CAP_SYS_ADMIN: the new root
Posted Mar 17, 2012 18:00 UTC (Sat) by
giraffedata (subscriber, #1954)
Parent article:
CAP_SYS_ADMIN: the new root
The article seems to imply that many of the things that today require CAP_SYS_ADMIN could instead require some other existing capability. But that's not my impression.
I see CAP_SYS_ADMIN as the miscellaneous category, for things that don't merit their own capability. When I've added privileged operations, I have always scanned all the existing categories and almost never found any more fitting than CAP_SYS_ADMIN.
(
Log in to post comments)