diff options
author | Parnell Springmeyer <parnell@awakenetworks.com> | 2016-07-01 11:09:14 -0500 |
---|---|---|
committer | Parnell Springmeyer <parnell@awakenetworks.com> | 2016-09-01 19:15:56 -0500 |
commit | 2efb60c8e9c502b0fb4df81b03700b600118722a (patch) | |
tree | 62520c16dd18d87f8379439ea380456a81f4abc9 /nixos | |
parent | 4e98aa639f9161fe461ba1c2e4f31519f9d89569 (diff) | |
download | nixlib-2efb60c8e9c502b0fb4df81b03700b600118722a.tar nixlib-2efb60c8e9c502b0fb4df81b03700b600118722a.tar.gz nixlib-2efb60c8e9c502b0fb4df81b03700b600118722a.tar.bz2 nixlib-2efb60c8e9c502b0fb4df81b03700b600118722a.tar.lz nixlib-2efb60c8e9c502b0fb4df81b03700b600118722a.tar.xz nixlib-2efb60c8e9c502b0fb4df81b03700b600118722a.tar.zst nixlib-2efb60c8e9c502b0fb4df81b03700b600118722a.zip |
security: tweaking the setcap-wrapper example to be more relevant
Diffstat (limited to 'nixos')
-rw-r--r-- | nixos/modules/security/setcap-wrappers.nix | 5 |
1 files changed, 2 insertions, 3 deletions
diff --git a/nixos/modules/security/setcap-wrappers.nix b/nixos/modules/security/setcap-wrappers.nix index faebc6f7e0df..b8383d813585 100644 --- a/nixos/modules/security/setcap-wrappers.nix +++ b/nixos/modules/security/setcap-wrappers.nix @@ -48,10 +48,9 @@ in type = types.listOf types.attrs; default = []; example = - [ { program = "sendmail"; - source = "${pkgs.sendmail.bin}/bin/sendmail"; + [ { program = "ping"; owner = "nobody"; - group = "postdrop"; + group = "nogroup"; setcap = true; capabilities = "cap_net_raw+ep"; } |