浏览代码

openvpn: Define service capabilities explicitly.

Signed-off-by: Maximilian Wilhelm <max@sdn.clinic>
Maximilian Wilhelm 4 年之前
父节点
当前提交
132339057a
共有 1 个文件被更改,包括 1 次插入0 次删除
  1. 1 0
      openvpn/openvpn@.service

+ 1 - 0
openvpn/openvpn@.service

@@ -3,6 +3,7 @@ Description=OpenVPN connection to %i
 PartOf=openvpn.service
 ReloadPropagatedFrom=openvpn.service
 After=network.target
+CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE CAP_AUDIT_WRITE
 
 [Service]
 Type=forking