summaryrefslogtreecommitdiff
path: root/sysconf/capability.conf
diff options
context:
space:
mode:
authorStephen Hemminger <stephen.hemminger@vyatta.com>2010-05-25 10:21:03 -0700
committerStephen Hemminger <stephen.hemminger@vyatta.com>2010-06-04 14:09:56 -0700
commite902973f24c75b24576e914d44a68beaaf2aff5b (patch)
treedb6072e677d632f8f52e0134dcdfbfa58dfa6847 /sysconf/capability.conf
parent379c2618cfbc337625f809f63fd4cb22793eccf8 (diff)
downloadvyatta-cfg-system-e902973f24c75b24576e914d44a68beaaf2aff5b.tar.gz
vyatta-cfg-system-e902973f24c75b24576e914d44a68beaaf2aff5b.zip
Add pam_cap capability configuration
Diffstat (limited to 'sysconf/capability.conf')
-rw-r--r--sysconf/capability.conf10
1 files changed, 10 insertions, 0 deletions
diff --git a/sysconf/capability.conf b/sysconf/capability.conf
new file mode 100644
index 00000000..0a7235f1
--- /dev/null
+++ b/sysconf/capability.conf
@@ -0,0 +1,10 @@
+# this is a capability file (used in conjunction with the pam_cap.so module)
+
+# Special capability for Vyatta admin
+all %vyattacfg
+
+# Vyatta Operator
+cap_net_admin,cap_sys_boot,cap_audit_write %vyattaop
+
+## 'everyone else' gets no inheritable capabilities
+none *