0000002
Summary0000002: Harden Security of Default Configuration
DescriptionThe default configuration used to deploy Debian is based on conventions from 2012; nothing much has changed since then aside from slimming it down.

There are numerous security issues with this now, and this ticket is designed to track all of them so that they can be resolved in the next major release of SE.

Comment is invited.
Additional InformationThis bug may link to other bugs.
2024-04-20 19:24

administrator   ~0000006

All eCryptfs configurations are now considered obsolete and will be in-field replaced with fscrypt. An automated migration is not currently possible, so this will involve manual effort on each affected system.


2024-12-09 12:21

administrator   ~0000026

All of the required changes have been made to SE2025; and it is now using all upstream security configuration.

