{"guid":"f4820009-ff1d-5c91-8d21-dc0c175afac9","title":"A Security Model for systemd","subtitle":null,"slug":"all-systems-go-2025-354-a-security-model-for-systemd","link":"https://cfp.all-systems-go.io/all-systems-go-2025/talk/FE98ZY/","description":"Linux lacks a coherent security model, and by extension we never defined one for the systemd project either.\n\nIn this talk I'd like to start changing this, and begin defining some general security design guidelines that we so far mostly followed implicitly, and make them more explicit. After all, systemd to a large degree is involved in security subsystems, from SecureBoot, Measured Boot \u0026 TPM, to its service sandboxing, dm-verity/dm-crypt support, its FIDO2/PKCS#11 hookups, its many security boundaries, secure parameterization, Linux Security Module initialization and more.\n\nWhile this distributions \u0026 applications consuming systemd might follow different security models I think it's important to talk about a unified vision from the systemd upstream perspective, even if various downstreams then make modifications or only deploy a subset of it.\n\nLicensed to the public under https://creativecommons.org/licenses/by/4.0/de/","original_language":"eng","persons":["Lennart Poettering"],"tags":["354","2025","asg2025","Loft","asg2025-eng","asg2025","Day 1"],"view_count":1527,"promoted":false,"date":"2025-09-30T09:30:00.000+02:00","release_date":"2025-09-30T00:00:00.000+02:00","updated_at":"2026-04-03T15:15:03.537+02:00","length":2431,"duration":2431,"thumb_url":"https://static.media.ccc.de/media/events/all_systems_go/2025/354-f4820009-ff1d-5c91-8d21-dc0c175afac9.jpg","poster_url":"https://static.media.ccc.de/media/events/all_systems_go/2025/354-f4820009-ff1d-5c91-8d21-dc0c175afac9_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/all_systems_go/2025/354-f4820009-ff1d-5c91-8d21-dc0c175afac9.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/all_systems_go/2025/354-f4820009-ff1d-5c91-8d21-dc0c175afac9.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/all-systems-go-2025-354-a-security-model-for-systemd","url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_title":"All Systems Go! 2025","conference_url":"https://api.media.ccc.de/public/conferences/asg2025","related":[],"recordings":[{"size":198,"length":2431,"mime_type":"video/webm;codecs=av01","language":"eng","filename":"asg2025-354-eng-A_Security_Model_for_systemd_av1-hd.webm","state":"new","folder":"av1-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-09-30T14:10:50.163+02:00","recording_url":"https://cdn.media.ccc.de/events/all_systems_go/2025/av1-hd/asg2025-354-eng-A_Security_Model_for_systemd_av1-hd.webm","url":"https://api.media.ccc.de/public/recordings/91706","event_url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_url":"https://api.media.ccc.de/public/conferences/asg2025"},{"size":37,"length":2431,"mime_type":"audio/mpeg","language":"eng","filename":"asg2025-354-eng-A_Security_Model_for_systemd_mp3.mp3","state":"new","folder":"mp3","high_quality":false,"width":0,"height":0,"updated_at":"2025-09-30T13:58:00.381+02:00","recording_url":"https://cdn.media.ccc.de/events/all_systems_go/2025/mp3/asg2025-354-eng-A_Security_Model_for_systemd_mp3.mp3","url":"https://api.media.ccc.de/public/recordings/91700","event_url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_url":"https://api.media.ccc.de/public/conferences/asg2025"},{"size":26,"length":2431,"mime_type":"audio/opus","language":"eng","filename":"asg2025-354-eng-A_Security_Model_for_systemd_opus.opus","state":"new","folder":"opus","high_quality":false,"width":0,"height":0,"updated_at":"2025-09-30T13:44:47.220+02:00","recording_url":"https://cdn.media.ccc.de/events/all_systems_go/2025/opus/asg2025-354-eng-A_Security_Model_for_systemd_opus.opus","url":"https://api.media.ccc.de/public/recordings/91699","event_url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_url":"https://api.media.ccc.de/public/conferences/asg2025"},{"size":267,"length":2431,"mime_type":"video/webm","language":"eng","filename":"asg2025-354-eng-A_Security_Model_for_systemd_webm-hd.webm","state":"new","folder":"webm-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-09-30T14:17:29.170+02:00","recording_url":"https://cdn.media.ccc.de/events/all_systems_go/2025/webm-hd/asg2025-354-eng-A_Security_Model_for_systemd_webm-hd.webm","url":"https://api.media.ccc.de/public/recordings/91708","event_url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_url":"https://api.media.ccc.de/public/conferences/asg2025"},{"size":103,"length":2431,"mime_type":"video/webm","language":"eng","filename":"asg2025-354-eng-A_Security_Model_for_systemd_webm-sd.webm","state":"new","folder":"webm-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-09-30T14:09:08.894+02:00","recording_url":"https://cdn.media.ccc.de/events/all_systems_go/2025/webm-sd/asg2025-354-eng-A_Security_Model_for_systemd_webm-sd.webm","url":"https://api.media.ccc.de/public/recordings/91705","event_url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_url":"https://api.media.ccc.de/public/conferences/asg2025"},{"size":83,"length":2431,"mime_type":"video/mp4","language":"eng","filename":"asg2025-354-eng-A_Security_Model_for_systemd_sd.mp4","state":"new","folder":"h264-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-09-30T13:42:18.757+02:00","recording_url":"https://cdn.media.ccc.de/events/all_systems_go/2025/h264-sd/asg2025-354-eng-A_Security_Model_for_systemd_sd.mp4","url":"https://api.media.ccc.de/public/recordings/91698","event_url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_url":"https://api.media.ccc.de/public/conferences/asg2025"},{"size":211,"length":2431,"mime_type":"video/mp4","language":"eng","filename":"asg2025-354-eng-A_Security_Model_for_systemd_hd.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-09-30T13:38:59.977+02:00","recording_url":"https://cdn.media.ccc.de/events/all_systems_go/2025/h264-hd/asg2025-354-eng-A_Security_Model_for_systemd_hd.mp4","url":"https://api.media.ccc.de/public/recordings/91697","event_url":"https://api.media.ccc.de/public/events/f4820009-ff1d-5c91-8d21-dc0c175afac9","conference_url":"https://api.media.ccc.de/public/conferences/asg2025"}]}