Restrict the Mandos server daemon in the systemd service file.
* mandos.service ([Service]/ProtectSystem): Set to "full". ([Service]/PrivateTmp, [Service]/PrivateDevices, [Service]/ProtectHome): Set to "yes". ([Service]/CapabilityBoundingSet): Set to "CAP_SETUID CAP_DAC_OVERRIDE CAP_NET_RAW".