This unit is provided by:
Options
-
[Install] -
[Service]-
CapabilityBoundingSet=CAP_SYS_ADMIN -
DeviceAllow=/dev/null rw /dev/random rw -
DevicePolicy=strict -
ExecStart=/usr/sbin/jitterentropy-rngd -
IPAddressDeny=any -
LimitMEMLOCK=0 -
LockPersonalityIntroduced in systemd 235=yes -
MemoryDenyWriteExecuteIntroduced in systemd 231=yes -
MountFlags=private -
NoNewPrivilegesIntroduced in systemd 239=yes -
PrivateDevicesIntroduced in systemd 209=yes -
PrivateMounts=yes -
PrivateNetwork=yes -
PrivateTmp=yes -
PrivateUsers=no -
ProtectControlGroupsIntroduced in systemd 232=yes -
ProtectHomeIntroduced in systemd 214=yes -
ProtectKernelModulesIntroduced in systemd 232=yes -
ProtectKernelTunablesIntroduced in systemd 232=yes -
ProtectSystemIntroduced in systemd 214=strict -
ReadOnlyPaths=-/ -
RemoveIPCIntroduced in systemd 232=yes -
RestrictAddressFamilies= -
RestrictNamespacesIntroduced in systemd 233=yes -
RestrictRealtimeIntroduced in systemd 231=yes -
SystemCallArchitectures=native -
SystemCallFilter=@system-service ~@chown @clock @cpu-emulation @debug @ipc @module @mount @obsolete @privileged @raw-io @reboot @resources @swap memfd_create mincore mlock mlockall personality -
UMask=0077
-
-
[Unit]-
After=local-fs.target -
Before=sysinit.target -
DefaultDependencies=no -
Description=Jitterentropy Gatherer Daemon
-
Additionnal notes
Nothing here.