[Pdns-users] why CAP_CHOWN?

Michael Ströder michael at stroeder.com
Sat May 16 18:42:21 UTC 2020


HI!

I appreciate that
pdns/recursordist/pdns-recursor.service.in
already contains some of systemd's hardening options.

But I wonder why CAP_CHOWN is set in CapabilityBoundingSet= and
AmbientCapabilities= and I could not find a reason in the git history of
that file.

It seems to run without that capability.

Ciao, Michael.


More information about the Pdns-users mailing list