b6cdfb1
diff -up dovecot-2.3.2/dovecot.service.in.systemd_w_protectsystem dovecot-2.3.2/dovecot.service.in
b6cdfb1
--- dovecot-2.3.2/dovecot.service.in.systemd_w_protectsystem	2018-07-09 12:00:13.359193526 +0200
b6cdfb1
+++ dovecot-2.3.2/dovecot.service.in	2018-07-09 12:00:46.387716884 +0200
b6cdfb1
@@ -23,6 +23,7 @@ ExecReload=@bindir@/doveadm reload
6cde4f1
 ExecStop=@bindir@/doveadm stop
8c9abbf
 PrivateTmp=true
8c9abbf
 NonBlocking=yes
88a20bf
+# this will make /usr /boot /etc read only for dovecot
88a20bf
 ProtectSystem=full
b6cdfb1
 ProtectHome=no
88a20bf
 PrivateDevices=true