Add SystemCallArchitectures=native

This commit is contained in:
Carl Tashian 2021-02-01 13:07:52 -08:00
parent 73fc350b84
commit 05daf22a1e

View file

@ -48,6 +48,7 @@ RemoveIPC=true
RestrictRealtime=true
PrivateDevices=true
SystemCallFilter=@system-service
SystemCallArchitectures=native
MemoryDenyWriteExecute=true
ReadWriteDirectories=/etc/step-ca/db