6e3858
diff -up dovecot-2.3.2/dovecot.service.in.systemd_w_protectsystem dovecot-2.3.2/dovecot.service.in
6e3858
--- dovecot-2.3.2/dovecot.service.in.systemd_w_protectsystem	2018-07-09 12:00:13.359193526 +0200
6e3858
+++ dovecot-2.3.2/dovecot.service.in	2018-07-09 12:00:46.387716884 +0200
6e3858
@@ -23,6 +23,7 @@ ExecReload=@bindir@/doveadm reload
0bb4c4
 ExecStop=@bindir@/doveadm stop
0bb4c4
 PrivateTmp=true
0bb4c4
 NonBlocking=yes
6e3858
+# this will make /usr /boot /etc read only for dovecot
6e3858
 ProtectSystem=full
6e3858
 ProtectHome=no
6e3858
 PrivateDevices=true