From 0336c6cfc76634d7d636da11524397ad832180fd Mon Sep 17 00:00:00 2001 From: Alberto Gonzalez Iniesta Date: Tue, 7 Jul 2015 11:54:34 +0200 Subject: Add upstream improvements to .service file --- debian/openvpn@.service | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/debian/openvpn@.service b/debian/openvpn@.service index a136de9..07f9e5b 100644 --- a/debian/openvpn@.service +++ b/debian/openvpn@.service @@ -2,6 +2,9 @@ Description=OpenVPN connection to %i PartOf=openvpn.service ReloadPropagatedFrom=openvpn.service +Documentation=man:openvpn(8) +Documentation=https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage +Documentation=https://community.openvpn.net/openvpn/wiki/HOWTO [Service] Type=forking @@ -9,6 +12,9 @@ ExecStart=/usr/sbin/openvpn --daemon ovpn-%i --status /run/openvpn/%i.status 10 ExecReload=/bin/kill -HUP $MAINPID WorkingDirectory=/etc/openvpn ProtectSystem=yes +CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_READ_SEARCH +DeviceAllow=/dev/null rw +DeviceAllow=/dev/net/tun rw [Install] WantedBy=multi-user.target -- cgit v1.2.3