1 diff --git a/distro/systemd/openvpn-client@.service.in b/distro/systemd/openvpn-client@.service.in
2 index cbcef653..71aa1335 100644
3 --- a/distro/systemd/openvpn-client@.service.in
4 +++ b/distro/systemd/openvpn-client@.service.in
5 @@ -11,6 +11,9 @@ Type=notify
7 WorkingDirectory=/etc/openvpn/client
8 ExecStart=@sbindir@/openvpn --suppress-timestamps --nobind --config %i.conf
11 +AmbientCapabilities=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE
12 CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE
14 DeviceAllow=/dev/null rw
15 diff --git a/distro/systemd/openvpn-server@.service.in b/distro/systemd/openvpn-server@.service.in
16 index d1cc72cb..691f369e 100644
17 --- a/distro/systemd/openvpn-server@.service.in
18 +++ b/distro/systemd/openvpn-server@.service.in
19 @@ -11,6 +11,9 @@ Type=notify
21 WorkingDirectory=/etc/openvpn/server
22 ExecStart=@sbindir@/openvpn --status %t/openvpn-server/status-%i.log --status-version 2 --suppress-timestamps --config %i.conf
25 +AmbientCapabilities=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE CAP_AUDIT_WRITE
26 CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE CAP_AUDIT_WRITE
28 DeviceAllow=/dev/null rw