this post was submitted on 26 Sep 2023
1069 points (98.6% liked)
Programmer Humor
32588 readers
1758 users here now
Post funny things about programming here! (Or just rant about your favourite programming language.)
Rules:
- Posts must be relevant to programming, programmers, or computer science.
- No NSFW content.
- Jokes must be in good taste. No hate speech, bigotry, etc.
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
(after) ...ah crap it's actually selinux....
SELINUX=disabled
First thing to do if you need a functioning server
Unless you're a security guy and get off on people not being able to do their jobs due to Access Denied
Recently, I learned of the concept of "Linux capabilities". And yeah, as much as I enjoy reading up on these things, the whole time I was thinking, if something's fucky with these capabilities, I'll never remember to check them...
Funfact: if you want to run for example HTTP server, you can run it with CAP_NET_BIND_SERVICE and no_new_priv.