1 |
On 2013-12-10, Grant Edwards <grant.b.edwards@×××××.com> wrote: |
2 |
|
3 |
> How do you grant a capability (e.g. CAP_NET_RAW) to a user? |
4 |
|
5 |
After more googling, I found this page which describes exactly what |
6 |
I'm trying to do: |
7 |
|
8 |
https://github.com/constanze/GSoC2010_Gentoo_Capabilities/wiki/pam_cap-on-gentoo |
9 |
|
10 |
Except it doesn't work: after modifying /etc/pam.d/system-auth and |
11 |
/etc/security/capability.conf as indicated and logging out/in, pscap |
12 |
shows no cap_net_raw for the user in question, and trying to run |
13 |
programs that use RAW sockets fail: |
14 |
|
15 |
socket: Operation not permitted |
16 |
Error opening socket: Operation not permitted |
17 |
|
18 |
I'm apparently missing something... |
19 |
|
20 |
-- |
21 |
Grant Edwards grant.b.edwards Yow! Sign my PETITION. |
22 |
at |
23 |
gmail.com |