Files
knockd/debian/knockd.service
Leo Antunes 688ef43fba systemd: downgrade ProtectSystem to "true" from "full"
this should enable interacting with tools such as ufw

Closes: #927883
2021-11-02 23:35:15 +01:00

18 lines
404 B
Desktop File

[Unit]
Description=Port-Knock Daemon
After=network-online.target
Wants=network-online.target
Documentation=man:knockd(1)
[Service]
EnvironmentFile=-/etc/default/knockd
ExecStart=/usr/sbin/knockd $KNOCKD_OPTS
ExecReload=/bin/kill -HUP $MAINPID
KillMode=mixed
SuccessExitStatus=0 2 15
ProtectSystem=true
CapabilityBoundingSet=CAP_NET_RAW CAP_NET_ADMIN CAP_SYS_MODULE
[Install]
WantedBy=multi-user.target