aboutsummaryrefslogtreecommitdiff
path: root/ejabberd.service.template
diff options
context:
space:
mode:
authorHolger Weiss <holger@zedat.fu-berlin.de>2016-10-19 23:29:46 +0200
committerHolger Weiss <holger@zedat.fu-berlin.de>2016-10-19 23:29:46 +0200
commitc3b62d2f75d70a6a6069f4e6a49c374e2fd52809 (patch)
tree9b633730bf8d78914135fa6b07effffe21ba742d /ejabberd.service.template
parentDon't let systemd hide /home and /tmp (diff)
Don't set "NoNewPrivileges" in systemd unit
The "NoNewPrivileges" setting breaks some PAM and extauth setups. Fixes #1281.
Diffstat (limited to 'ejabberd.service.template')
-rw-r--r--ejabberd.service.template3
1 files changed, 0 insertions, 3 deletions
diff --git a/ejabberd.service.template b/ejabberd.service.template
index fdb8fd0b7..4a2635776 100644
--- a/ejabberd.service.template
+++ b/ejabberd.service.template
@@ -12,11 +12,8 @@ ExecStop=@ctlscriptpath@/ejabberdctl stop
ExecReload=@ctlscriptpath@/ejabberdctl reload_config
Type=oneshot
RemainAfterExit=yes
-# The CAP_DAC_OVERRIDE capability is required for pam authentication to work
-CapabilityBoundingSet=CAP_DAC_OVERRIDE
PrivateDevices=true
ProtectSystem=full
-NoNewPrivileges=true
[Install]
WantedBy=multi-user.target