[Unit] Description=Authoritative DNS Server Documentation=man:nsd(8) [Install] WantedBy=multi-user.target [Service] ExecReload=/bin/kill -HUP $MAINPID ExecStart=/usr/local/sbin/nsd NotifyAccess=main Type=notify CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_CHROOT MemoryDenyWriteExecute=true NoNewPrivileges=true PrivateDevices=true PrivateTmp=true ProtectHome=true ProtectControlGroups=true ProtectKernelModules=true ProtectKernelTunables=true ProtectSystem=strict ReadWritePaths=/usr/local/etc /usr/local/var /run /usr/local/etc/nsd RestrictAddressFamilies=AF_INET AF_UNIX RestrictRealtime=true SystemCallArchitectures=native SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module mount @obsolete @resources