aboutsummarylogtreecommitdiffstats
path: root/caddy-systemd-service.patch
diff options
context:
space:
mode:
Diffstat (limited to 'caddy-systemd-service.patch')
-rw-r--r--caddy-systemd-service.patch15
1 files changed, 15 insertions, 0 deletions
diff --git a/caddy-systemd-service.patch b/caddy-systemd-service.patch
new file mode 100644
index 000000000000..779703c9247d
--- /dev/null
+++ b/caddy-systemd-service.patch
@@ -0,0 +1,15 @@
+--- init/linux-systemd/caddy.service 2016-09-28 21:07:57.000000000 +0200
++++ init/linux-systemd/caddy.service.patched 2016-09-29 13:51:35.533691718 +0200
+@@ -38,9 +38,9 @@
+ ; The following additional security directives only work with systemd v229 or later.
+ ; They further retrict privileges that can be gained by caddy. Uncomment if you like.
+ ; Note that you may have to add capabilities required by any plugins in use.
+-;CapabilityBoundingSet=CAP_NET_BIND_SERVICE
+-;AmbientCapabilities=CAP_NET_BIND_SERVICE
+-;NoNewPrivileges=true
++CapabilityBoundingSet=CAP_NET_BIND_SERVICE
++AmbientCapabilities=CAP_NET_BIND_SERVICE
++NoNewPrivileges=true
+
+ [Install]
+ WantedBy=multi-user.target