chiark / gitweb /
units: add SecureBits
[elogind.git] / units / systemd-hostnamed.service.in
index c8bf8480c9762520b286ef0452da4daa2a1eb2bd..259b451cbdf49405d75c74a14caee4bfad52d611 100644 (file)
@@ -13,7 +13,11 @@ Documentation=http://www.freedesktop.org/wiki/Software/systemd/hostnamed
 [Service]
 ExecStart=@rootlibexecdir@/systemd-hostnamed
 BusName=org.freedesktop.hostname1
-CapabilityBoundingSet=CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SYS_PTRACE
+CapabilityBoundingSet=CAP_SYS_ADMIN
+SecureBits=noroot noroot-locked
 WatchdogSec=1min
 PrivateTmp=yes
 PrivateDevices=yes
+PrivateNetwork=yes
+ProtectSystem=yes
+ProtectHome=yes