Not OC

  • iluminae
    link
    fedilink
    arrow-up
    34
    ·
    1 year ago

    (after) …ah crap it’s actually selinux…

      • lightnegative
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        First thing to do if you need a functioning server

        Unless you’re a security guy and get off on people not being able to do their jobs due to Access Denied

    • Knusper@feddit.de
      link
      fedilink
      arrow-up
      6
      ·
      1 year ago

      Recently, I learned of the concept of “Linux capabilities”. And yeah, as much as I enjoy reading up on these things, the whole time I was thinking, if something’s fucky with these capabilities, I’ll never remember to check them…

      • uis
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        1 year ago

        Funfact: if you want to run for example HTTP server, you can run it with CAP_NET_BIND_SERVICE and no_new_priv.