[Unit] Description=Squid caching proxy Documentation=man:squid(8) After=network.target named.service nss-lookup.service [Service] # added automatically, for details please see # https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort ProtectSystem=full ProtectHome=true PrivateDevices=true ProtectHostname=true ProtectClock=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true RestrictRealtime=true # end of automatic additions Type=forking ExecStartPre=%{_libexecdir}/squid/initialize_cache_if_needed.sh ExecStart=/usr/sbin/squid -FC ExecReload=/usr/bin/kill -HUP $MAINPID LimitNOFILE=4096 [Install] WantedBy=multi-user.target