The trouble with CAP_SYS_RAWIO
Posted Mar 22, 2013 4:36 UTC (Fri) by
kevinm (guest, #69913)
Parent article:
The trouble with CAP_SYS_RAWIO
It still sounds to me like the simple solution is "remove CAP_SYS_RAWIO from the initial capability set on secure-booted kernels". So you'll lose the ability to perform some iffy SCSI commands - well, you signed up for some bondage and discipline when you asked for a locked-down, secure-booted kernel, didn't you?
(
Log in to post comments)