|
@@ -16,7 +16,7 @@ ProtectHome=yes
|
|
|
ProtectSystem=full
|
|
|
ReadOnlyDirectories=/
|
|
|
ReadWriteDirectories=-/opt/vpnbridge
|
|
|
-CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW CAP_SYS_NICE CAP_SYS_ADMIN
|
|
|
+CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW CAP_SYS_NICE CAP_SYS_ADMIN CAP_SETUID
|
|
|
|
|
|
[Install]
|
|
|
WantedBy=multi-user.target
|