This unit is provided by:
Options
-
[Service]-
ExecStart=/usr/bin/certutil -N -d sql:/etc/pki/pesign --empty-password -
Group=pesign -
LockPersonalityIntroduced in systemd 235=yes -
MemoryDenyWriteExecuteIntroduced in systemd 231=yes -
NoNewPrivilegesIntroduced in systemd 239=yes -
PrivateDevicesIntroduced in systemd 209=yes -
PrivateTmp=yes -
ProtectControlGroupsIntroduced in systemd 232=yes -
ProtectHomeIntroduced in systemd 214=yes -
ProtectHostnameIntroduced in systemd 242=yes -
ProtectKernelLogsIntroduced in systemd 244=yes -
ProtectKernelModulesIntroduced in systemd 232=yes -
ProtectKernelTunablesIntroduced in systemd 232=yes -
ProtectSystemIntroduced in systemd 214=strict -
ReadWritePaths=/etc/pki/pesign -
RemainAfterExit=yes -
RemoveIPCIntroduced in systemd 232=yes -
RestrictNamespacesIntroduced in systemd 233=yes -
RestrictRealtimeIntroduced in systemd 231=yes -
RestrictSUIDSGIDIntroduced in systemd 242=yes -
SystemCallArchitectures=native -
SystemCallFilter=@system-service ~@resources -
Type=oneshot -
User=pesign
-
-
[Unit]-
ConditionPathExists=|!/etc/pki/pesign/cert9.db |!/etc/pki/pesign/key4.db |!/etc/pki/pesign/pkcs11.txt -
Description=Pesign database generation -
Documentation=man:certutil(1)
-
Additionnal notes
Nothing here.