Austin Seipp 0ce90d58cc nixos/chrony: clean up, rework to be a little closer to upstream
Most importantly, this sets PrivateTmp, ProtectHome, and ProtectSystem
so that Chrony flaws are mitigated, should they occur.

Moving to ProtectSystem=full however, requires moving the chrony key
files under /var/lib/chrony -- which should be fine, anyway.

This also ensures ConditionCapability=CAP_SYS_TIME is set, ensuring
that chronyd will only be launched in an environment where such a
capability can be granted.

Signed-off-by: Austin Seipp <aseipp@pobox.com>
2018-09-24 15:42:44 -05:00
..
2018-04-26 13:57:11 +03:00
2018-05-02 10:30:30 -04:00
2018-07-20 18:48:37 +00:00
2018-09-06 12:38:30 +02:00
2018-09-23 15:26:55 +03:00
2018-07-20 18:48:37 +00:00
2018-05-05 00:33:20 -05:00
2018-09-06 16:31:20 +02:00
2018-08-01 21:39:09 +02:00
2018-04-13 13:39:21 +03:00
2018-07-20 18:48:37 +00:00