Here's some additional Apparmor config bits to tighten down Mastodon: https://codeberg.org/wtfismyip/mastodon-hardening
#apparmor #infosec #hardening
Andreas Schulz
@AndreasSchulz@freiburg.social
Software Engineer. macOS, Linux, ARM. Villingen-Schwenningen, DE
freiburg.social
Nur 2 von 100 #Linux-Distributionen sind tatsächlich sicher vorkonfiguriert: #Fedora und #openSUSE. In diesem Video (Englisch) wird es genauer erklärt.
https://redirect.invidious.io/watch?v=dt-YepVq9Es
#security #sicherheit #selinux #AppArmor
Neuer Tip im Blog :
Letztens haben wir den pod komplett automatisiert - als Service, mit auto-update. läuft. Nur auf Alma / Rocky / etc grätscht beim bind-mount dann SELinux dazwischen.
Der neue Quick-Tipp: bind-mount oder named volume, wie man das Label sauber setzt (chcon/semanage) - und warum das auf Debian mit AppArmor kein Thema ist.
https://just-stuff.blog/podman-bind-mount-selinux/
#Podman #SELinux #AppArmor #Debian #Linux #AlmaLinux #Blog
Neuer Artikel im Blog. :)
NTFS-ACL , SELinux und AppArmor: ACLs, SIDs und MIC auf Windows, Type Enforcement und Profile auf Linux – technischer Vergleich der Sicherheitsmodelle beider Betriebssysteme
https://just-stuff.blog/ntfs-srm-vs-selinux-apparmor-wer-darf-was-und-warum/
#acl #selinux #apparmor #security #blog #windows #linux
guix works fine…until I guix pull #packagemanagement #2404 #apparmor
https://askubuntu.com/q/1565715/612
Apparmor passt and pasta profiles #mount #docker #apparmor #libvirt
https://askubuntu.com/q/1564086/612
You've seen all posts