diff --git a/systemd/step-ca.service b/systemd/step-ca.service index 352151f5..11fdffae 100644 --- a/systemd/step-ca.service +++ b/systemd/step-ca.service @@ -48,6 +48,7 @@ RemoveIPC=true RestrictRealtime=true PrivateDevices=true SystemCallFilter=@system-service +SystemCallArchitectures=native MemoryDenyWriteExecute=true ReadWriteDirectories=/etc/step-ca/db