Correct way to handle SELinux for a systemd-started SSH VPN