1dedfbb
From 565ef3ffcaaef69a768b6a341777c339217bbbab Mon Sep 17 00:00:00 2001
4f58854
From: Lukas Slebodnik <lslebodn@fedoraproject.org>
eb6c560
Date: Mon, 12 Dec 2016 21:56:16 +0100
eb6c560
Subject: [PATCH] SYSTEMD: Use capabilities
eb6c560
eb6c560
copied from selinux policy
eb6c560
---
eb6c560
 src/sysv/systemd/sssd.service.in | 1 +
eb6c560
 1 file changed, 1 insertion(+)
eb6c560
eb6c560
diff --git a/src/sysv/systemd/sssd.service.in b/src/sysv/systemd/sssd.service.in
1dedfbb
index 0c515d34caaa3ea397c4c7e95eef0188df170840..252889dbb2b7b1e651966258e7b76eab38357e76 100644
eb6c560
--- a/src/sysv/systemd/sssd.service.in
eb6c560
+++ b/src/sysv/systemd/sssd.service.in
1dedfbb
@@ -11,6 +11,7 @@ ExecStart=@sbindir@/sssd -i ${DEBUG_LOGGER}
8500713
 Type=notify
8500713
 NotifyAccess=main
80b5586
 PIDFile=@pidpath@/sssd.pid
4f58854
+CapabilityBoundingSet=CAP_IPC_LOCK CAP_CHOWN CAP_DAC_READ_SEARCH CAP_KILL CAP_NET_ADMIN CAP_SYS_NICE CAP_FOWNER CAP_SETGID CAP_SETUID CAP_SYS_ADMIN CAP_SYS_RESOURCE CAP_BLOCK_SUSPEND
252666a
 Restart=on-failure
eb6c560
 
eb6c560
 [Install]
eb6c560
-- 
1dedfbb
2.15.1
eb6c560