[Pkg-utopia-maintainers] Bug#941905: firewalld: Dont Allow Services/Open Ports on default Zone "public"

Kinky Nekoboi kinky_nekoboi at bluetardis.de
Mon Oct 7 14:37:55 BST 2019


Package: firewalld
Version: 0.6.3-5
Severity: wishlist

As default SSH and dhcpv6-client is allowed,
as in my unterstanding the default config on a "Desktop firewall" should allow
no incoming connections.

I guess to avoid locking one self out on headless installations (aka no SSH )
firewalld systemd service should be disabled by default on installation.

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
   * What exactly did you do (or not do) that was effective (or
     ineffective)?
   * What was the outcome of this action?
   * What outcome did you expect instead?

*** End of the template - remove these template lines ***



-- System Information:
Debian Release: 10.1
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-6-amd64 (SMP w/2 CPU cores)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), LANGUAGE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages firewalld depends on:
ii  dbus                 1.12.16-1
ii  gir1.2-glib-2.0      1.58.3-2
ii  init-system-helpers  1.56+nmu1
ii  iptables             1.8.2-4
ii  policykit-1          0.105-25
ii  python3              3.7.3-1
ii  python3-dbus         1.2.8-3
ii  python3-gi           3.30.4-1
ii  python3-slip-dbus    0.6.5-2

Versions of packages firewalld recommends:
ii  ipset  6.38-1.2

firewalld suggests no packages.

-- Configuration Files:
/etc/firewalld/firewalld.conf [Errno 13] Keine Berechtigung: '/etc/firewalld/firewalld.conf'
/etc/firewalld/lockdown-whitelist.xml [Errno 13] Keine Berechtigung: '/etc/firewalld/lockdown-whitelist.xml'

-- no debconf information



More information about the Pkg-utopia-maintainers mailing list