diff --git a/deploy_configs/mail4one.service b/deploy_configs/mail4one.service index 10bb51e..9401a71 100644 --- a/deploy_configs/mail4one.service +++ b/deploy_configs/mail4one.service @@ -9,19 +9,20 @@ Requires=network-online.target [Service] User=mail4one ExecStart=/usr/local/bin/mail4one --config /etc/mail4one/config.json + AmbientCapabilities=CAP_NET_BIND_SERVICE +CapabilityBoundingSet=CAP_NET_BIND_SERVICE +NoNewPrivileges=yes StateDirectory=mail4one/certs mail4one/mails StateDirectoryMode=0750 -UMask= LogsDirectory=mail4one WorkingDirectory=/var/lib/mail4one ProtectSystem=strict PrivateTmp=true -PrivateUsers=true ProtectHome=yes -NoNewPrivileges=yes +ProtectProc=invisible [Install] WantedBy=multi-user.target