3
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -436,8 +436,8 @@ include but are not limited to:
##### permission-hardener #####
`permission-hardener` removes SUID / SGID bits from non-essential binaries as
these are often used in privilege escalation attacks. It runs at package
installation and upgrade time.
these are often used in privilege escalation attacks. It is enabled by default
and applied at security-misc package installation and upgrade time.
There is also an optional systemd unit which does the same at boot time that
can be enabled by running `systemctl enable permission-hardener.service` as