[Unit] Description=Tell haveged about new root DefaultDependencies=no ConditionPathExists=/etc/initrd-release Before=initrd-switch-root.service JoinsNamespaceOf=haveged.service [Service] ExecStart=-/usr/sbin/haveged -c root=/sysroot PrivateNetwork=yes # added automatically, for details please see # https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort ProtectSystem=full ProtectHome=true PrivateDevices=true ProtectHostname=true ProtectClock=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true RestrictRealtime=true # end of automatic additions Type=oneshot StandardInput=null StandardOutput=null StandardError=null [Install] WantedBy=initrd-switch-root.target