Replacement of

asked 2017-11-30

q2dg gravatar image module is missing in Fedora.

Although I haven't found any notice about it, I suspect the reason could be it is deprecated because, documentation is pretty old and this module (which is present in Ubuntu repositories) doesn't work there neither.

Anyway, how can I restrict use of kernel capabilities to certain users, then? Thanks!

answered 2017-12-01

villykruse gravatar image

It is not missing in fedora. is provided by the libcap package.

$ rpm -ql libcap
Oooh, sorry! I was looking at "pam" package. Anyway, I miss its man page (man pam_cap), which I haven't been able to find. Thanks a lot!!!!

q2dg ( 2017-12-01 )

You will need to use the ubunto manpage.

villykruse ( 2017-12-01 )

I see.../etc/security/capability.conf isn't created by default...

q2dg ( 2017-12-01 )

It doesn't work neither . If I assign a capability to a binary (setcap capnetraw=ip /bin/customping), all users can enjoy it : via pam_cap I've not been able to restrict this to only a "selected" pool of privileged users.

I desist.

NOTE: I've put at the beginning of /etc/pam.d/su the line "auth required" and at the beginning of /etc/security/capability.conf the line "capnet_raw userPrivileged" and, below it, the line "none *"

q2dg ( 2017-12-01 )

Asked: 2017-11-30

