Russ Allbery <r...@debian.org> writes: [...] > > Consider instead having systemd set the capabilties in the unit file using > AmbientCapabilities. It ends up being roughly equivalent for the service,
Hm. I tried to add --8<---------------cut here---------------start------------->8--- AmbientCapabilities=CAP_NET_ADMIN CAP_NET_RAW CAP_NET_BIND_SERVICE --8<---------------cut here---------------end--------------->8--- and takes off capabilities from file but without success (ie. service does not starts) Shoudl I do something else? KJ -- http://wolnelektury.pl/wesprzyj/teraz/ ... [concerning quotation marks] even if we *___did* quote anybody in this business, it probably would be gibberish. -- Thom McLeod