Austin Seipp 0ce90d58cc nixos/chrony: clean up, rework to be a little closer to upstream
Most importantly, this sets PrivateTmp, ProtectHome, and ProtectSystem
so that Chrony flaws are mitigated, should they occur.

Moving to ProtectSystem=full however, requires moving the chrony key
files under /var/lib/chrony -- which should be fine, anyway.

This also ensures ConditionCapability=CAP_SYS_TIME is set, ensuring
that chronyd will only be launched in an environment where such a
capability can be granted.

Signed-off-by: Austin Seipp <aseipp@pobox.com>
2018-09-24 15:42:44 -05:00
..
2018-04-26 13:57:11 +03:00
2018-05-02 10:30:30 -04:00
2016-11-23 15:23:10 +01:00
2017-09-09 00:29:46 +02:00
2018-07-20 18:48:37 +00:00
2018-09-06 12:38:30 +02:00
2018-09-23 15:26:55 +03:00
2017-05-18 15:57:26 +02:00
2018-07-20 18:48:37 +00:00
2018-05-05 00:33:20 -05:00
2018-02-20 10:14:55 +00:00
2018-09-06 16:31:20 +02:00
2018-08-01 21:39:09 +02:00
2016-12-05 13:37:08 +01:00
2017-02-09 18:01:14 +01:00
2018-04-13 13:39:21 +03:00
2018-01-21 11:23:07 +00:00
2018-07-20 18:48:37 +00:00