[Unit] Description=Verify integrity of password and group files [Service] # added automatically, for details please see # https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort ProtectSystem=full ProtectHome=read-only PrivateDevices=true ProtectHostname=true ProtectClock=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true RestrictRealtime=true # end of automatic additions Type=oneshot ExecStart=/usr/sbin/pwck -r ExecStart=/usr/sbin/grpck -r Nice=19 IOSchedulingClass=best-effort IOSchedulingPriority=7