mirror of
https://github.com/yrutschle/sslh.git
synced 2025-04-13 07:37:15 +03:00
remove useless capabilities and use standard environment in systemd
This commit is contained in:
parent
a80d79fd40
commit
fee8491a8e
@ -3,12 +3,12 @@ Description=SSL/SSH multiplexer (select mode) for %I
|
|||||||
After=network.target
|
After=network.target
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
EnvironmentFile=/etc/conf.d/sslh
|
EnvironmentFile=/etc/default/sslh
|
||||||
ExecStart=/usr/sbin/sslh-select -F/etc/sslh/%I.cfg -f $DAEMON_OPTS
|
ExecStart=/usr/sbin/sslh-select -F/etc/sslh/%I.cfg -f $DAEMON_OPTS
|
||||||
KillMode=process
|
KillMode=process
|
||||||
#Hardening
|
#Hardening
|
||||||
PrivateTmp=true
|
PrivateTmp=true
|
||||||
CapabilityBoundingSet=CAP_SETGID CAP_SETUID CAP_NET_BIND_SERVICE
|
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
|
||||||
AmbientCapabilities=CAP_NET_BIND_SERVICE
|
AmbientCapabilities=CAP_NET_BIND_SERVICE
|
||||||
SecureBits=noroot-locked
|
SecureBits=noroot-locked
|
||||||
ProtectSystem=strict
|
ProtectSystem=strict
|
||||||
|
@ -3,7 +3,7 @@ Description=SSL/SSH multiplexer (fork mode) for %I
|
|||||||
After=network.target
|
After=network.target
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
EnvironmentFile=/etc/conf.d/sslh
|
EnvironmentFile=/etc/default/sslh
|
||||||
ExecStart=/usr/sbin/sslh -F/etc/sslh/%I.cfg -f $DAEMON_OPTS
|
ExecStart=/usr/sbin/sslh -F/etc/sslh/%I.cfg -f $DAEMON_OPTS
|
||||||
KillMode=process
|
KillMode=process
|
||||||
#Hardening
|
#Hardening
|
||||||
|
Loading…
x
Reference in New Issue
Block a user