mirror of
https://github.com/skeeto/endlessh.git
synced 2024-05-19 06:49:58 +00:00
PrivateUsers=true prevents privileged port mapping
This commit is contained in:
@ -27,10 +27,11 @@ ProtectHome=true
|
||||
## setcap 'cap_net_bind_service=+ep' /usr/local/bin/endlessh
|
||||
## 2) uncomment following line
|
||||
#AmbientCapabilities=CAP_NET_BIND_SERVICE
|
||||
## 4) comment following line
|
||||
PrivateUsers=true
|
||||
|
||||
NoNewPrivileges=true
|
||||
ConfigurationDirectory=endlessh
|
||||
PrivateUsers=true
|
||||
ProtectKernelTunables=true
|
||||
ProtectKernelModules=true
|
||||
ProtectControlGroups=true
|
||||
|
Reference in New Issue
Block a user