Stubby needs to be able to bind to privileged ports, but otherwise
shouldn't need root capabilities.
systemd makes it easy to set the minimal capability set while
otherwise launching the daemon as a non-privileged user.
Ship these files upstream for distributors to deploy.