2017-12-04 20:33:29 +00:00
|
|
|
From 565ef3ffcaaef69a768b6a341777c339217bbbab Mon Sep 17 00:00:00 2001
|
2017-10-20 16:00:47 +00:00
|
|
|
From: Lukas Slebodnik <lslebodn@fedoraproject.org>
|
2016-12-13 19:09:35 +00:00
|
|
|
Date: Mon, 12 Dec 2016 21:56:16 +0100
|
|
|
|
Subject: [PATCH] SYSTEMD: Use capabilities
|
|
|
|
|
|
|
|
copied from selinux policy
|
|
|
|
---
|
|
|
|
src/sysv/systemd/sssd.service.in | 1 +
|
|
|
|
1 file changed, 1 insertion(+)
|
|
|
|
|
|
|
|
diff --git a/src/sysv/systemd/sssd.service.in b/src/sysv/systemd/sssd.service.in
|
2017-12-04 20:33:29 +00:00
|
|
|
index 0c515d34caaa3ea397c4c7e95eef0188df170840..252889dbb2b7b1e651966258e7b76eab38357e76 100644
|
2016-12-13 19:09:35 +00:00
|
|
|
--- a/src/sysv/systemd/sssd.service.in
|
|
|
|
+++ b/src/sysv/systemd/sssd.service.in
|
2017-12-04 20:33:29 +00:00
|
|
|
@@ -11,6 +11,7 @@ ExecStart=@sbindir@/sssd -i ${DEBUG_LOGGER}
|
2017-01-27 18:57:42 +00:00
|
|
|
Type=notify
|
|
|
|
NotifyAccess=main
|
2019-06-17 12:39:56 +00:00
|
|
|
PIDFile=@pidpath@/sssd.pid
|
2017-10-20 16:00:47 +00:00
|
|
|
+CapabilityBoundingSet=CAP_IPC_LOCK CAP_CHOWN CAP_DAC_READ_SEARCH CAP_KILL CAP_NET_ADMIN CAP_SYS_NICE CAP_FOWNER CAP_SETGID CAP_SETUID CAP_SYS_ADMIN CAP_SYS_RESOURCE CAP_BLOCK_SUSPEND
|
2016-12-13 19:09:35 +00:00
|
|
|
|
|
|
|
[Install]
|
|
|
|
WantedBy=multi-user.target
|
|
|
|
--
|
2017-12-04 20:33:29 +00:00
|
|
|
2.15.1
|
2016-12-13 19:09:35 +00:00
|
|
|
|