more systemd hardening

This commit is contained in:
Balakrishnan Balasubramanian 2023-06-24 21:17:47 -04:00
parent 95423ebf63
commit 7cb1b69744

View File

@ -9,19 +9,20 @@ Requires=network-online.target
[Service]
User=mail4one
ExecStart=/usr/local/bin/mail4one --config /etc/mail4one/config.json
AmbientCapabilities=CAP_NET_BIND_SERVICE
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
NoNewPrivileges=yes
StateDirectory=mail4one/certs mail4one/mails
StateDirectoryMode=0750
UMask=
LogsDirectory=mail4one
WorkingDirectory=/var/lib/mail4one
ProtectSystem=strict
PrivateTmp=true
PrivateUsers=true
ProtectHome=yes
NoNewPrivileges=yes
ProtectProc=invisible
[Install]
WantedBy=multi-user.target