From 28c231d68667483a562c2ffe0d490c86d22f9528 Mon Sep 17 00:00:00 2001 From: Beniamino Galvani Date: Fri, 24 Jul 2015 17:08:30 +0200 Subject: [PATCH] systemd: require CAP_AUDIT_WRITE for NetworkManager service We need it to write messages to kernel auditing log. --- data/NetworkManager.service.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/NetworkManager.service.in b/data/NetworkManager.service.in index 42b43e381..fbaf77d85 100644 --- a/data/NetworkManager.service.in +++ b/data/NetworkManager.service.in @@ -11,7 +11,7 @@ ExecStart=@sbindir@/NetworkManager --no-daemon Restart=on-failure # NM doesn't want systemd to kill its children for it KillMode=process -CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE +CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE ProtectSystem=true ProtectHome=read-only