我对这些结果感到困惑。我该如何解决这些警报?这对于带有 Ubuntu 的家用计算机是否正常?谢谢。
me@ubuntu:~$ systemd-analyze security
UNIT EXPOSURE PREDICATE HAPPY
ModemManager.service 5.6 MEDIUM ?
NetworkManager.service 7.7 EXPOSED ?
accounts-daemon.service 9.6 UNSAFE ?
acpid.service 9.6 UNSAFE ?
alsa-state.service 9.6 UNSAFE ?
anacron.service 9.6 UNSAFE ?
apport.service 9.6 UNSAFE ?
avahi-daemon.service 9.6 UNSAFE ?
bolt.service 5.1 MEDIUM ?
colord.service 8.8 EXPOSED ?
cron.service 9.6 UNSAFE ?
cups-browsed.service 9.6 UNSAFE ?
cups.service 9.6 UNSAFE ?
dbus.service 9.6 UNSAFE ?
dmesg.service 9.6 UNSAFE ?
emergency.service 9.5 UNSAFE ?
gdm.service 9.7 UNSAFE ?
[email protected] 9.6 UNSAFE ?
glances.service 9.6 UNSAFE ?
grub-common.service 9.6 UNSAFE ?
hddtemp.service 9.6 UNSAFE ?
irqbalance.service 6.0 MEDIUM ?
kerneloops.service 9.1 UNSAFE ?
networkd-dispatcher.service 9.6 UNSAFE ?
nvidia-persistenced.service 9.6 UNSAFE ?
ondemand.service 9.6 UNSAFE ?
packagekit.service 9.6 UNSAFE ?
plymouth-start.service 9.5 UNSAFE ?
polkit.service 9.6 UNSAFE ?
rc-local.service 9.6 UNSAFE ?
rescue.service 9.5 UNSAFE ?
rsync.service 9.6 UNSAFE ?
rsyslog.service 9.6 UNSAFE ?
rtkit-daemon.service 7.0 MEDIUM ?
snapd.service 9.6 UNSAFE ?
spice-vdagentd.service 9.2 UNSAFE ?
strongswan.service 9.6 UNSAFE ?
switcheroo-control.service 9.6 UNSAFE ?
systemd-ask-password-console.service 9.3 UNSAFE ?
systemd-ask-password-plymouth.service 9.5 UNSAFE ?
systemd-ask-password-wall.service 9.4 UNSAFE ?
systemd-fsckd.service 9.5 UNSAFE ?
systemd-initctl.service 9.3 UNSAFE ?
systemd-journald.service 4.2 OK ?
systemd-logind.service 2.8 OK ?
systemd-networkd.service 2.8 OK ?
systemd-resolved.service 2.1 OK ?
systemd-rfkill.service 9.3 UNSAFE ?
systemd-timesyncd.service 2.0 OK ?
systemd-udevd.service 8.1 EXPOSED ?
thermald.service 9.6 UNSAFE ?
udisks2.service 9.6 UNSAFE ?
unattended-upgrades.service 9.6 UNSAFE ?
upower.service 2.0 OK ?
[email protected] 9.3 UNSAFE ?
[email protected] 9.3 UNSAFE ?
uuidd.service 4.3 OK ?
vboxweb.service 9.6 UNSAFE ?
virtualbox-guest-utils.service 9.6 UNSAFE ?
virtualbox.service 9.6 UNSAFE ?
whoopsie.service 9.6 UNSAFE ?
wpa_supplicant.service 9.6 UNSAFE ?
systemd-analyze security
查看 systemd 中内置的沙盒功能。它不检查服务本身。所以忽略这些是安全的,但如果你确实想解决这些问题,请参阅freedesktop systemd了解沙盒选项的方法:您可以设置一长串选项来强制该单元遵守更严格的政策,每个选项都对其功能进行了冗长的解释。
一些: