Skip to content
Snippets Groups Projects
acmeserver.service 470 B
Newer Older
ale's avatar
ale committed
[Unit]
Description=ACMEserver
After=network.target

[Service]
User=acmeserver
Group=acmeserver
EnvironmentFile=-/etc/default/acmeserver
ExecStart=/usr/bin/acmeserver --addr $ADDR
ale's avatar
ale committed
ExecReload=/bin/kill -HUP $MAINPID
ale's avatar
ale committed
Restart=always

# Hardening
NoNewPrivileges=yes
PrivateTmp=yes
PrivateDevices=yes
ProtectHome=yes
ProtectSystem=full
ReadOnlyDirectories=/
ale's avatar
ale committed
ReadWriteDirectories=/var/lib/acme
ale's avatar
ale committed
CapabilityBoundingSet=CAP_NET_BIND_SERVICE

[Install]
WantedBy=multi-user.target