splash=silent preempt=full mitigations=auto quiet security=apparmor
auto
auto
false
true
true
gfxterm
8
true
grub2-efi
public
true
off
true
Unsolicited incoming network packets are rejected. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed.
false
block
Block
%%REJECT%%
For computers in your demilitarized zone that are publicly-accessible with limited access to your internal network. Only selected incoming connections are accepted.
false
dmz
ssh
DMZ
default
All network connections are accepted.
docker0
false
docker
docker
ACCEPT
Unsolicited incoming network packets are dropped. Incoming packets that are related to outgoing network connections are accepted. Outgoing network connections are allowed.
false
drop
Drop
DROP
For use on external networks. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
true
external
ssh
External
default
For use in home areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
false
home
dhcpv6-client
mdns
samba-client
ssh
Home
default
For use on internal networks. You mostly trust the other computers on the networks to not harm your computer. Only selected incoming connections are accepted.
false
internal
dhcpv6-client
mdns
samba-client
ssh
Internal
default
For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
eth0
false
public
dhcpv6-client
ssh
Public
default
All network connections are accepted.
false
trusted
Trusted
ACCEPT
For use in work areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.
false
work
dhcpv6-client
ssh
Work
default
false
100
users
499
messagebus
1
bin
daemon
488
input
495
kmem
493
utmp
62
man
477
polkitd
479
systemd-timesync
2
daemon
480
systemd-network
71
ntadmin
490
dialout
59
maildrop
postfix
478
nscd
51
postfix
485
tape
487
render
476
sshd
491
cdrom
486
sgx
0
root
489
disk
15
shadow
484
video
496
wheel
483
audit
498
mail
postfix
5
tty
65533
nogroup
65534
nobody
497
lp
482
chrony
492
audio
494
lock
36
kvm
42
trusted
481
systemd-journal
127.0.0.1
localhost
::1
localhost ipv6-localhost ipv6-loopback
fe00::0
ipv6-localnet
ff00::0
ipv6-mcastprefix
ff02::1
ipv6-allnodes
ff02::2
ipv6-allrouters
ff02::3
ipv6-allhosts
en_GB
en_GB
AUTO
true
localhost
auto
dhcp
eth0
auto
public
true
true
false
false
false
auto
systemd
/dev/vda
gpt
false
true
vfat
true
utf8
/boot/efi
uuid
259
1
false
134217728
true
true
btrfs
true
/
uuid
131
2
false
false
6307167744
false
var
true
usr/local
true
tmp
true
srv
true
root
true
opt
true
home
true
boot/grub2/arm64-efi
@
CT_DISK
false
multi-user
YaST2-Firstboot
YaST2-Second-Stage
apparmor
auditd
klog
chronyd
cron
cups
firewalld
wickedd-auto4
wickedd-dhcp4
wickedd-dhcp6
wickedd-nanny
irqbalance
issue-generator
kbdsettings
wicked
nscd
postfix
purge-kernels
rsyslog
smartd
sshd
systemd-pstore
systemd-remount-fs
true
wicked
shim
os-prober
openssh
openSUSE-release
mokutil
kexec-tools
grub2-arm64-efi
glibc
firewalld
e2fsprogs
dosfstools
chrony
btrfsprogs
autoyast2
apparmor
base
documentation
enhanced_base
minimal_base
sw_management
yast2_basis
Leap
false
false
100
/home
-1
/bin/bash
022
true
user
100
/home/user
false
99999
0
7
/bin/bash
1000
$6$WV8CB/c6j0zhAi5S$4euhbt4alH7WNfaatS9IJgPiiKDJ48d5Ru1zCZCA0N9GiyOPuefN2PAUWlyYeTgqAInpyvPh1frdp4fFVjvEn0
user
true
User for nscd
478
/run/nscd
false
/sbin/nologin
478
!
nscd
true
systemd Network Management
480
/
false
/usr/sbin/nologin
480
!*
systemd-network
true
Daemon
2
/sbin
false
/usr/sbin/nologin
2
!
daemon
true
systemd Time Synchronization
479
/
false
/usr/sbin/nologin
479
!*
systemd-timesync
true
user for rpcbind
65534
/var/lib/empty
false
/sbin/nologin
475
!
rpc
true
SSH daemon
476
/var/lib/sshd
false
/usr/sbin/nologin
476
!
sshd
true
Postfix Daemon
51
/var/spool/postfix
false
/usr/sbin/nologin
51
!
postfix
true
NFS statd daemon
65533
/var/lib/nfs
false
/sbin/nologin
474
!
statd
true
bin
1
/bin
false
/usr/sbin/nologin
1
!
bin
true
root
0
/root
false
/bin/bash
0
$6$zAe5W7gw/kja9aKy$mM.BWtNyjalXrDNig4CUfN3bgfmehUIs8.zvBwWn1XroK104G.rY3lyup3OH8TujieUmgO4J74Df.LktV4A1K1
root
true
User for D-Bus
499
/run/dbus
false
/usr/bin/false
499
!
messagebus
true
Manual pages viewer
62
/var/lib/empty
false
/usr/sbin/nologin
13
!
man
true
Printing daemon
497
/var/spool/lpd
false
/usr/sbin/nologin
497
!
lp
true
User for polkitd
477
/var/lib/polkit
false
/usr/sbin/nologin
477
!
polkitd
true
Chrony Daemon
482
/var/lib/chrony
false
/usr/sbin/nologin
496
!
chrony
true
nobody
65534
/var/lib/nobody
false
/bin/bash
65534
!
nobody
true
Mailer daemon
498
/var/spool/clientmqueue
false
/usr/sbin/nologin
498
!
mail