3 ms·
> but an issue I see is that users are now only able to get ports through the init system The capabilities can also be specified by a fs attribute using setcap
by kj4ips 4y ago
> but an issue I see is that users are now only able to get ports through the init system
The capabilities can also be specified by a fs attribute using setcap(8). This works like setuid, in the the capability is set whenever the file in question is exec'd. *
> Only root can restart a systemd service right
By default, only root can manage system-level systemd services, however, you can add policykit rules to allow specific users (or groups) to perform actions on specific services.
* Certain sandboxing techniques will break this (like no_new_privs)