1
0

tex: add stuff on security policies

This commit is contained in:
leo 2023-05-25 17:05:05 +02:00
parent 23c57658a5
commit 8b3b3be4e4
Signed by: wanderer
SSH Key Fingerprint: SHA256:Dp8+iwKHSlrMEHzE3bJnPng70I7LEsa3IJXRH/U+idQ

@ -1445,6 +1445,11 @@ therefore only be available over \texttt{localhost}.
It goes without saying that the operator should substitute values of any
default configuration secrets with the new ones that were securely generated.
System-wide security policies should target highest feasible security level, if
at all available (such as by default on Fedora or RHEL), firewalls should be
configured and SELinux (kernel-level mandatory access control and security
policy mechanism) running in \emph{enforcing} mode, if available.
\n{2}{Deployment recommendations}