DELETE. EVERYTHING.
This commit is contained in:
parent
7e533a6d6f
commit
2c206d394b
@ -312,25 +312,6 @@ let
|
|||||||
description = "Heimdal propagation listener server.";
|
description = "Heimdal propagation listener server.";
|
||||||
path = with pkgs; [ heimdal ];
|
path = with pkgs; [ heimdal ];
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
StandardInput = "socket";
|
|
||||||
StandardOutput = "socket";
|
|
||||||
PrivateDevices = true;
|
|
||||||
PrivateTmp = true;
|
|
||||||
ProtectControlGroups = true;
|
|
||||||
ProtectKernelTunables = true;
|
|
||||||
ProtectHostname = true;
|
|
||||||
ProtectClock = true;
|
|
||||||
ProtectKernelLogs = true;
|
|
||||||
MemoryDenyWriteExecute = true;
|
|
||||||
RestrictRealtime = true;
|
|
||||||
LimitNOFILE = "4096";
|
|
||||||
User = cfg.user;
|
|
||||||
Group = cfg.group;
|
|
||||||
# Server will retry -- this results in stacking
|
|
||||||
Restart = "never";
|
|
||||||
AmbientCapabilities = "CAP_NET_BIND_SERVICE";
|
|
||||||
SecureBits = "keep-caps";
|
|
||||||
#ReadWritePaths = [ "${dirOf cfg.kdc.database}" ];
|
|
||||||
ExecStart = let
|
ExecStart = let
|
||||||
startScript = pkgs.writeShellScript "launch-heimdal-hpropd.sh"
|
startScript = pkgs.writeShellScript "launch-heimdal-hpropd.sh"
|
||||||
(concatStringsSep " " [
|
(concatStringsSep " " [
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user