Just a test...
This commit is contained in:
parent
42f486a6fc
commit
1186de6c36
|
@ -323,14 +323,14 @@ let
|
||||||
ProtectKernelLogs = true;
|
ProtectKernelLogs = true;
|
||||||
MemoryDenyWriteExecute = true;
|
MemoryDenyWriteExecute = true;
|
||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
LimitNOFILE = 4096;
|
# LimitNOFILE = 4096;
|
||||||
User = cfg.user;
|
User = cfg.user;
|
||||||
Group = cfg.group;
|
Group = cfg.group;
|
||||||
# Server will retry -- this results in stacking
|
# Server will retry -- this results in stacking
|
||||||
Restart = "never";
|
Restart = "never";
|
||||||
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
|
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
|
||||||
SecureBits = "keep-caps";
|
SecureBits = "keep-caps";
|
||||||
ReadWritePaths = [ "${dirOf cfg.kdc.database}" ];
|
# ReadWritePaths = [ "${dirOf cfg.kdc.database}" ];
|
||||||
ExecStart = pkgs.writeShellScript "launch-heimdal-hpropd.sh"
|
ExecStart = pkgs.writeShellScript "launch-heimdal-hpropd.sh"
|
||||||
(concatStringsSep " " [
|
(concatStringsSep " " [
|
||||||
"${pkgs.heimdal}/libexec/heimdal/hpropd"
|
"${pkgs.heimdal}/libexec/heimdal/hpropd"
|
||||||
|
|
Loading…
Reference in New Issue