systemd: drop all capabilities by default
authorRuben Kerkhof <ruben@rubenkerkhof.com>
Wed, 9 Sep 2015 16:52:26 +0000 (18:52 +0200)
committerRuben Kerkhof <ruben@rubenkerkhof.com>
Mon, 14 Sep 2015 18:41:33 +0000 (20:41 +0200)
commite9ad0b82b3620ba9ed6754e9324f9d2b9ff027c3
treea0d78f887233235ac9201521e6718fd6ffe365b2
parent71bc7b2a9bf47879ce1824d295465de29ca9b152
systemd: drop all capabilities by default

dns and ping need CAP_NET_RAW, iptables needs CAP_NET_ADMIN
so leave those commented out in the .service file.
contrib/systemd.collectd.service