Fixed systemd capabilities for alfis user.
This commit is contained in:
@@ -8,10 +8,15 @@ After=alfis-default-config.service
|
|||||||
[Service]
|
[Service]
|
||||||
User=alfis
|
User=alfis
|
||||||
Group=alfis
|
Group=alfis
|
||||||
|
|
||||||
ProtectHome=true
|
ProtectHome=true
|
||||||
ProtectSystem=true
|
ProtectSystem=true
|
||||||
|
|
||||||
|
SecureBits=keep-caps
|
||||||
|
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
|
||||||
|
AmbientCapabilities=CAP_NET_BIND_SERVICE
|
||||||
|
|
||||||
SyslogIdentifier=alfis
|
SyslogIdentifier=alfis
|
||||||
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
|
||||||
WorkingDirectory=/var/lib/alfis
|
WorkingDirectory=/var/lib/alfis
|
||||||
ExecStart=/usr/bin/alfis -n -c /etc/alfis.conf
|
ExecStart=/usr/bin/alfis -n -c /etc/alfis.conf
|
||||||
ExecReload=/bin/kill -HUP $MAINPID
|
ExecReload=/bin/kill -HUP $MAINPID
|
||||||
|
|||||||
Reference in New Issue
Block a user