Commit report for v3.0.x branch
The git bot
announce at freeradius.org
Fri Jul 12 02:00:02 CEST 2019
New activity for FreeRADIUS (the high performance and highly configurable RADIUS server)
gpgsig -----BEGIN PGP SIGNATURE-----
-----END PGP SIGNATURE-----
Adjust, and disable, the systemd CapabilityBoundingSet option
CapabilityBoundingSet is a list of all capabilities that the
process gets, not a list of new ones that it's allowed. So without
e.g. CAP_SETUID the calls to setuid will fail, and radiusd can't
start up if (correctly) configured to run non-root.
Notably, not having CAP_DAC_OVERRIDE set means that it's very
likely that radiusd won't be able to read /etc/raddb due to file
permissions in some installations. Removing it is possible with
correct permissions, but then the -Cx pre config check will fail
as that tried to access log files as root, and will also fail.
(Essentially, it is more secure to remove it, but that will need
It's also very possible that some other capabilities are required
that are not yet listed here.
This option needs testing on a wide range of systems before being
enabled by default, hence commenting it out for now.
Matthew Newton at 2019-07-11T19:21:25Z
rlm_mschap: Fix typo
Jorge Pereira (via Arran Cudbard-Bell)@2019-07-11T17:59:52Z
This commit summary was generated @2019-07-12T00:00:02Z by lgfeed version 0.00 (https://github.com/arr2036/lgfeed).
More information about the Freeradius-Devel