[Unit] Description=mcat - MCIAS Login Policy Tester After=network-online.target Wants=network-online.target [Service] Type=simple User=mcat Group=mcat ExecStart=/usr/local/bin/mcat server --config /srv/mcat/mcat.toml # Security hardening NoNewPrivileges=true ProtectSystem=strict ProtectHome=true PrivateTmp=true PrivateDevices=true ProtectKernelTunables=true ProtectKernelModules=true ProtectControlGroups=true RestrictSUIDSGID=true RestrictNamespaces=true LockPersonality=true MemoryDenyWriteExecute=true RestrictRealtime=true ReadWritePaths=/srv/mcat [Install] WantedBy=multi-user.target