adrelanos / vpn-firewall

Leak Protection (Fail Safe Mechanism) for (Open)VPN
https://www.whonix.org/wiki/Impressum
Other
169 stars 46 forks source link

Hardening systemd service #31

Closed ghost closed 6 years ago

ghost commented 6 years ago

This PR hardens existing openvpn service. It basically mounts whole filesystem read-only or inaccessible except few relevant directories. It allows for CAP_NET_ADMIN capability which gives openvpn daemon ability to run properly. All options are explained in https://manpages.debian.org/stretch/systemd/systemd.exec.5.en.html