Add capabilities to run a charon IPsec daemon 86/157286/1
authorJiung <jiung.yu@samsung.com>
Tue, 24 Oct 2017 05:32:06 +0000 (14:32 +0900)
committerJiung <jiung.yu@samsung.com>
Tue, 24 Oct 2017 05:32:39 +0000 (14:32 +0900)
Change-Id: If32cff2a0e60d7e50d2b4cd5669536267d4bef4c
Signed-off-by: Yu jiung <jiung.yu@samsung.com>
src/connman.service.in
vpn/connman-vpn.service.in

index cc964e2..de1b37d 100755 (executable)
@@ -12,7 +12,7 @@ Restart=on-failure
 SmackProcessLabel=System
 ExecStart=@bindir@/connmand -n --noplugin vpn
 StandardOutput=null
-Capabilities=cap_net_admin,cap_net_bind_service,cap_net_broadcast,cap_net_raw=i
+Capabilities=cap_setgid,cap_net_admin,cap_net_bind_service,cap_net_broadcast,cap_net_raw=i
 SecureBits=keep-caps
 
 [Install]
index a4c294e..32d2d14 100755 (executable)
@@ -11,7 +11,7 @@ BusName=net.connman.vpn
 SmackProcessLabel=System
 ExecStart=@bindir@/connman-vpnd -n
 StandardOutput=null
-Capabilities=cap_net_admin,cap_net_bind_service,cap_net_broadcast,cap_net_raw=i
+Capabilities=cap_setgid,cap_net_admin,cap_net_bind_service,cap_net_broadcast,cap_net_raw=i
 SecureBits=keep-caps
 
 [Install]